finds.dev← search

// the find

mCodex/react-native-sensitive-info

★ 1,066 · TypeScript · MIT · updated Sep 2026

🔐 React Native secure storage, rebuilt with Nitro Modules ⚡️ Biometric-ready, StrongBox-aware, and metadata-rich for modern mobile apps

A hardware-backed secure storage library for React Native, rebuilt on Nitro Modules for v6. It wraps iOS Keychain and Android Keystore (with StrongBox/Secure Enclave awareness) behind a Promise API and React hooks, aimed at apps that need to store tokens or secrets gated by biometrics rather than plain AsyncStorage.

Nitro Modules gives it JSI-level calls instead of the old bridge, and the crypto design is specific rather than hand-waved: AES-GCM payloads with a recomputed HMAC-SHA256 integrity tag on every read, documented in a dedicated THREAT_MODEL.md. The hooks API (useSecureStorage, useSecret, useKeyRotation) handles cancellation on unmount and ships typed error classes with instanceof predicates instead of string-matching error codes. Key rotation is a first-class operation that transparently re-encrypts old entries on next read, which is the kind of thing most secure-storage wrappers skip entirely.

v6 is a hard break: New Architecture + react-native-nitro-modules only, so anyone on the old architecture or using Expo Go is stuck on v5 or blocked until they migrate. Windows support was dropped outright. The access-control fallback behavior ('picks the strongest supported policy') is convenient but opaque — an app that assumes StrongBox or Secure Enclave is actually in use has no easy way to verify that without calling getSupportedSecurityLevels() itself. Secure Enclave and StrongBox don't exist on simulators, so meaningful security testing requires physical devices, which the troubleshooting section confirms but doesn't solve. The 92% coverage badge is self-reported in the README rather than tied to a visible CI coverage gate.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →