Skip to content

hypergate-com/react-native-hypergate

Repository files navigation

Hypergate React Native Plugin

Kerberos single sign-on for React Native apps on Android through Hypergate Authenticator. This library wraps the Hypergate SDK (com.hypergate:sdk on Maven Central) so your app can authenticate against Kerberos-protected services without passwords or NTLM.

If you are planning a migration away from NTLM, start with the blog post Moving Your Android App off NTLM: Kerberos SSO with the Hypergate SDK. It covers the full integration story that this library implements for React Native.

Using Cordova or Capacitor instead? See cordova-plugin-hypergate and capacitor-plugin-hypergate.

How it works

Hypergate Authenticator holds the user's Kerberos credentials (TGT) on the device. Your app never sees a password: it asks Hypergate for a SPNEGO/Negotiate token for a given service principal (SPN) and attaches it to the request.

The library is Android-only. On iOS, getToken rejects with an "unavailable" error, so cross-platform apps can share the same code path. It is implemented as a Turbo Module (new architecture).

Requirements

  • React Native 0.76+ (new architecture)
  • Android SDK platform 37 installed (the Hypergate SDK compiles against API 37); set compileSdkVersion = 37 in your app's android/build.gradle
  • A device managed by an MDM/EMM/UEM (supported EMMs) with Hypergate Authenticator deployed

Installation

npm install react-native-hypergate

Managed configuration

Configure these managed configurations (app restrictions) in your MDM/EMM/UEM:

Managed configuration Value
Account type for HTTP Negotiate authentication ch.papers.hypergate
Authentication server allowlist * or an explicit list of domains allowed to request tokens

In addition, your app's package name must be on the discoverability list in the Hypergate Authenticator managed configuration, otherwise token requests fail with error 101.

Usage

import { getToken } from 'react-native-hypergate';

const token = await getToken('HTTP@securedbackend.com');
// attach to your request:
// headers: { 'Authorization': 'Negotiate ' + token }

Do not cache the token. Request a fresh one for every API call, because a cached token may have expired between app start and the actual request. The recommended pattern is a request interceptor that fetches a token per request.

API

getToken(servicePrincipal: string): Promise<string>

Param Description
servicePrincipal SPN of the target service, e.g. HTTP@securedbackend.com

Resolves with the raw Negotiate token. Rejects when Hypergate is not in possession of a valid TGT, the device is not managed, or the app is not on the discoverability list.

Troubleshooting

  • Error 101 ("no accounts found"): the app's package name is missing from the discoverability list, or the device has no Hypergate account at all.
  • Token issued but the backend returns 401: verify the SPN matches the backend's service principal and that the account has AES key material (see Kerberos RC4 removal).

Example app

A runnable example lives in example/:

yarn
yarn example android

Contributing

See the contributing guide to learn how to contribute to the repository and the development workflow.

License

MIT, see LICENSE. Questions go to support@hypergate.com.

About

React Native Hypergate integration to authenticate with Kerberos on Android

Resources

Code of conduct

Contributing

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages