device-integrity
dpearson2699/swift-ios-skills
Verify device legitimacy and app integrity using Apple's DeviceCheck and App Attest.
What is device-integrity?
Implements fraud prevention and app authenticity validation on iOS using DeviceCheck (per-device bits) and App Attest (Secure Enclave-backed cryptographic attestation). Use when protecting sensitive API endpoints, detecting compromised devices, or validating that requests come from genuine Apple devices running legitimate app instances.
- Generate and manage DeviceCheck tokens for per-device verification flags
- Create and attest Secure Enclave-backed key pairs for cryptographic app identity
- Perform App Attest attestation flow to prove app legitimacy to Apple servers
- Sign requests with attested keys to prove ongoing device and app authenticity
- Handle error cases and unsupported device/extension scenarios
- Store and reuse keyIds for account/device-scoped key management
How to install device-integrity
npx skills add https://github.com/dpearson2699/swift-ios-skills --skill device-integrity- iOS 11+ for DeviceCheck (DCDevice)
- iOS 14+ for App Attest (DCAppAttestService)
- Apple Developer account and app signing certificate
- Server-side integration with Apple's DeviceCheck API endpoints
- Keychain access for storing attestation keyIds
How to use device-integrity
- 1.Check if DeviceCheck or App Attest is supported on the device using DCDevice.current.isSupported or DCAppAttestService.shared.isSupported
- 2.For DeviceCheck: generate a fresh token with DCDevice.current.generateToken(), send it to your server, and exchange it with Apple's DeviceCheck API to read/write per-device bits
- 3.For App Attest: generate a key pair once per user account with DCAppAttestService.shared.generateKey() and store the keyId securely in Keychain
- 4.Perform attestation by fetching a server challenge, hashing it with SHA-256, and calling service.attestKey(keyId, clientDataHash:), then send the attestation object to your server for verification with Apple
- 5.After server verification succeeds, use the keyId to create assertions on future requests by signing request data with the attested key to prove ongoing legitimacy
Use cases
- Prevent promotional offer fraud by flagging devices that have already claimed incentives
- Protect sensitive financial or account-access endpoints with cryptographic app attestation
- Detect jailbroken or compromised devices before processing high-risk transactions
- Validate app authenticity on backend servers to block requests from modified or sideloaded apps
- Implement multi-layered fraud detection combining per-device bits with cryptographic assertions
- iOS app developers implementing fraud prevention
- Backend engineers validating app authenticity on sensitive endpoints
- Security teams building device integrity checks into risk assessment pipelines
- Fintech and payment apps requiring strong device verification
- Apps handling user accounts or promotional offers vulnerable to abuse
device-integrity FAQ
DeviceCheck (iOS 11+) provides two Boolean bits per device for simple flags like promo claims, verified server-side via Apple's API. App Attest (iOS 14+) uses Secure Enclave keys for cryptographic proof that a specific app instance on a specific device is legitimate, suitable for protecting sensitive endpoints.
No. Generate a fresh token for each server operation. Each token is single-use and ephemeral; reusing or caching tokens defeats the security model.
No. Generate one key pair per user account on each device. Sharing keys across users breaks the per-account security model and affects risk metrics.
Discard the keyId and generate a new key before retrying. Do not attempt to reuse a keyId that failed server verification.
App Attest is supported only in Action, extensible SSO, and watchOS extensions. Other extension types are unsupported even if isSupported returns true; fall back to DeviceCheck tokens.
Full instructions (SKILL.md)
Source of truth, from dpearson2699/swift-ios-skills.
name: device-integrity description: "Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows). Use when implementing fraud prevention, detecting compromised devices, validating app authenticity with Apple's servers, protecting sensitive API endpoints with attested requests, or adding device verification to a backend architecture."
Device Integrity
Verify that requests to your server come from a genuine Apple device running a legitimate instance of your app. DeviceCheck provides per-device bits for simple flags (e.g., "claimed promo offer"). App Attest uses Secure Enclave keys and Apple attestation to cryptographically prove app legitimacy on sensitive requests.
