PAM Native Auth
Start here
Section titled “Start here”Every PAM Native product runs on the PAM runtime. Install and verify PAM first, create a Native application, and add this package through PAM Composer:
curl -fsSL https://github.com/push-in/pam/releases/latest/download/install.sh | shpam doctorpam init my-app --template nativecd my-apppam composer require pushinbr/pam-native-authpam doctorpam native devThe package is installed through pam composer. Remove it with pam composer remove.
Vault and PKCE
Section titled “Vault and PKCE”use Pam\Native\Auth\AuthVault;use Pam\Native\Auth\Pkce;
$pkce = Pkce::generate();
(new AuthVault())->store( 'session.refresh-token', $refreshToken, function ($state, ?string $error): void {},);AuthVault stores, retrieves, and deletes credentials. Android uses a
non-exportable Keystore key with AES-256-GCM; Apple uses Keychain generic
password items and defaults to WhenUnlockedThisDeviceOnly. Pkce/PkcePair
produce cryptographically random OAuth 2.1 S256 verifier/challenge material.
CredentialAccessibility selects native policy and AuthOperationState
reports typed results.
Store short-lived sessions or refresh tokens, never user passwords. Rotate server-side and delete locally on logout/revocation. Never log credentials, PKCE verifiers, authorization codes, or token responses.
Support: PAM Native 0.6.x, Android API 26+, iOS 15+. Passkeys and interactive OAuth presentation are outside the vault contract.
Public types: AuthVault, Pkce, PkcePair, CredentialAccessibility,
AuthOperationState, and the auto-discovered AuthPluginProvider.