AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Add Expo Secure Store Keystore

skill-khadinakbarlabs-expo-mobile-app-builder-add-expo-secure-store-keystore · by khadinakbarlabs

Add expo-secure-store backed by Android Keystore for storing auth tokens and secrets. Use when the user says 'secure store android', 'keystore android', 'store token secure'.

No reviews yet
0 installs
13 views
0.0% view→install

Install

$ agentstack add skill-khadinakbarlabs-expo-mobile-app-builder-add-expo-secure-store-keystore

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-khadinakbarlabs-expo-mobile-app-builder-add-expo-secure-store-keystore)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Add Expo Secure Store Keystore? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Add Expo Secure Store (Android Keystore)

Hardware-backed encrypted key-value store. Uses Android Keystore on Android.

Install

npx expo install expo-secure-store

Basic use

import * as SecureStore from 'expo-secure-store';

await SecureStore.setItemAsync('auth_token', 'jwt...');
const token = await SecureStore.getItemAsync('auth_token');
await SecureStore.deleteItemAsync('auth_token');

Android-specific options

// Require biometric or PIN to access (Android 6+)
await SecureStore.setItemAsync('sensitive', 'value', {
  requireAuthentication: true,
  authenticationPrompt: 'Verify to unlock',
});

What it uses under the hood

  • Android: EncryptedSharedPreferences + Android Keystore (hardware-backed on TEE/StrongBox devices)
  • Each key encrypted with hardware-derived key
  • Survives app data clear (but NOT uninstall)

When NOT to use SecureStore

  • Large data (use SQLite encrypted instead)
  • Frequently-read values (slow ~5-10ms per read)
  • Data that should survive uninstall (use cloud sync)

When to use

  • Auth tokens (access, refresh)
  • API keys for the user's session
  • Encryption keys for local SQLite
  • Sensitive user inputs (PIN, recovery phrase)

Gotcha: rooted devices

SecureStore relies on Android Keystore. On rooted devices, Keystore can be bypassed. For high-value apps, also implement:

  • add-app-attestation (Play Integrity API)
  • Server-side validation

Pair with

  • add-supabase-auth-android for token persistence
  • Use MMKV (add-zustand persistence) for non-sensitive data

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.