Yubico/yubioath-flutter
63.9
Adequate · 19 September 2026
49.3k
lines of production code
Dart
with Kotlin, Python
1
measurement over time
What this system is
This system is the Yubico Authenticator, a cross-platform desktop and mobile application for managing YubiKey security tokens. It provides comprehensive capabilities for handling FIDO passkeys, OATH TOTP/HOTP credentials, YubiOTP slots, and PIV cryptographic keys across USB and NFC interfaces. The architecture relies on a shared Flutter frontend with platform-specific native layers and a background RPC helper service to facilitate secure device communication and state management.
How it got here
2021 — Foundational app shell and core architecture
22 changes.
This period established the foundational infrastructure for the Yubico Authenticator application, introducing the core data models, state management layer, and reusable UI widget library. It also implemented platform-specific initialization and build configurations for Linux, macOS, and Windows, while setting up localization and development tooling to support the new architecture.
2022 — Android launch and desktop restructuring
35 changes.
This period focused on establishing the initial Android platform implementation, including native bridges, QR scanning, and OATH management, while simultaneously restructuring the desktop application with a new RPC helper and Riverpod state management. The work also introduced foundational features for FIDO passkey management, device configuration screens, and multi-language support across both platforms.
2023–2026 — PIV and OTP feature expansion
25 changes.
This period focused on implementing foundational state management and UI layers for the PIV and OTP applications across Android and desktop platforms. The work included introducing structured exception handling, custom lint rules, and comprehensive unit tests to support these new features and improve code quality.
Features
Add custom lint rules for widget usage and initialization
The lint module now includes two new custom lint rules to enforce best practices. The 'use\_recommended\_widget' rule flags direct usage of 'TextField' and recommends using 'AppTextField' instead. The 'call\_init\_after\_creation' rule ensures that the 'init()' method is called immediately after creating an instance of 'AppTextField', preventing potential initialization errors.
lint · high confidence
Added Android Gradle wrapper scripts
The Android module now includes the Gradle wrapper scripts (gradlew and gradlew.bat) along with a .gitignore file to exclude generated build artifacts and sensitive keystore files. This allows developers to build and run the Android application without manually installing Gradle, ensuring consistent build environments across different machines.
android · high confidence
Added build and artifact collection scripts for Android APKs
New shell scripts have been added to the android/scripts directory to automate the Android build and release process. The build.sh script generates third-party licenses and compiles the Flutter app into split-per-ABI and universal APKs. The collect-artifacts.sh script gathers the resulting APKs (for arm64-v8a, armeabi-v7a, x86\_64, and universal variants), mapping files, and native library symbol archives into a dedicated artifacts directory, facilitating release packaging.
android/scripts · high confidence
Added systray icon template
A new EPS file (systray-template.eps) has been added to the resources/icons directory, providing the vector template for the system tray icon.
resources/icons · high confidence
Android PIV state management implementation
The Android-specific PIV state notifier has been implemented to manage device state and handle PIN/PUK operations. This change introduces a new \AndroidPivStateNotifier\ class that listens to native events via an \EventChannel\ to update the PIV state asynchronously. It provides concrete implementations for core PIV operations including resetting the device, authenticating with a management key, verifying, changing, and unblocking PINs and PUKs, as well as setting management keys. The implementation bridges the Flutter UI layer with the underlying Android platform methods to ensure accurate state reflection and error handling for PIN-related failures.
lib/android/piv · high confidence
Android app now supports NFC bypass touch, clipboard, and locale preferences
The Android native layer introduces a new AppPreferences class to manage user settings for NFC interactions, including options to bypass the physical touch requirement, silence NFC discovery sounds, and automatically copy OTP/password content to the clipboard. It also persists the last used app section and the preferred UI locale. These preferences are consumed by the new NdefActivity, which handles NFC intents by copying OTP data to the clipboard and/or launching the main app, and by the MainViewModel, which uses the saved locale and section context to initialize the app state.
app · high confidence
Android logging now supports retrieving buffered logs via Flutter
The Android logging layer has been refactored to use SLF4J/Logback and introduces a new mechanism for Flutter to access recent log entries. A new BufferAppender captures the last 1,000 log messages in memory, and the FlutterLog component exposes a 'getLogs' method via the platform channel, allowing the Flutter app to retrieve this buffer. This change also separates Flutter-specific logging handling from native Android logging and simplifies the core Log API.
android/app/src/main/kotlin/com/yubico/authenticator/logging · high confidence
Desktop FIDO state management and RPC session handling
This change introduces the core state management logic for FIDO operations on the desktop platform. It establishes a dedicated RPC session layer that automatically selects the appropriate USB interface (FIDO or CCID) for CTAP communication and handles session persistence. The state notifier manages device-specific behaviors, such as caching PINs to unlock devices and automatically refreshing state when the application window becomes active. It also implements error handling for authentication requirements and device resets, ensuring the UI remains synchronized with the hardware token's status.
lib/desktop/fido · high confidence
Desktop PIV state management and authentication logic
The desktop PIV module now includes a dedicated state management implementation (state.dart) that handles device sessions, PIN and management key authentication, and user interaction prompts (such as touch requests). This change introduces logic to verify credentials, manage session lifecycles, and handle authentication errors, forming the core backend state for PIV operations on the desktop platform.
lib/desktop/piv · high confidence
Establishes development tooling and localization infrastructure
This change introduces the foundational tooling for the project, including a pre-commit configuration that enforces code formatting and linting for both Flutter (Dart) and Python (Ruff, mypy) codebases. It adds a comprehensive localization pipeline, featuring scripts to pull translations from Crowdin, reformat ARB files, and update Android string resources, alongside configuration files for the Crowdin integration and Flutter's l10n system. Additionally, it provides build helper scripts for Windows and macOS, a version management script, and a new Apache 2.0 license file.
(repo-wide) · high confidence
Initial PIV module implementation with certificate and key management
The Android app now includes a new PIV (Personal Identity Verification) module that enables users to manage cryptographic keys and certificates on YubiKeys. This update introduces core capabilities including generating keys and self-signed certificates, importing and exporting key material in PEM and DER formats, and managing PINs, PUKs, and management keys. The implementation supports RSA, EC, and Ed25519 algorithms, handles Pivman data for derived keys, and provides strict validation for X.509 subject Distinguished Names. It also includes utilities for parsing key material and managing smart card connections over both USB and NFC.
android/app/src/main/kotlin/com/yubico/authenticator/piv · high confidence
Initial implementation of PIV manager data structures
Added new Kotlin classes in the PIV data package to handle PIV manager-specific data structures. PivmanData now parses and serializes TLV-encoded fields for flags (including PUK blocked and management key protected states), salt, and PIN timestamp, while PivmanProtectedData handles the storage and retrieval of protected key material. DataExt.kt provides utility functions for ISO date formatting and X.509 certificate fingerprinting to support these data operations.
android/app/src/main/kotlin/com/yubico/authenticator/piv/data · high confidence
Initial localization infrastructure and language support
The application now supports multiple languages, with initial translation files added for Bulgarian, Czech, German, Greek, English, Spanish, French, Hebrew, Hungarian, and Italian. This change introduces the \lib/l10n\ directory containing \.arb\ resource files and a README explaining that translations are managed via Crowdin, enabling users to see the interface in their preferred language.
lib/l10n · high confidence
Initial release of Android QR code scanner plugin
This change introduces the \qrscanner\_zxing\ Flutter plugin for Android, enabling QR code scanning via the device camera and from image data (bitmaps). The plugin uses the ZXing library and CameraX, exposing a \QRScannerZxingView\ widget for live scanning with permission handling callbacks, and a \scanBitmap\ API for decoding static images. It is an Android-only plugin (v1.0.0) that communicates with the native layer via method channels.
_android/flutter\_plugins/qrscanner\zxing · high confidence
Introduce Android platform-specific implementation layer
This change adds the initial Android platform implementation for the Yubico Authenticator app, establishing the native bridge and state management required for the mobile experience. It introduces a new \lib/android\ directory containing files for device discovery (\devices.dart\), app initialization (\init.dart\), and platform-specific state providers (\state.dart\, \window\_state\_provider.dart\). The implementation includes a \MethodChannel\ (\app\_methods.dart\) to handle native calls such as NFC state monitoring, camera availability, and clipboard operations, while \logger.dart\ redirects application logs to Android's native logcat. Additionally, it provides Android-specific state notifiers for OTP (\otp/state.dart\) and FIDO/PIV features, ensuring that platform-specific behaviors like NFC overlay handling and section switching are correctly wired into the Flutter UI.
lib/android · high confidence
Introduce FIDO passkey management and state infrastructure
This change adds the foundational state management and data models for FIDO passkey operations within the application. It introduces Riverpod AsyncNotifiers to manage device state, PIN handling, credential lists, and fingerprint data, enabling features such as passkey search, layout switching, and PIN/PUK error handling. The update also defines the core data structures for FIDO state, credentials, and fingerprints, along with UI action keys to support the new passkey management interface.
lib/fido · high confidence
Introduce ManagementScreen for configuring YubiKey capabilities and modes
Added a new ManagementScreen view that allows users to configure USB and NFC capabilities (such as OTP and CCID) and interface modes for connected YubiKeys. The screen includes UI components for toggling capabilities via filter chips, selecting USB interfaces, and managing lock codes, providing a centralized interface for key configuration.
lib/management/views · high confidence
Introduce OTP application with slot configuration models and state management
This change adds the foundational data models and state management layer for the new OTP (One-Time Password) application. It introduces structured models for YubiKey OTP slots (including HOTP, Challenge-Response, Static Password, and YubiOTP configurations) and their associated options, enabling the app to represent and persist slot states. Additionally, it provides the Riverpod-based state providers and abstract notifier interface required to manage device-specific OTP configurations, such as generating passwords, swapping slots, and handling access codes.
lib/otp · high confidence
Introduce Yubico Authenticator Helper RPC service
This change introduces the Yubico Authenticator Helper, a new background service that exposes YubiKey management capabilities via an RPC interface. It provides structured access to FIDO2, PIV, OATH, and YubiOTP applications, allowing connected clients to perform operations such as credential management, PIN verification, and device configuration. The helper handles device discovery, connection switching, and secure storage of sensitive keys, serving as the backend bridge for desktop applications interacting with YubiKeys.
helper/helper · high confidence
Introduce Yubico Authenticator Helper as a standalone Python application
The Yubico Authenticator Helper is now a distinct Python component, replacing the previous build setup. It includes a main entry point (\authenticator-helper.py\) that supports both standard input/output pipes and TCP socket communication, with explicit UTF-8 encoding configured for the pipe mode. A PyInstaller spec file (\authenticator-helper.spec\) defines the build process, enabling the creation of a standalone executable that targets Windows 10/11 and builds a universal2 binary on macOS when the host Python is universal. The helper also ships with a \shell.py\ module providing an interactive RPC shell for debugging and manual interaction with the helper's API, alongside a \uv.lock\ file managing its Python dependencies.
helper · high confidence
Introduce core data models and application state management
The lib/core directory now provides the foundational data structures and state management layer for the application. New models define device capabilities and identity, including the Transport (USB/NFC), UsbInterface, and UsbPid enums to identify specific YubiKey hardware variants, as well as a Version model with strict range assertions for firmware versioning. Additionally, a new state management layer has been added, featuring an ApplicationStateNotifier base class for async state handling, a hierarchical Feature flag system for enabling/disabling capabilities, and a LayoutNotifier to persist user interface layout preferences.
lib/core · high confidence
Introduce custom icon pack support with caching and import UI
Users can now import custom icon packs (ZIP files containing SVG or raster images) via a new dialog that supports drag-and-drop, replace, and removal. The system includes a dual-layer cache (memory and file-system) to store and quickly load icon assets, and a dedicated widget that renders the matched custom icon or falls back to the default, ensuring smooth display of issuer-specific branding.
_lib/app/icon\provider · high confidence
Introduce desktop management state handling
Added a new state management layer for the desktop application that handles device configuration and mode setting. This implementation establishes a session with the device, attempts to connect via preferred USB interfaces (CCID, OTP, FIDO), and exposes methods to set device modes, write configurations (including lock codes), and perform device resets.
lib/desktop/management · high confidence
Introduce desktop-specific device polling, RPC session management, and system tray integration
The desktop application now manages USB and NFC device discovery through dedicated state notifiers that poll the Yubico Authenticator Helper at defined intervals, updating the UI when device states change. A new RPC session layer handles communication with the helper process, including JSON response parsing, error handling, and Windows privilege elevation. Additionally, a system tray component is added to provide quick access to favorite OATH credentials and manage application visibility, while window state and clipboard interactions are adapted for desktop environments like Wayland.
lib/desktop · high confidence
Introduce management state and device info models
The management module now includes a new \ManagementStateNotifier\ that exposes device information via an async provider, allowing the UI to react to device state changes. This is supported by new data models (\DeviceInfo\, \DeviceConfig\, \VersionQualifier\) and enums (\FormFactor\, \Capability\, \ReleaseType\) that define the structure of device data, including FIPS status, supported capabilities, and version qualifiers. The state notifier provides methods to write device configuration, set device mode, and perform a device reset.
lib/management · high confidence
Introduce new core UI components and page structure
The application's view layer has been restructured with the introduction of several new foundational widgets and pages. \AppPage\ now serves as the primary layout container, managing responsive navigation states (drawer, rail, and sidebar) and handling scroll interactions. \ActionList\ and \ActionListItem\ provide a standardized way to display actionable items with support for feature flags and keyboard intents, while \AppListItem\ offers a versatile list tile with popup menu support. Error handling is centralized in \AppFailurePage\ and \DeviceErrorScreen\, which display specific messages for connection issues, NFC restrictions, and Windows elevation requirements. Additionally, \DevicePickerContent\ handles the selection of connected devices, and \FsDialog\ provides a consistent fullscreen dialog pattern.
lib/app/views · high confidence
Introduces platform-specific window state management for desktop
The application now uses a dedicated \WindowManagerHelper\ to persist and restore window size and position across sessions. This implementation respects platform constraints: on Linux, it manages window size but defers positioning to the window manager; on macOS, it saves and restores the specific display and local offset to handle multi-monitor setups; and on Windows, it accounts for display scaling factors and validates that the window remains within visible display bounds. A new \defaults.dart\ file defines standard window dimensions (1100x700) and size constraints (300x300 to 4096x4096) used by the helper.
