Skip to content

Mobile app authentication

In short

Native iOS and Android apps use the same Authorization Code flow with PKCE as the web, opened in the system browser rather than an embedded web view.
  • Use ASWebAuthenticationSession on iOS and Custom Tabs on Android.
  • Embedded web views are rejected by app review and cannot share sign-in state.
  • Register your custom scheme or universal link as the redirect URI.

The flow: Authorization Code with PKCE

  1. 1

    Register a redirect the OS can route

    A custom scheme or an app link. It must be registered ahead of time, exactly as the app will send it.

    Full detail in the docs
  2. 2

    Open the system browser, not a web view

    ASWebAuthenticationSession on iOS, Custom Tabs on Android. Both platforms require it, and both let the user reuse an existing session.

    Full detail in the docs
  3. 3

    Exchange the code on device

    Handle the redirect, verify the state, and exchange the code with the verifier. No client secret is involved.

  4. 4

    Store tokens in the platform keystore

    Keychain on iOS, EncryptedSharedPreferences or the Keystore on Android. Never in plain preferences or a file.

Common mistakes

  • Using an embedded web view — the most common reason a sign-in flow fails review.
  • Reusing one redirect scheme across several apps, which lets another app intercept the code.
  • Keeping refresh tokens outside the platform keystore.

Mobile & native apps

Open the guide