Contents
- DCDevice (DeviceCheck Tokens)
- DCAppAttestService (App Attest)
- App Attest Key Generation
- App Attest Attestation Flow
- App Attest Assertion Flow
- Server Verification Guidance
- Error Handling
- Common Patterns
- Common Mistakes
- Review Checklist
- References
DCDevice (DeviceCheck Tokens)
DCDevice generates a
unique, ephemeral token that identifies a device. Treat each token as
single-use: generate a new token for each server operation instead of caching or
reusing one. The token is sent to your server, which then communicates with
Apple's servers to read or set two per-device bits. Available on iOS 11+.
Token Generation
import DeviceCheck
func generateDeviceToken() async throws -> Data {
guard DCDevice.current.isSupported else {
throw DeviceIntegrityError.deviceCheckUnsupported
}
return try await DCDevice.current.generateToken()
}
Sending the Token to Your Server
func sendTokenToServer(_ token: Data) async throws {
let tokenString = token.base64EncodedString()
var request = URLRequest(url: serverURL.appending(path: "verify-device"))
request.httpMethod = "POST"
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = try JSONEncoder().encode(["device_token": tokenString])
let (_, response) = try await URLSession.shared.data(for: request)
guard let httpResponse = response as? HTTPURLResponse,
httpResponse.statusCode == 200 else {
throw DeviceIntegrityError.serverVerificationFailed
}
}
Server-Side Overview
The server exchanges each fresh token with Apple's authenticated DeviceCheck API. Load DeviceCheck Server Endpoints for endpoint and environment details.
What the Two Bits Are For
Apple stores two Boolean values per device per developer team. You decide what they mean. Common uses:
- Bit 0: Device has claimed a promotional offer.
- Bit 1: Device has been flagged for fraud.
Bits persist across app reinstall. You control when to reset them via the server API.
DCAppAttestService (App Attest)
DCAppAttestService
validates that a specific instance of your app on a specific device is
legitimate. It uses a hardware-backed key in the Secure Enclave to create
cryptographic attestations and assertions. Available on iOS 14+.
The flow has three phases:
- Key generation -- create a key pair in the Secure Enclave.
- Attestation -- Apple certifies the key belongs to a genuine Apple device running your app.
- Assertion -- sign server requests with the attested key to prove ongoing legitimacy.
Checking Support
import DeviceCheck
let attestService = DCAppAttestService.shared
guard attestService.isSupported else {
// Fall back to DCDevice token or other risk assessment.
// App Attest is not available on simulators or all device models.
return
}
For app extensions, App Attest is supported only in Action, extensible SSO, and
watchOS extensions. Treat other extension types as unsupported even if
isSupported returns true.
App Attest Key Generation
Generate one cryptographic key pair per user account on each device. The
private key stays in the Secure Enclave. The returned keyId is the only
identifier your app can later use to access the key, so record and reuse the
account/device-scoped keyId; do not share one key across users. Avoid
unnecessary regeneration because each new key affects App Attest key-count risk
metrics. Only treat the keyId as usable after your server verifies
attestation. If server verification fails, discard the keyId and generate a
new key before retrying.
import DeviceCheck
actor AppAttestManager {
private let service = DCAppAttestService.shared
private var keyId: String?
/// Generate and record a key pair for App Attest.
func generateKeyIfNeeded() async throws -> String {
if let existingKeyId = loadKeyIdFromKeychain() {
self.keyId = existingKeyId
return existingKeyId
}
let newKeyId = try await service.generateKey()
saveKeyIdToKeychain(newKeyId)
self.keyId = newKeyId
return newKeyId
}
// MARK: - Keychain helpers (simplified)
private func saveKeyIdToKeychain(_ keyId: String) {
let data = Data(keyId.utf8)
let query: [String: Any] = [
kSecClass as String: kSecClassGenericPassword,
kSecAttrAccount as String: "app-attest-key-id-\(currentAccountID)",
kSecAttrService as String: Bundle.main.bundleIdentifier ?? "",
kSecValueData as String: data,
kSecAttrAccessible as String: kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly
]
SecItemDelete(query as CFDictionary) // Remove old if exists
SecItemAdd(query as CFDictionary, nil)
}
private func loadKeyIdFromKeychain() -> String? {
let query: [String: Any] = [
kSecClass as String: kSecClassGenericPassword,
kSecAttrAccount as String: "app-attest-key-id-\(currentAccountID)",
kSecAttrService as String: Bundle.main.bundleIdentifier ?? "",
kSecReturnData as String: true,
kSecMatchLimit as String: kSecMatchLimitOne
]
var result: AnyObject?
let status = SecItemCopyMatching(query as CFDictionary, &result)
guard status == errSecSuccess, let data = result as? Data else { return nil }
return String(data: data, encoding: .utf8)
}
}
App Attest Attestation Flow
Attestation proves that the key was generated on a genuine Apple device running
a legitimate instance of your app. You perform attestation once per key, then
store the verified public key and receipt on your server. The app stores the
keyId for future assertions after the server accepts the attestation.
Client-Side Attestation
import DeviceCheck
import CryptoKit
extension AppAttestManager {
/// Attest the key with Apple. Send the attestation object to your server.
func attestKey() async throws -> Data {
guard let keyId else {
throw DeviceIntegrityError.keyNotGenerated
}
// 1. Request a one-time challenge from your server
let challenge = try await fetchServerChallenge()
// 2. Hash the challenge (Apple requires a SHA-256 hash)
let challengeHash = Data(SHA256.hash(data: challenge))
// 3. Ask Apple to attest the key
let attestation = try await service.attestKey(keyId, clientDataHash: challengeHash)
// 4. Send the attestation object to your server for verification
try await sendAttestationToServer(
keyId: keyId,
attestation: attestation,
challenge: challenge
)
return attestation
}
private func fetchServerChallenge() async throws -> Data {
let url = serverURL.appending(path: "attest/challenge")
let (data, _) = try await URLSession.shared.data(from: url)
return data
}
private func sendAttestationToServer(
keyId: String,
attestation: Data,
challenge: Data
) async throws {
var request = URLRequest(url: serverURL.appending(path: "attest/verify"))
request.httpMethod = "POST"
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
let payload: [String: String] = [
"key_id": keyId,
"attestation": attestation.base64EncodedString(),
"challenge": challenge.base64EncodedString()
]
request.httpBody = try JSONEncoder().encode(payload)
let (_, response) = try await URLSession.shared.data(for: request)
guard let httpResponse = response as? HTTPURLResponse,
httpResponse.statusCode == 200 else {
throw DeviceIntegrityError.attestationVerificationFailed
}
}
}
Server-Side Attestation Verification
The server must verify the attestation before the client treats keyId as usable,
then store the verified public key and receipt. Load
Server-Side Attestation Verification
for the certificate, App ID, environment, counter, credential, and nonce checks.
App Attest Assertion Flow
After attestation, use assertions to sign sensitive requests. Each assertion proves the request came from the attested app instance and includes a server-issued, one-time challenge to prevent replay.
Client-Side Assertion
import DeviceCheck
import CryptoKit
extension AppAttestManager {
/// Generate an assertion for encoded client data.
/// Client data should include a one-time server challenge and request context.
func generateAssertion(for clientData: Data) async throws -> Data {
guard let keyId else {
throw DeviceIntegrityError.keyNotGenerated
}
let clientDataHash = Data(SHA256.hash(data: clientData))
return try await service.generateAssertion(keyId, clientDataHash: clientDataHash)
}
}
Using Assertions in Network Requests
struct AppAttestClientData: Encodable {
let challenge: String
let method: String
let path: String
let bodySHA256: String
}
extension AppAttestManager {
/// Perform an attested API request.
func makeAttestedRequest(
to url: URL,
method: String = "POST",
body: Data
) async throws -> (Data, URLResponse) {
let challenge = try await fetchAssertionChallenge()
let bodyHash = Data(SHA256.hash(data: body)).base64EncodedString()
let clientData = try JSONEncoder().encode(
AppAttestClientData(
challenge: challenge,
method: method,
path: url.path,
bodySHA256: bodyHash
)
)
let assertion = try await generateAssertion(for: clientData)
var request = URLRequest(url: url)
request.httpMethod = method
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.setValue(assertion.base64EncodedString(), forHTTPHeaderField: "X-App-Attest-Assertion")
request.setValue(clientData.base64EncodedString(), forHTTPHeaderField: "X-App-Attest-Client-Data")
request.httpBody = body
return try await URLSession.shared.data(for: request)
}
private func fetchAssertionChallenge() async throws -> String {
let url = serverURL.appending(path: "assert/challenge")
let (data, _) = try await URLSession.shared.data(from: url)
return String(decoding: data, as: UTF8.self)
}
}
Server-Side Assertion Verification
The server must verify each assertion's signature, RP ID, counter, one-time challenge, and request binding before authorizing the request. Load Server-Side Assertion Verification for the complete algorithm.