_lib/desktop/window\_manager\helper · high confidence
Linux desktop integration support
Yubico Authenticator on Linux now includes a shell script and desktop file to integrate the application with the user's desktop environment. Users can run the provided integration script to install a desktop entry (com.yubico.yubioath.desktop) that allows launching the app from application menus, while also ensuring any legacy desktop files are removed during the process.
resources/linux · high confidence
Native YubiOTP support on Android
The Android app now supports configuring and reading YubiOTP credentials (static passwords, HOTP, HMAC-SHA1, and Yubico OTP) directly on the device. This change introduces the core Kotlin implementation for OTP management, including a connection helper that manages USB and NFC device sessions, a manager that exposes OTP operations via the Flutter method channel, and utilities for generating random passwords and formatting CSV exports. It also ports the complete set of keyboard layout scancode maps (US, UK, DE, FR, IT, BEPO, NORMAN, MODHEX, and DE-CH) from the desktop Python implementation to ensure consistent character encoding and decoding across platforms.
android/app/src/main/kotlin/com/yubico/authenticator/otp · high confidence
New Home screen with device status, FIPS indicators, and label management
The app now features a dedicated Home screen that displays the connected YubiKey's name, serial number, and enabled capabilities. A new FIPS legend clarifies shield icons for FIPS-capable versus FIPS-approved status. Users can manage device labels via a new dialog that enforces a 20-byte limit and provides real-time byte counting. The screen also includes action buttons for toggling applications/interfaces and performing a factory reset, with proper navigation handling to ensure dialogs close correctly before opening.
lib/home · high confidence
New NFC overlay UI components for Android
This change introduces the visual layer for the NFC overlay on Android, adding dedicated widgets to display status, progress, and actions. The new \NfcContentWidget\ provides a standardized layout for titles, subtitles, and icons, while \NfcOverlayWidget\ manages the overlay container, including a close button and positioning. Specific progress indicators (\NfcIconProgressBar\ and \UsbIconProgressBar\) and status icons (success, failure, USB, contactless) are now available to give users clear visual feedback during NFC interactions.
lib/android/overlay/nfc/views · high confidence
New PIV management dialogs and action handlers
The PIV view layer now includes dedicated UI components for managing keys and certificates, introducing new dialogs for generating keys, importing files, moving keys, and deleting certificates or keys. Authentication and PIN/PUK management are handled through updated dialogs that support default key usage, hex format validation, and visibility toggles. The \key\_actions.dart\ file provides a centralized action list for managing PIN, PUK, and management keys, including warnings for default credentials and blocked states.
lib/piv/views · high confidence
New YubiKey management capabilities via Flutter method channel
The Android app now exposes a new \android.management.methods\ channel that allows the Flutter layer to perform device management operations. Users can now reset a YubiKey to factory defaults, update device configuration settings (such as interface modes and timeouts), and change the device lock code. These operations are handled by the new \ManagementManager\ and \ManagementConnectionHelper\, which manage the connection lifecycle and ensure pending actions are cancelled if the device is disconnected or changed during the operation.
android/app/src/main/kotlin/com/yubico/authenticator/management · high confidence
New reusable widget library for forms, dialogs, and UI components
This release introduces a suite of new, reusable widgets in the \lib/widgets\ directory to standardize the user interface. \AppTextField\ and \AppInputDecoration\ provide consistent form fields with built-in support for required-field indicators and screen-reader announcements for validation errors. \BasicDialog\ and \ResponsiveDialog\ offer accessible, focus-managed dialog experiences that adapt to screen size. Additional components include \FileDropTarget\ and \FileDropOverlay\ for drag-and-drop file handling, \FlexBox\ for switching between list and grid layouts, \ChoiceFilterChip\ for compact selection menus, and \InfoPopupButton\ for contextual help. The update also includes \CircleTimer\ for OATH code progress, \DelayedVisibility\ for staged content rendering, \EnsureFocusVisible\ for Android keyboard handling, and \Toast\ for user notifications.
lib/widgets · high confidence
OATH module foundational models and state management
The OATH module now includes its core data models and state management infrastructure. This introduces the \OathCredential\ and \CredentialData\ models, which support OATH-TOTP and OATH-HOTP types with configurable hash algorithms (SHA-1, SHA-256, SHA-512), digits, and periods. The module also defines the \OathState\ to track device version, lock status, and keystore state, alongside Riverpod providers for managing credential lists, search filters, and layout preferences (list, grid, or mixed).
lib/oath · high confidence
OTP slot configuration dialogs and access code handling
The OTP view layer now includes dedicated dialogs for configuring Challenge-Response, HOTP, Static Password, and YubiOTP slots, along with a new Access Code dialog for devices requiring authentication. These dialogs enforce format and length validation, support keyboard layout selection for static passwords, and allow exporting YubiOTP credentials to a file. An overwrite confirmation step is added before modifying configured slots, and the Access Code dialog is reused across configuration and deletion actions to handle access-code-required errors gracefully.
lib/otp/views · high confidence
PIV module foundational data models and state management introduced
This change establishes the core data structures and state management layer for the PIV feature. It introduces typed models for PIV slots (including authentication, signature, and retired slots), key types (RSA, ECC, Ed25519, X25519), and metadata (PIN/PUK policies, touch policies, management key types). It also defines the Riverpod state providers (\pivStateProvider\, \pivSlotsProvider\) that expose device state and slot operations such as generate, import, export, delete, and move keys, along with associated UI keys for testability and localization.
lib/piv · high confidence
Persistent PIN/UV Auth Token storage and improved FIDO connection handling
The FIDO module now supports persistent PIN/UV authentication tokens (PPUAT) by introducing a new storage mechanism that encrypts tokens using the Android KeyStore (AES/GCM) and saves them to a local file, allowing tokens to survive app restarts. This is accompanied by a new FidoConnectionHelper that manages FIDO sessions over USB and NFC, including proper cancellation handling and device info updates, and a FidoPinStore for managing PINs in memory with secure zeroing upon replacement.
android/app/src/main/kotlin/com/yubico/authenticator/fido · high confidence
QR scanner example app now supports scanning from image files
The example application for the qrscanner\_zxing plugin has been updated to allow users to scan QR codes from static image files in addition to live camera feeds. A new 'Scan from file' button has been added to the main page, which uses the file\_picker package to let users select PNG, JPG, GIF, or WebP images; the selected image data is then passed to the scanner to detect and display any embedded QR codes. The app also includes a custom cutout overlay for the camera view and removes page transition animations when opening the scanner.
_android/flutter\_plugins/qrscanner\zxing/example · high confidence
QR scanner now supports decoding from static image data
The Android QR scanner plugin now accepts raw image bytes for decoding, in addition to live camera scanning. Users can pass image data (e.g., from a gallery or screenshot) to the scanner, which attempts to decode QR codes using multiple sample sizes to improve reliability on low-resolution or compressed images.
_android/flutter\_plugins/qrscanner\zxing/android/src/main/kotlin · high confidence
Architecture
Refactored OATH account management views and actions
The OATH account management UI has been restructured into a set of dedicated view components (account\_dialog, account\_helper, account\_icon, account\_list, account\_view, actions, add\_account\_page, add\_multi\_account\_page, delete\_account\_dialog, key\_actions, and manage\_password\_dialog). This change consolidates account display logic, action handling (copy, refresh, pin, rename, delete), and account creation flows into a more modular architecture, improving code organization and maintainability for the OATH credential management experience.
lib/oath/views · high confidence
Behavioural changes
Added support for system tray, URL launching, and window management on Windows
The Windows build now registers several new plugins, enabling features such as system tray integration (tray\_manager), opening external links (url\_launcher\_windows), managing window focus and visibility (window\_manager), retrieving screen information (screen\_retriever\_windows), handling desktop file drops (desktop\_drop), and displaying local notifications (local\_notifier). Additionally, the build system now supports FFI plugins (such as jni) and uses a configurable target platform variable for better compatibility with older Flutter tool versions.
windows/flutter · high confidence
Android FIDO state management and platform integration
This change introduces the Android-specific state management layer for FIDO operations, replacing or augmenting previous implementations with a new \AndroidFidoStateNotifier\. It establishes the core logic for handling FIDO PIN operations (setting, unlocking, and handling violations), device reset flows over NFC/USB, and enterprise attestation settings. The implementation relies on Flutter's \EventChannel\ to listen to native Android session state updates and uses a method channel notifier to invoke platform-specific actions, ensuring proper error handling for cancellations and platform exceptions.
lib/android/fido · high confidence
Android Management state handling via Method Channel
The Android management module now uses a dedicated \AndroidManagementStateNotifier\ that communicates with the native Android layer through a \MethodChannel\. This change enables users to configure device modes, write device configurations (including lock codes), and perform device resets directly from the app, with the state notifier automatically refreshing the attached devices list after configuration changes.
lib/android/management · high confidence
Android NFC overlay UI and state management refactored
The Android NFC overlay has been rewritten to use a Riverpod-based event-driven architecture, introducing dedicated state models and notifiers to manage the overlay lifecycle. This change improves the user experience by ensuring the overlay correctly handles landscape orientation constraints and waits for key removal during NFC actions, while also simplifying the underlying method channel communication for more reliable UI updates.
lib/android/overlay/nfc · high confidence
Android OATH state management and deep link handling
The Android OATH module now uses a dedicated state notifier that listens to native session events via an EventChannel to keep the UI in sync with the device's OATH state. It also introduces a method channel handler for 'otpauth://' deep links, allowing users to add credentials directly from external sources, and refactors error handling to use specific exceptions like CancellationException for better user feedback during unlock and reset operations.
lib/android/oath · high confidence
Build-time permission guard and updated ProGuard rules
The release build process now includes a new permission guard that inspects the merged manifest and fails the build if the APK or AAB requests any permission not explicitly allowed (currently NFC, HIDE\_OVERLAY\_WINDOWS, and CAMERA), preventing silent permission creep from dependencies. Additionally, initial ProGuard rules have been added to preserve kotlinx-serialization components, Yubico logging classes, Bouncy Castle cryptography classes, and exception class names, ensuring these critical runtime behaviors are not broken by code shrinking.
android/app · high confidence
Desktop OATH state management migrated to Riverpod and RPC
The OATH state management for the desktop application has been rewritten to use Riverpod providers and an RPC-based session layer. This change introduces a new \DesktopOathStateNotifier\ that handles device communication via \RpcNodeSession\, manages lock keys in memory using a dedicated \StateNotifier\, and implements error handling for authentication requirements. Users will experience this as the underlying engine for OATH operations on desktop, replacing the previous implementation with a more robust, provider-driven architecture.
