oneid_sdk

Flutter SDK for OneID: authentication, device identity, and eKYC.

Authentication is a standard OAuth 2.0 Authorization Code flow with PKCE (RFC 6749 / RFC 7636 / RFC 8252), with every token DPoP-bound (RFC 9449) to a key held in Android Keystore / iOS Secure Enclave. See docs/architecture/PROTOCOL.md for the full design and why the native side vendors AppAuth 2 instead of depending on a community package.

Status

This is a project scaffold. The public Dart API in lib/auth/ is real and tested; the native side (android/, ios/) is stubbed — every call currently fails with a clear UNIMPLEMENTED error until the vendored AppAuth 2 + Keystore/Secure Enclave DPoP integration lands (see the TODO(mobile) blocks on OneidSdkPlugin). lib/device/ and lib/ekyc/ are structural placeholders with no provider/protocol decided yet.

Structure

lib/
  oneid_sdk.dart        # barrel export
  auth/                 # OAuth 2.0 + PKCE + DPoP authentication (implemented, native pending)
  device/                # device identity / security posture (placeholder)
  ekyc/                  # eKYC verification (placeholder)
  src/
    pigeon/generated.dart # Pigeon-generated platform channel — do not hand-edit
    exceptions/
    network/
    storage/
pigeon/api.dart          # Pigeon schema — edit this, then regenerate (see below)
android/, ios/           # native plugin implementation
example/                 # demo app
security/                # mobsf / frida / zap scan config — see each README
docs/
  architecture/          # protocol/design docs (start here: architecture/PROTOCOL.md)
  development/           # local dev workflow notes
  security/              # security testing overview
  releases/              # release process

Usage

final auth = OneIdAuth(
  OneIdAuthConfig(
    environment: OneIdEnvironment.uat,
    clientId: 'your-client-id',
    redirectUrl: 'com.yourapp://callback',
  ),
);

final tokens = await auth.login();       // OAuth Authorization Code + PKCE, DPoP-bound
final me = await auth.fetchUserInfo(Uri.parse('https://.../userinfo'));
await auth.logout();

Development

flutter pub get
dart run pigeon --input pigeon/api.dart   # after editing pigeon/api.dart
dart format .
flutter analyze
flutter test

Contributing

See CONTRIBUTING.md (setup, checks to run before a PR, the Pigeon regeneration workflow, dependency policy, and commit message conventions) and AGENTS.md for the fuller set of conventions for human and AI contributors alike.

License

BSD-3-Clause — see LICENSE.

Libraries

auth/auth
auth/auth_config
auth/auth_result
device/attestation_evidence
device/device_info
device/device_management
device/security_status
ekyc/ekyc
ekyc/ekyc_config
ekyc/ekyc_result
ocr/device_services
ocr/ocr_engine
ocr/ocr_result
oneid_sdk
Flutter SDK for OneID: authentication (OAuth 2.0 Authorization Code + PKCE, DPoP-bound per RFC 9449, via a vendored AppAuth 2), device identity/security posture, and eKYC.