Skip to content

hypergate-com/hypergate_flutter

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Hypergate Flutter Plugin

Kerberos single sign-on for Flutter apps on Android through Hypergate Authenticator. This plugin wraps the Hypergate SDK (com.hypergate:sdk on Maven Central) so your app can authenticate against Kerberos-protected services without passwords or NTLM.

If you are planning a migration away from NTLM, start with the blog post Moving Your Android App off NTLM: Kerberos SSO with the Hypergate SDK. It covers the full integration story that this plugin implements for Flutter.

Using Cordova, Capacitor or React Native instead? See cordova-plugin-hypergate, capacitor-plugin-hypergate and react-native-hypergate.

How it works

Hypergate Authenticator holds the user's Kerberos credentials (TGT) on the device. Your app never sees a password: it asks Hypergate for a SPNEGO/Negotiate token for a given service principal (SPN) and attaches it to the request.

The plugin is Android-only.

Requirements

  • Android SDK platform 37 installed (the Hypergate SDK compiles against API 37); set compileSdk = 37 in your app's android/app/build.gradle.kts
  • A device managed by an MDM/EMM/UEM (supported EMMs) with Hypergate Authenticator deployed

Installation

flutter pub add hypergate_flutter

Managed configuration

Configure these managed configurations (app restrictions) in your MDM/EMM/UEM:

Managed configuration Value
Account type for HTTP Negotiate authentication ch.papers.hypergate
Authentication server allowlist * or an explicit list of domains allowed to request tokens

In addition, your app's package name must be on the discoverability list in the Hypergate Authenticator managed configuration, otherwise token requests fail with error 101.

Usage

import 'package:hypergate_flutter/hypergate_flutter.dart';

final hypergate = HypergateFlutter();
final token = await hypergate.getToken('HTTP@securedbackend.com');
// attach to your request:
// headers: {'Authorization': 'Negotiate $token'}

Do not cache the token. Request a fresh one for every API call, because a cached token may have expired between app start and the actual request. The recommended pattern is a request interceptor (e.g. a dio interceptor) that fetches a token per request.

API

Future<String> getToken(String servicePrincipal)

Param Description
servicePrincipal SPN of the target service, e.g. HTTP@securedbackend.com

Returns the raw Negotiate token. Throws a PlatformException when Hypergate is not in possession of a valid TGT, the device is not managed, or the app is not on the discoverability list.

Troubleshooting

  • Error 101 ("no accounts found"): the app's package name is missing from the discoverability list, or the device has no Hypergate account at all.
  • Token issued but the backend returns 401: verify the SPN matches the backend's service principal and that the account has AES key material (see Kerberos RC4 removal).

Example app

A runnable example lives in example/:

cd example
flutter run

License

MIT, see LICENSE. Questions go to support@hypergate.com.

About

Flutter Hypergate integration to authenticate with Kerberos on Android

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages