Fingerprint and face recognition.
WHAT IT ACTUALLY DOES
Confirms the device's owner is present.
WHAT IT DOES NOT DO
Authenticate to your server.
WHY THAT DISTINCTION MATTERS
Biometrics unlock something held locally. They are not a credential you transmit.
WHAT THE CORRECT PATTERN IS
A token stored in secure storage, released only after biometric confirmation.
WHAT TO USE IT FOR
Convenient re-entry to an application Confirming a sensitive action Unlocking locally stored credentials
WHAT TO ALWAYS PROVIDE
A fallback: a passcode or password.
WHY
Biometrics fail, and some users cannot use them.
WHAT TO HANDLE
Hardware not present No biometrics enrolled Repeated failure, which locks it out Biometrics changed on the device
WHY THAT LAST POINT MATTERS
Adding a new fingerprint or face should invalidate what was protected, and the platform supports this.
WHAT TO NEVER DO
Treat biometric success alone as authorisation for anything on the server Store biometric data yourself
WHY THAT SECOND POINT
The platform never gives it to you, deliberately.