Authentication
Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.
Email and password · Sessions
Use Playstack authentication and local-first contracts with Expo SecureStore, SQLite, and React Native lifecycle adapters.
Visit Expo ↗Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.
Email and password · Sessions
Define typed notifications, resolve recipient preferences, deliver across explicit channels, and retain one provider-independent history of every send.
Share durable local mutations and synchronization semantics across web, Expo, and desktop clients while keeping product policy explicit.
Atomic local mutations · Portable synchronization · Platform storage
@playstack/auth-react/expo adapts Expo SecureStore to Playstack's TokenStorage seam without installing or hiding Expo. It stores only opaque access and refresh tokens with numeric expiries, rejects expanded session records, and exposes the injected SecureStore client.
import * as SecureStore from 'expo-secure-store'
import { createExpoTokenStorage } from '@playstack/auth-react/expo'
export const tokenStorage = createExpoTokenStorage(SecureStore)The application's transport uses that storage when exchanging and refreshing tokens against its Playstack-enabled API. Native navigation, deep links, biometric policy, and server authorization remain application boundaries.
@playstack/local-first-expo adapts Expo SQLite transactions and React Native lifecycle/connectivity signals to the runtime-neutral @playstack/local-first engine. The product shares mutation envelopes, retry and conflict policy, cursor semantics, and migrations with its web and desktop clients while retaining native background-execution and file-handling policy.
The separate @playstack/delivery/expo seam supplies push transport integration; it does not require the notifications inbox. Device enrollment, silent hints, coalescing, provider receipts and background scheduling remain product-owned.
SecureStore at rest does not prove that tokens never enter JavaScript. Native refresh ownership, callbacks, restart and cancellation, and real-device delivery are yours to verify on the devices you ship to. The new Chakra/App UI/Admin UI packages target React DOM and are not Expo-native components.