Server Verification Guidance
See references/device-integrity-patterns.md for full server architecture guidance including attestation vs. assertion comparison, recommended endpoint design, and risk assessment.
Security Boundaries
App Attest proves app-instance integrity for selected requests. It does not replace user authentication, OAuth/JWT/session handling, API token design, entitlement or subscription authorization, TLS, certificate pinning, or general networking security. Treat those as handoffs to authentication, networking, or broader security guidance, and still enforce normal authentication and authorization after App Attest passes.
Error Handling
Handle DCError codes from DeviceCheck operations. Key cases:
.serverUnavailable— retry with exponential backoff.invalidKey— the key was already attested, assertion used an unattested key, or the service rejected the key.featureUnsupported— fall back toDCDevicetokens.invalidInput— malformedclientDataHashorkeyId
For attestKey, retry .serverUnavailable later with the same keyId and the
same clientDataHash. For other attestation errors, discard the key identifier
and create a new key before retrying. See
references/device-integrity-patterns.md
for full error handling code, retry strategy, and rejected-key recovery.
Common Patterns
Environment Entitlement
Set the App Attest environment in your entitlements file. Use development
during testing and production for App Store builds. Load
Environment Entitlement
for the XML, default sandbox behavior, distribution behavior, and extension limits.
See references/device-integrity-patterns.md for the full integration manager pattern, gradual rollout guidance, and error type definition.
Common Mistakes
- Generating a new key on every launch. Generate once per user account on a device, persist the
keyId, and keep key counts low. - Reusing
DCDevicetokens. Treat generated tokens as single-use. Generate a new token for each server operation. - Skipping the fallback for unsupported devices or extensions. Not all devices and extension types support App Attest. Use
DCDevicetokens or other risk assessment as fallback. - Trusting attestation client-side. All verification must happen on your server.
- Signing only the raw request body. Assertion client data must include a one-time server challenge and enough request context for the server to bind the assertion to the request.
- Verifying the wrong attestation nonce. Compare the certificate extension with
SHA256(authData || SHA256(challenge)), notSHA256(challenge)alone. - Not implementing replay protection. The server must validate one-time challenges and track the assertion counter.
- Mixing development and production environments. Sandbox keys and receipts do not work in production, and production keys and receipts do not work in sandbox.
- Not handling
DCError.invalidKey. Check for repeated attestation, unattested assertion keys, or service rejection; regenerate only after the state is known bad.
Review Checklist
-
DCDevicetokens generated per server operation and never cached for reuse -
DCAppAttestService.isSupportedchecked before use; unsupported devices and extension types have a fallback - Key generated once per user account on each device and
keyIdpersisted only for that app account/device - Attestation performed once per key; server stores verified public key and receipt
- Server validates attestation certificate chain, App ID hash, environment
aaguid, credential ID, and nonceSHA256(authData || SHA256(challenge)) - Assertions include one-time challenge plus request context; server verifies signature, RP ID, counter, challenge, and request binding
- Protected endpoints still enforce normal user authentication and entitlement authorization after App Attest passes
-
DCErrorcases handled:.serverUnavailableretries attestation with the same key/hash; bad keys are discarded and regenerated - App Attest environment entitlement and sandbox/production server routing are consistent
- Gradual rollout considered; feature flag in place for enabling/disabling
References
Related skills
More from dpearson2699/swift-ios-skills and the wider catalog.

dockkit
Control motorized camera docks and enable intelligent subject tracking with DockKit for iOS.

energykit
Query grid electricity forecasts and optimize home device scheduling for cleaner, cheaper power.

eventkit
Create, read, and manage calendar events and reminders using EventKit and EventKitUI.

financekit
Access Apple Wallet financial data—transactions, balances, Apple Card, Apple Cash, and Savings—with user authorization.

focus-engine
Keyboard, directional, and scene-level focus management for SwiftUI and UIKit across iOS, macOS, tvOS, and visionOS.

gamekit
Integrate Game Center features: authentication, leaderboards, achievements, and real-time/turn-based multiplayer.