Security & FAQ

Security model, common questions, and how to reach support.

Security

  • Keys are ephemeral: a new ECDH pair is generated per authenticate call, held only in process memory and destroyed once the response is decrypted.
  • Generate the nonce on your server and verify it there when exchanging the code; this is the protection against replay attacks.
  • authCode is single-use and contains no personal data on its own; user data is transmitted only over your secure server-to-server channel.
  • Do not log the nonce or the authorization code.
  • Declarations annotated @PaspoInternalApi (the crypto layer and wire models) are not public API; the compiler prevents their use and they may change in any release.

FAQ

Does the application require internet access during the call? The SDK itself does not; it communicates with Paspo ID over an Intent. Paspo ID and your server must be online.

What happens if the user uninstalls Paspo ID between sign-ins?authenticate detects this, opens the Play Store and returns NotInstalled.

Can the SDK be used from Compose? Yes; see the first example under Custom integration, or use the ready-made button.

Support

For onboarding inquiries (registering the application's package and signature, the repository URL, the server-side exchange API): paspo.id or see Support.