My understanding from the App Attest wwdc session is that we store attestation keys in keychain on a per-user basis. For apps that don't require user login, I'm thinking of using StoreKit's AppTransactionID [1] as the identifier to discriminate keys. Do you have opinions on whether this is a valid pattern?
[1] https://developer.apple.com/documentation/storekit/apptransaction/apptransactionid
Topic:
Privacy & Security
SubTopic:
App Attest & DeviceCheck
1
0
494