lib/desktop/oath · high confidence
Desktop OTP state management with interface fallback
The desktop OTP module now includes a state notifier that manages YubiOTP interactions via RPC. It implements a fallback mechanism that prefers the CCID interface for devices with firmware version 5.4.3 or newer, while falling back to the OTP interface for older devices. This state layer exposes core OTP capabilities to the desktop client, including slot configuration, static password generation, and credential deletion.
lib/desktop/otp · high confidence
Enable desktop-specific capabilities via new plugin registrations
The Linux build now registers several desktop-oriented plugins, enabling features such as system tray management, window state control, URL launching, screen retrieval, local notifications, and file drop support. This is achieved by updating the generated plugin registrant and CMake configuration to include desktop\_drop, local\_notifier, screen\_retriever\_linux, tray\_manager, url\_launcher\_linux, and window\_manager, while also adding support for FFI plugins like jni.
linux/flutter · high confidence
Example app Android configuration updated for Flutter v2 embedding
The Android configuration for the qrscanner\_zxing example app has been updated to support Flutter's v2 Android embedding. This includes adding the required \flutterEmbedding\ meta-data to the main manifest, creating standard launch splash screens and themes for both light and dark modes, and setting up the necessary \App\ and \MainActivity\ Kotlin classes. Additionally, debug and profile manifests now explicitly declare the INTERNET permission to support Flutter tooling features like hot reload and debugging.
_android/flutter\_plugins/qrscanner\zxing/example/android · high confidence
Improved YubiKey connection handling and device detection on Android
The Android app now features more robust handling of YubiKey connections and device identification. A new helper simplifies connection management using Kotlin coroutines, while the device info logic has been expanded to probe multiple transport layers (SmartCard, FIDO, OTP) and identify unrecognized or restricted NFC devices. The app also includes a new mechanism to wait for USB reclaim periods, ensuring smoother interactions with security keys, and introduces a state dispatcher to better track NFC activity states.
android/app/src/main/kotlin/com/yubico/authenticator/yubikit · high confidence
Introduce structured app shell, localization, and keyboard shortcuts
The application now uses a centralized \YubicoAuthenticatorApp\ entry point that integrates Riverpod for state management and Flutter's localization delegates for multi-language support, including a fallback to English for incomplete translations. A new keyboard shortcut system (Shortcuts/Intents) is implemented, providing platform-aware global shortcuts (e.g., Cmd/Ctrl+W to hide, Cmd/Ctrl+B for navigation) and a dedicated shortcuts help dialog. The UI now supports dynamic theming with light/dark modes and custom primary colors, while a \LogWarningOverlay\ displays warnings for sensitive logging or screen recording permissions. Additionally, new models define device nodes (USB/NFC), key customization, and feature flags to control section availability.
lib/app · high confidence
Linux build updates: branding, window sizing, and security hardening
The Linux application now uses the binary name 'authenticator' and the application ID 'com.yubico.yubioath', with the window title updated to 'Yubico Authenticator'. The default window size has been adjusted to 1100x700 pixels, and a minimum width constraint of 300 pixels has been enforced. Additionally, the build process now includes security hardening flags (such as stack protector, PIE, and RELRO) and installs helper scripts and support files to improve desktop integration.
linux · high confidence
MacOS app renamed to Yubico Authenticator with CocoaPods and Swift Package integration
The MacOS application bundle has been renamed from 'yubico\_authenticator' to 'Yubico Authenticator'. The Xcode project configuration has been updated to integrate CocoaPods dependencies (adding Pods\_Runner.framework and associated build phases) and Swift Package Manager support (FlutterGeneratedPluginSwiftPackage). Additionally, a 'helper' resource folder is now included in the app bundle resources.
macos/Runner.xcodeproj · high confidence
Native Android infrastructure for YubiKey interaction and app context management
The Android native layer has been refactored to introduce dedicated managers for handling YubiKey device connections and app state. A new ActivityUtil class allows the app to dynamically enable or disable system-level USB and NFC discovery intents, improving control over when the app launches upon device attachment. An AppContextManager hierarchy (including HomeContextManager) now handles device-specific logic, ensuring that interactions are processed correctly based on the current app section. Additionally, a new AppContextChannel facilitates communication with the Flutter UI to synchronize the active context, while utility classes like CompatUtil and ClipboardUtil ensure robust handling of Android SDK version differences and secure clipboard operations.
android/app/src/main/kotlin/com/yubico/authenticator · high confidence
New Android device management and fallback handling
The Android app now uses a dedicated DeviceManager to coordinate YubiKey connections via USB and NFC, including lifecycle-aware cleanup of device data when the app is paused or a USB device disconnects. It introduces robust fallback logic for unknown or restricted devices, providing specific Info objects for OATH, FIDO2, NFC-restricted, and SCP11b-incompatible scenarios to ensure the app can gracefully handle devices it cannot fully identify or communicate with.
