Download the PHP package pushinbr/pam-native-auth without Composer

On this page you can find all versions of the php package pushinbr/pam-native-auth. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package pam-native-auth

# PAM Native Auth **Credentials belong in the device vault, not in application storage.** Build secure sessions and OAuth 2.1/PKCE flows with Android Keystore and Apple Keychain primitives exposed through strict PHP APIs. [![Latest version](https://img.shields.io/packagist/v/pushinbr/pam-native-auth?style=flat-square&label=stable)](https://packagist.org/packages/pushinbr/pam-native-auth) [![CI](https://img.shields.io/github/actions/workflow/status/push-in/pam-native-auth/ci.yml?branch=main&style=flat-square&label=CI)](https://github.com/push-in/pam-native-auth/actions) ![PHP](https://img.shields.io/badge/PHP-8.5-777BB4?style=flat-square&logo=php&logoColor=white) ![Android](https://img.shields.io/badge/Android-API%2026%2B-3DDC84?style=flat-square&logo=android&logoColor=white) ![iOS](https://img.shields.io/badge/iOS-15%2B-000000?style=flat-square&logo=apple&logoColor=white) **[Documentation](https://push-in.github.io/pam-docs/native/overview/) · [Quick start](#quick-start) · [What you can build](#what-you-can-build) · [PAM ecosystem](https://push-in.github.io/pam-docs/ecosystem/) · [Issues](https://github.com/push-in/pam-native-auth/issues)**

Why PAM Native Auth

Build secure sessions and OAuth 2.1/PKCE flows with Android Keystore and Apple Keychain primitives exposed through strict PHP APIs. The public API is strictly typed for PHP 8.5; expensive or frame-sensitive work stays in Rust or the platform SDK instead of crossing the application boundary every frame.

Best for A focused capability you can add to any PAM Native application
Native path Android Keystore · Apple Keychain
Application model Composer package + generated native integration
Design rule Independent module; no feed, vertical, or application template bundled

What you can build

Quick start

Already have a PAM Native project? Add only this capability:

New to PAM? Follow the five-minute PAM Native setup once, then return here. Your application stays a normal Composer project with a committed lockfile.

See it in action

Production authentication foundations for PAM Native applications. Secrets are encrypted by Android Keystore or stored by Apple Keychain instead of being written to PHP files, preferences, or application databases.

The vault uses AES-256-GCM with a non-exportable Android Keystore key. On Apple platforms it uses a generic-password Keychain item and defaults to WhenUnlockedThisDeviceOnly. PKCE uses SHA-256 (S256) and a cryptographically random verifier.

Do not store user passwords. Store short-lived sessions or refresh tokens, rotate them server-side, and delete the local credential on logout or revocation.

Platform support

Passkeys and interactive OAuth authorization are deliberately separate from the vault because they require an app presentation context, associated domains, and server-side challenge verification. Those flows will be added only with end-to-end app lifecycle support.

What installation does

pam add auth resolves the official compatible package, performs a non-mutating Composer preflight, updates the normal composer.json and composer.lock, refreshes generated native integration when required, and leaves the project ready for pam doctor validation.

Use pam packages to inspect availability and pam remove auth to uninstall the capability safely. Direct Composer commands are an advanced interoperability path; PAM is the supported application workflow.

API guide

API Responsibility
Biometrics Check availability and request system biometric authentication.
ScreenPrivacy Conceal protected content until the application explicitly authorizes reveal.
AuthVault Store, check, retrieve, and delete encrypted secrets; exists() never returns secret material.
Pkce / PkcePair Generate and verify OAuth 2.1 S256 PKCE material.
CredentialAccessibility Choose the native credential accessibility policy.
AuthOperationState Typed result state for vault operations.

All coded states, kinds, and variants are sequential integer-backed enums. Use enum cases in application code; do not depend on raw wire numbers.

Production checklist

Troubleshooting

Compatibility and support

This package supports PAM Native 1.x, Android API 26+, and iOS 15+ unless a platform-specific section above states a stricter requirement. Platform SDKs, credentials, entitlements, physical hardware, and store configuration remain application responsibilities.

Security vulnerabilities should be reported through the repository security policy or GitHub private vulnerability reporting, not a public issue.

Biometric unlock and screen privacy

Biometrics uses strong Android biometrics and biometric-only Apple LocalAuthentication. Results are explicit integer-backed enums; cancellation, unavailability, lockout, failure and concurrent requests never report authentication success.

ScreenPrivacy keeps content covered after backgrounding until the application explicitly calls reveal. Android also blocks screenshots on the protected Activity and conceals accessibility content. iOS covers inactive scene windows; it does not prevent screenshots.

These primitives do not implement an application session gate or cryptographically bind vault retrieval to biometric authentication. Gate credential access, request dispatch and navigation together; validate session expiry and revocation with your backend before revealing private content.


All versions of pam-native-auth with dependencies

PHP Build Version
Package Version
Requires php Version ^8.5
pushinbr/pam-native Version ^0.8 || ^0.9 || ^0.10 || ^1.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package pushinbr/pam-native-auth contains the following files

Loading the files please wait ...