Kerberos single sign-on for Flutter apps on Android through
Hypergate Authenticator. This plugin wraps the
Hypergate SDK (com.hypergate:sdk on Maven
Central) so your app can authenticate against Kerberos-protected services without passwords or NTLM.
If you are planning a migration away from NTLM, start with the blog post Moving Your Android App off NTLM: Kerberos SSO with the Hypergate SDK. It covers the full integration story that this plugin implements for Flutter.
Using Cordova, Capacitor or React Native instead? See cordova-plugin-hypergate, capacitor-plugin-hypergate and react-native-hypergate.
Hypergate Authenticator holds the user's Kerberos credentials (TGT) on the device. Your app never sees a password: it asks Hypergate for a SPNEGO/Negotiate token for a given service principal (SPN) and attaches it to the request.
The plugin is Android-only.
- Android SDK platform 37 installed (the Hypergate SDK compiles against API 37); set
compileSdk = 37in your app'sandroid/app/build.gradle.kts - A device managed by an MDM/EMM/UEM (supported EMMs) with Hypergate Authenticator deployed
flutter pub add hypergate_flutterConfigure these managed configurations (app restrictions) in your MDM/EMM/UEM:
| Managed configuration | Value |
|---|---|
| Account type for HTTP Negotiate authentication | ch.papers.hypergate |
| Authentication server allowlist | * or an explicit list of domains allowed to request tokens |
In addition, your app's package name must be on the discoverability list in the Hypergate Authenticator managed configuration, otherwise token requests fail with error 101.
import 'package:hypergate_flutter/hypergate_flutter.dart';
final hypergate = HypergateFlutter();
final token = await hypergate.getToken('HTTP@securedbackend.com');
// attach to your request:
// headers: {'Authorization': 'Negotiate $token'}Do not cache the token. Request a fresh one for every API call, because a cached token may
have expired between app start and the actual request. The recommended pattern is a request
interceptor (e.g. a dio interceptor) that fetches a token per request.
| Param | Description |
|---|---|
servicePrincipal |
SPN of the target service, e.g. HTTP@securedbackend.com |
Returns the raw Negotiate token. Throws a PlatformException when Hypergate is not in
possession of a valid TGT, the device is not managed, or the app is not on the discoverability
list.
- Error 101 ("no accounts found"): the app's package name is missing from the discoverability list, or the device has no Hypergate account at all.
- Token issued but the backend returns 401: verify the SPN matches the backend's service principal and that the account has AES key material (see Kerberos RC4 removal).
A runnable example lives in example/:
cd example
flutter runMIT, see LICENSE. Questions go to support@hypergate.com.