android/app/src/main/kotlin/com/yubico/authenticator/device · high confidence
OATH module restructured with new session management and Steam support
The OATH module has been significantly refactored to improve state management and add new capabilities. A new OathSession model and KeyManager now handle persistent and in-memory storage of access keys, allowing for better handling of remembered unlock states. The OathManager has been rewritten to use Kotlin coroutines and lifecycle-aware observers, ensuring that credential refreshes and pending actions are correctly managed during app pauses and context switches. Additionally, native support for Steam TOTP codes has been added, and the module now includes an AppLinkMethodChannel to handle OTP authentication links via URI intents.
android/app/src/main/kotlin/com/yubico/authenticator/oath · high confidence
QR scanner now uses CameraX with improved orientation and permission handling
The Android QR scanner implementation has been migrated to use the CameraX library, replacing the previous camera API. This change introduces more robust handling of camera permissions and ensures the scanner view correctly adapts to device rotation by manually updating the image analysis target rotation. The scanner also preserves its connection state when paused and resumes properly, reducing errors related to camera lifecycle management.
_android/flutter\_plugins/qrscanner\zxing/android/src · high confidence
Redesigned Android QR scanner with file import and new UI
The Android QR scanner now features a redesigned interface with a rounded cutout overlay and status indicators (scanning, success, error). Users can now scan QR codes from image files (PNG, JPG, GIF, WebP) via a new 'Read from file' option, in addition to live camera scanning. The scanner also supports manual entry and handles camera permission requests more gracefully, including re-checking permissions when the app resumes.
_lib/android/qr\scanner · high confidence
Redesigned FIDO passkey and fingerprint management interface
The FIDO management experience has been overhauled with new dedicated screens for Passkeys and Fingerprints, replacing the previous unified view. Users can now manage credentials and biometric keys through a structured action list, with specific dialogs for adding, renaming, and deleting fingerprints, as well as managing PINs and enterprise attestation settings. The interface includes improved error handling for PIN entry, visual feedback during fingerprint capture, and clearer status indicators for device states like PIN blocking or required PIN changes.
lib/fido/views · high confidence
Replace Flutter template with Yubico Authenticator app shell and platform-specific initialization
The application entry point (lib/main.dart) has been replaced with a production-ready startup sequence that initializes platform-specific logic (Android or Desktop) before launching the app, and displays a new ErrorPage if initialization fails. This change introduces a dedicated theme configuration (lib/theme.dart) enabling Material 3 styling with consistent focus indicators and a centralized version file (lib/version.dart) for build tracking.
lib · high confidence
Simplified macOS menu bar by removing standard items
The macOS application menu has been streamlined by removing the 'About', 'Preferences', and 'Edit' menu items (including Undo, Redo, Cut, Copy, Paste, Find, Spelling, and Substitutions) from MainMenu.xib. Users will no longer see these standard options in the app menu bar, resulting in a cleaner interface with only the 'Services' menu remaining in that section.
macos/Runner/Base.lproj · high confidence
Structured exception handling for CTAP and APDU errors
The application now introduces specific exception classes (ApduException, CancellationException, CtapException, NoDataException, TagLostException) to replace generic error handling. A new PlatformException decoder extension automatically translates platform-level errors into these domain-specific types by parsing error codes and messages, allowing the UI and business logic to handle NFC tag loss, CTAP protocol errors, and APDU status words distinctly rather than swallowing or displaying raw platform exceptions.
lib/exception · high confidence
Update macOS app identity and fix file permissions
The macOS app's identity has been updated: the display name is now "Yubico Authenticator", the bundle identifier is set to com.yubico.yubioath, and the copyright notice reflects Yubico. Additionally, the executable permission bit has been removed from the configuration files (AppInfo.xcconfig, Debug.xcconfig, Release.xcconfig, Warnings.xcconfig) to ensure they are treated as standard data files rather than scripts.
macos/Runner/Configs · high confidence
Updated Xcode scheme for Yubico Authenticator with GPU validation and Flutter preparation
The macOS build scheme for the Yubico Authenticator app has been updated to target Xcode 15.10 and renamed from 'yubico\_authenticator.app' to 'Yubico Authenticator.app'. A pre-action script has been added to prepare the Flutter framework before building, and GPU validation mode is now enabled during debugging to assist with graphics-related issues.
macos/Runner.xcodeproj/xcshareddata · high confidence
Updated macOS release process with notarization and sandbox entitlements
The macOS release workflow has been updated to support both standalone and App Store distribution. For standalone releases, the script now uses \notarytool\ for notarization and staples the application and DMG, while also removing the quarantine attribute. The helper binary is now signed with specific entitlements (\helper.entitlements\ for standalone, \helper-sandbox.entitlements\ for App Store) that define access to smartcard and USB devices, or inherit sandbox permissions. This change ensures compliance with modern macOS security requirements for distribution.
macos · high confidence
Windows installer now includes license agreement and high-DPI support
The Windows release process now generates an MSI installer that requires users to accept a license agreement before installation, and the application executable is configured to support per-monitor high DPI awareness for better display on modern screens. The release script also ensures that all DLLs are properly signed before building the installer.
resources/win · high confidence
Windows runner: dark mode support, single-instance enforcement, and UI refinements
The Windows application now respects the system's dark/light theme preference, automatically applying dark mode decorations when the OS setting is dark and updating dynamically if the theme changes. Launching the app while it is already running will now bring the existing window to the foreground instead of starting a second instance. The default window size has been adjusted to 1100x700 pixels, and the window title and metadata have been updated to 'Yubico Authenticator'. Additionally, the build process now copies a helper executable to the output directories and includes the DWM API library to support the new theme handling.
windows/runner · high confidence
macOS app behavior and configuration updates
The macOS app now keeps running in the background after the main window is closed, rather than terminating immediately. The window is also hidden during the initial launch sequence to prevent a flash of the UI. Additionally, the app category is set to 'Utilities' in the Info.plist, and several security entitlements (including USB, smartcard, file access, and code signing exceptions) have been added to both Debug and Release profiles to support broader device and file interactions.
macos/Runner · high confidence
Test coverage
Added platform integration and exception handling tests; removed obsolete widget test; Added tests for OperationContext enum alignment; Added unit tests for OATH key management, model state, and Steam code generation; Added unit tests for OTP configuration and keyboard layout helpers; Added unit tests for PIV key material parsing and X.500 DN validation; Added unit tests for SkyHelper device info logic; Added unit tests for device configuration and capability serialization; Added unit tests for the QR Scanner ZXing plugin; New integration test suite for YubiKey applications and settings.
Dependencies
Android build system migration and YubiKit 3.2.0 upgrade
The Android build configuration has been migrated to the declarative plugins block and updated to use Kotlin 2.3.21, Android Gradle Plugin 9.2.1, and compile/target SDK 37. The app now depends on YubiKit version 3.2.0, which includes the new support module alongside core, management, oath, fido, piv, and yubiotp. A new license collection script automatically aggregates third-party licenses from the OSS Licenses Plugin and ZXing into a JSON file for distribution. Additionally, the helper tool's Python dependencies have been updated to yubikey-manager 5.9.1, fido2 2.2.0, and zxing-cpp 3.0.0.
(dependencies) · high confidence
Updated Gradle wrapper to version 9.6.1
The Android build system now uses Gradle 9.6.1 for executing builds, replacing the previous wrapper configuration. This ensures that the project relies on a specific, modern version of the Gradle build toolchain.
_android/flutter\_plugins/qrscanner\zxing/android/gradle, android/gradle · high confidence
Updated macOS Flutter plugin registrations and build configuration
The macOS build configuration now includes CocoaPods support by referencing the Pods xcconfig files and adding the Pods project to the workspace. Additionally, the Flutter plugin registry has been updated to register several new native plugins, including desktop\_drop, file\_picker, local\_notifier, screen\_retriever\_macos, shared\_preferences\_foundation, tray\_manager, url\_launcher\_macos, and window\_manager, enabling their respective features within the macOS application.
macos/Flutter · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 64.
Lenses
- Code Health 83
- Architecture 98
- Maturity 47
- Readiness 73
- Security 78
- Domain Modelling 100
Changes since last survey
- 300 commits — 242 feature/other, 58 fixes
By area
- (repo) — 72 commits
- android/app — 44 commits
- (root) — 34 commits
- .github/workflows — 25 commits
- lib/app — 18 commits
- lib/l10n — 16 commits
- android/flutter_plugins — 15 commits
- lib/desktop — 15 commits
- lib/otp — 7 commits
- lib/android — 6 commits
- lib/piv — 6 commits
- resources/win — 6 commits
- lib/fido — 5 commits
- lib/widgets — 5 commits
- lib/home — 4 commits
- helper/pyproject.toml — 3 commits
- helper/uv.lock — 3 commits
- macos/Podfile.lock — 3 commits
- .github/scribe-sign-exe-dll.yml — 2 commits
- android/build.gradle — 2 commits
Notable commits
- fix: Fix PIN error handling based on PPUAT presence
- fix: Fix build with :app:debugOssLicensesTask
- fix: Fix clearing of error texts and ensure submit buttons are not disabled
- fix: Fix color on generic device image
- fix: Fix error text logic in FIDO PIN entry form
- fix: Fix focus when changing devices
- fix: Fix null-aware element
- fix: Merge branch 'main' into adamve/fix/2036_window_not_displaying
- fix: Merge branch 'main' into adamve/fix/2054_oath_timer
- fix: Merge branch 'main' to adamve/fix/android_crashes
- fix: android deps bump + migration fixes
- fix: chore: revert NEWS
- fix: ci: fix Flutter hooks in linked worktrees
- fix: fix default condition
- fix: fix invalid window bounds on startup
- fix: fix(android): Move blocking I/O off main thread
- fix: fix(android): activate context manager on setup
- fix: fix(android): avoid unsafe casts in bindUseCases
- fix: fix(android): clean up camera objects
- fix: fix(android): clean up on cancellation
- …and 280 more
Architecture
- 0 containers · 2 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Yubico/yubioath-flutter was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b4eca6a3888bf504cb991b1898ba8542109ded4f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.