Device Integrity API
Local-only device integrity detection APIs for detecting rooted (Android) or jailbroken (iOS) devices.
These checks are local and bypassable. For hardware-backed, server-verified attestation (Play Integrity / App Attest), see the Device Attestation API — an opt-in package that complements these checks: use local detection as a fast offline pre-filter and attestation as the gate your server trusts.
Overview
These APIs perform local detection only (file system checks, package detection, etc.) without any server-side verification. They're commonly used as one layer of defense in:
- Financial/banking apps
- Healthcare apps with sensitive data
- Enterprise MDM solutions
- Apps with DRM requirements
:::warning Limitations All detection methods are local-only and can be bypassed by sophisticated tools (Magisk + Shamiko, RootHide, PlayIntegrityFix, etc.).
- "Not detected" does NOT guarantee a secure device
- These APIs do NOT use Play Integrity API or iOS App Attest
- Use as one layer of defense-in-depth, not as sole security measure :::
API Reference
isDeviceCompromised()
Synchronously checks if the device is rooted (Android) or jailbroken (iOS).
Returns: true if device is compromised, false otherwise
Performance: <50ms
Emulator Policy: Returns false on emulators/simulators for development convenience.
verifyDeviceIntegrity()
Asynchronous wrapper for device integrity verification.
Returns: Promise resolving to true if device is rooted/jailbroken
Performance:
- iOS: up to 200ms (includes SSH port scanning)
- Android: <50ms (async wrapper for
isDeviceCompromised())
Platform Differences:
- iOS: Includes SSH port scanning (ports 22, 44) in addition to all checks performed by
isDeviceCompromised(). This additional check can detect OpenSSH installed by jailbreak tools. - Android: Same as
isDeviceCompromised(), provided as async wrapper for API consistency.
Emulator Policy: Returns false on emulators/simulators.
Detection Methods
Android
iOS
Usage Examples
Basic Check
Financial App Protection
Conditional Feature Access
Platform Support
Best Practices
- Don't rely solely on detection - Use as one layer of defense-in-depth
- Handle gracefully - Don't crash, provide alternative flows
- Log for analytics - Track detection rates for security insights
- Test on real devices - Emulators always return
false - Update regularly - New rooting tools emerge frequently
