Require that authentication API operations don’t fall back to an app password or the device passcode. They can query whether a user is enrolled, allowing Optic ID, Face ID, or Touch ID to be used as a second factor in security-sensitive apps.
Generate and use Elliptic Curve Cryptography (ECC) keys inside the Secure Enclave that can be protected by Optic ID, Face ID, or Touch ID. Operations with these keys are always performed inside the Secure Enclave after it authorizes their use.
Users can also configure Optic ID, Face ID, or Touch ID to approve purchases from the iTunes Store, the App Store, Apple Books, and more, so users donʼt have to enter their Apple Account password. When purchases are made, the Secure Enclave verifies that a biometric authorization occurred and then releases ECC keys used to sign the store request.
On devices with iOS 18, iPad OS 18, or later, Face ID and Touch ID can be used to access apps that the user decided to lock or hide.