Skip to content
Back to skills

Add Expo Secure Store Keystore

ASecurity

Add expo-secure-store backed by Android Keystore for storing auth tokens and secrets. Use when the user says 'secure store android', 'keystore android', 'store token secure'.

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added October 4, 2026
developmentgobashsqlapi

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add khadinakbarlabs/expo-mobile-app-builder --skill add-expo-secure-store-keystore --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Add Expo Secure Store Keystore?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Add Expo Secure Store Keystore
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/khadinakbarlabs-add-expo-secure-store-keystore/badge)](https://www.skillsdirectory.com/skills/khadinakbarlabs-add-expo-secure-store-keystore)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "add-expo-secure-store-keystore"
description: "Add expo-secure-store backed by Android Keystore for storing auth tokens and secrets. Use when the user says 'secure store android', 'keystore android', 'store token secure'."
---

# Add Expo Secure Store (Android Keystore)

Hardware-backed encrypted key-value store. Uses Android Keystore on Android.

## Install
```bash
npm exec --no -- expo install expo-secure-store
```

## Basic use
```tsx
import * as SecureStore from 'expo-secure-store';

await SecureStore.setItemAsync('auth_token', 'jwt...');
const token = await SecureStore.getItemAsync('auth_token');
await SecureStore.deleteItemAsync('auth_token');
```

## Android-specific options

```tsx
// Require biometric or PIN to access (Android 6+)
await SecureStore.setItemAsync('sensitive', 'value', {
  requireAuthentication: true,
  authenticationPrompt: 'Verify to unlock',
});
```

## What it uses under the hood

- Android: EncryptedSharedPreferences + Android Keystore (hardware-backed on TEE/StrongBox devices)
- Each key encrypted with hardware-derived key
- Survives app data clear (but NOT uninstall)

## When NOT to use SecureStore

- Large data (use SQLite encrypted instead)
- Frequently-read values (slow ~5-10ms per read)
- Data that should survive uninstall (use cloud sync)

## When to use

- Auth tokens (access, refresh)
- API keys for the user's session
- Encryption keys for local SQLite
- Sensitive user inputs (PIN, recovery phrase)

## Gotcha: rooted devices

SecureStore relies on Android Keystore. On rooted devices, Keystore can be bypassed. For high-value apps, also implement:
- `add-app-attestation` (Play Integrity API)
- Server-side validation

## Pair with
- `add-supabase-auth-android` for token persistence
- Use MMKV (`add-zustand` persistence) for non-sensitive data

Files in this skill

  • SKILL.md1.8 KB
  • agents/openai.yaml221 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…