Kerberos single sign-on for React Native apps on Android through
Hypergate Authenticator. This library wraps the
Hypergate SDK (com.hypergate:sdk on Maven
Central) so your app can authenticate against Kerberos-protected services without passwords or NTLM.
If you are planning a migration away from NTLM, start with the blog post Moving Your Android App off NTLM: Kerberos SSO with the Hypergate SDK. It covers the full integration story that this library implements for React Native.
Using Cordova or Capacitor instead? See cordova-plugin-hypergate and capacitor-plugin-hypergate.
Hypergate Authenticator holds the user's Kerberos credentials (TGT) on the device. Your app never sees a password: it asks Hypergate for a SPNEGO/Negotiate token for a given service principal (SPN) and attaches it to the request.
The library is Android-only. On iOS, getToken rejects with an "unavailable" error, so
cross-platform apps can share the same code path. It is implemented as a Turbo Module (new
architecture).
- React Native 0.76+ (new architecture)
- Android SDK platform 37 installed (the Hypergate SDK compiles against API 37); set
compileSdkVersion = 37in your app'sandroid/build.gradle - A device managed by an MDM/EMM/UEM (supported EMMs) with Hypergate Authenticator deployed
npm install react-native-hypergateConfigure these managed configurations (app restrictions) in your MDM/EMM/UEM:
| Managed configuration | Value |
|---|---|
| Account type for HTTP Negotiate authentication | ch.papers.hypergate |
| Authentication server allowlist | * or an explicit list of domains allowed to request tokens |
In addition, your app's package name must be on the discoverability list in the Hypergate Authenticator managed configuration, otherwise token requests fail with error 101.
import { getToken } from 'react-native-hypergate';
const token = await getToken('HTTP@securedbackend.com');
// attach to your request:
// headers: { 'Authorization': 'Negotiate ' + token }Do not cache the token. Request a fresh one for every API call, because a cached token may have expired between app start and the actual request. The recommended pattern is a request interceptor that fetches a token per request.
| Param | Description |
|---|---|
servicePrincipal |
SPN of the target service, e.g. HTTP@securedbackend.com |
Resolves with the raw Negotiate token. Rejects when Hypergate is not in possession of a valid TGT, the device is not managed, or the app is not on the discoverability list.
- Error 101 ("no accounts found"): the app's package name is missing from the discoverability list, or the device has no Hypergate account at all.
- Token issued but the backend returns 401: verify the SPN matches the backend's service principal and that the account has AES key material (see Kerberos RC4 removal).
A runnable example lives in example/:
yarn
yarn example androidSee the contributing guide to learn how to contribute to the repository and the development workflow.
MIT, see LICENSE. Questions go to support@hypergate.com.