After KeyPermanentlyInvalidatedException: silent key re-enrollment or forced server re-authentication?
I'm designing credential handling for an Android app that binds its refresh-token encryption key to the Android Keystore with setUserAuthenticationRequired(true) and setInvalidatedByBiometricEnrollment(true) . The goal is least-privilege access: no usable credential without fresh user authentication. The documented behavior creates a fork I can't resolve. Wh