Sample CodeiOS, iPadOS, Mac CatalystReviewed 2026-07-21View on Apple Developer

Logging a User into Your App with Face ID or Touch ID

At a glance

Item Summary
Purpose Supplement your own authentication scheme with biometric authentication, making it easy for users to access sensitive parts of your app.
App architecture A Swift sample with the source-visible chain AppDelegateViewControllerLocalAuthentication APIs.
Main patterns View-controller organization, Delegate or data-source callbacks
Project style 2 scanned source file(s) across Swift, organized around ranked entry, type, and file boundaries.
Execution model Source-visible boundaries: @MainActor, Task, await suspension point; none alone proves a background thread.
State/event model No structured observation or publisher-scheduling marker indexed.
Key frameworks/packages UIKit, LocalAuthentication; these are source dependencies, not architecture labels.

Project structure

Source bundle/
├── Authenticator/
│   ├── AppDelegate.swift
│   ├── ViewController.swift
│   ├── Base.lproj/
│   │   ├── LaunchScreen.storyboard
│   │   └── Main.storyboard
│   └── Info.plist
├── Authenticator.xcodeproj/
│   ├── .xcodesamplecode.plist
│   └── project.pbxproj
└── Configuration/
    └── SampleCode.xcconfig

Structure observations

  • Architecturally prominent files are ranked from entry points and role-named declarations; resource-only paths are omitted.
  • Primary languages: Swift.
  • The verified tree contains 6 project/configuration file(s) and 3 source declaration(s).

Overall architecture

Reference code

Authenticator/AppDelegate.swift:10 — architecture anchor

@UIApplicationMain
class AppDelegate: UIResponder, UIApplicationDelegate {

    var window: UIWindow?

}

Interpretation

The arrows summarize the source-visible entry, role-named types or folders, and framework direction; when nodes come from structural folders, the sequence is a high-level interpretation rather than proof that every adjacent node calls the next. Ownership is claimed only where the next section cites a stored property or assignment. The diagram is intentionally limited to the dominant path into Local Authentication.

Ownership and state

Ownership evidence

Authenticator/AppDelegate.swift:13 — stored dependency or nearest verified ownership anchor

@UIApplicationMain
class AppDelegate: UIResponder, UIApplicationDelegate {

    var window: UIWindow?

}
Owner Object or state Relationship Mutation authority
AppDelegate UIWindow (window) stores or receives App/module collaborators
ViewController UIButton (loginButton) holds a non-owning reference The referenced object’s lifecycle is owned elsewhere
ViewController UIView (stateView) holds a non-owning reference The referenced object’s lifecycle is owned elsewhere
ViewController UILabel (faceIDLabel) holds a non-owning reference The referenced object’s lifecycle is owned elsewhere

Composition arrows indicate a source-visible construction expression or locally owned value state; aggregation means the owner stores or receives a dependency without proving exclusive lifetime ownership.

Concurrency, scheduling, and thread safety

Evidence limit: actor isolation, async/await, or Task creation does not by itself prove background-thread execution; Sendable conformance alone does not prove thread-safe mutation.

Concern Source mechanism Verified placement or handoff Evidence
Main isolation @MainActor The cited annotation marks its attached declaration or closure as main-actor isolated. Authenticator/ViewController.swift:26
Task creation Task The source creates an unstructured task; surrounding context determines inherited actor isolation. Authenticator/ViewController.swift:82
Suspension boundary await suspension point The source declares or crosses an asynchronous boundary; it does not by itself establish background execution. Authenticator/ViewController.swift:84

@MainActor/MainActor.run, DispatchQueue.main, and RunLoop.main are reported as distinct isolation, queue, and event-loop mechanisms. A plain Task is kept separate from Task.detached; neither is labeled as a background thread.

Reference code

Authenticator/ViewController.swift:26 — representative execution boundary

class ViewController: UIViewController {
    // ...
    @MainActor
    var state = AuthenticationState.loggedout {

        // Update the UI on a change.
        didSet {
            loginButton.isHighlighted = state == .loggedin  // The button text changes on highlight.
            stateView.backgroundColor = state == .loggedin ? .green : .red

            // FaceID runs right away on evaluation, so you might want to warn the user.
            //  In this app, show a special Face ID prompt if the user is logged out, but
            //  only if the device supports that kind of authentication.
            faceIDLabel.isHidden = (state == .loggedin) || (context.biometryType != .faceID)
        }
    }
    // ...
}

State propagation, frameworks, and dependencies

Evidence limit: an import proves a source-level compilation dependency at the cited line; it does not prove runtime use, architectural adoption, or whether a Swift package is a direct application dependency.

Category Mechanism or module Verified role Evidence
Source import UIKit The cited file imports this module; runtime use and architectural role are not inferred. Authenticator/AppDelegate.swift:8
Source import LocalAuthentication The cited file imports this module; runtime use and architectural role are not inferred. Authenticator/ViewController.swift:9

receive(on:) describes downstream delivery scheduling, while subscribe(on:) describes upstream subscription/request/cancel scheduling. An import Combine alone establishes neither behavior nor a Store, reducer, Redux, or other application architecture.

Class and protocol design

Authenticator/AppDelegate.swift:11 — representative type boundary

@UIApplicationMain
class AppDelegate: UIResponder, UIApplicationDelegate {

    var window: UIWindow?

}
Type Responsibility Depends on or conforms to
AppDelegate Receives callback-driven events UIResponder, UIApplicationDelegate
ViewController View lifecycle, callbacks, and feature coordination UIViewController
AuthenticationState Represents mutable feature state Concrete collaborators/imported frameworks

No local protocol conformance is claimed as protocol-oriented design; external framework conformances are listed only as dependencies.

Access control

Symbol Access Verified effect Likely rationale
AppDelegate (Authenticator/AppDelegate.swift:11) implicit internal No explicit modifier means the Swift declaration is internal to the module. Inference: app-target collaboration needs no exported library surface.
ViewController (Authenticator/ViewController.swift:11) implicit internal No explicit modifier means the Swift declaration is internal to the module. Inference: app-target collaboration needs no exported library surface.
AuthenticationState (Authenticator/ViewController.swift:21) implicit internal No explicit modifier means the Swift declaration is internal to the module. Inference: app-target collaboration needs no exported library surface.

Reference code

Authenticator/AppDelegate.swift:11 — representative boundary

@UIApplicationMain
class AppDelegate: UIResponder, UIApplicationDelegate {

    var window: UIWindow?

}

Swift declarations without a modifier are internal; explicit private, fileprivate, private(set), public, or open entries above are interpreted by language semantics. Objective-C/C samples instead rely on header and implementation boundaries, which are not equivalent to Swift lexical privacy.

Logic ownership and placement

Logic Owning type or file Placement rationale
View lifecycle, callbacks, and feature coordination ViewController The source’s Controller suffix makes this role explicit.
Receives callback-driven events AppDelegate The source’s Delegate suffix makes this role explicit.

Design patterns

Pattern Source evidence Purpose or tradeoff
View-controller organization Authenticator/ViewController.swift:11 A controller is the verified coordination boundary; this is MVC-style only where a separate model is present.
Delegate or data-source callbacks Authenticator/AppDelegate.swift:11 Callback protocols invert event delivery back into the sample’s owner.

Naming conventions

  • Types: Controller: ViewController; Delegate: AppDelegate.
  • Protocols: no local protocol declaration in the scanned source.
  • Methods: viewDidLoad, tapButton.
  • Files: Authenticator/AppDelegate.swift, Authenticator/ViewController.swift.

Architecture takeaways

  • AppDelegate is the main source-visible entry or composition anchor for this sample.
  • Framework work reaches UIKit, LocalAuthentication through a deliberately small high-level chain; the detailed API graph remains inside the cited implementation files.
  • Stored-property evidence identifies lifecycle collaboration; it does not by itself prove exclusive object ownership.
  • Access-control conclusions separate verified language visibility from the likely design rationale.
  • The source does not justify labeling the design protocol-oriented.

Source map

Source file Relevant symbols
Authenticator/AppDelegate.swift Cited implementation, AppDelegate, UIKit
Authenticator/ViewController.swift ViewController, AuthenticationState, @MainActor, Task, await suspension point, LocalAuthentication