Flutter Local Database in 2026: What to Use, and Which Packages Have Gone Quiet
Which Flutter local database to use in 2026: shared_preferences, secure storage, sqflite, drift, Hive CE, Isar forks and ObjectBox, checked on pub.dev.

Search for "Flutter local database" and you'll still find lists that put Hive or Isar at the top. On pub.dev, the original hive package hasn't shipped a stable release since June 30, 2022, and the original isar package's last stable release was April 25, 2023. Neither is marked discontinued, so nothing warns you when you add them.
This guide picks a storage package by the kind of data you're saving, not by benchmark charts. Every version and date below was checked on pub.dev and the official docs on October 2, 2026, against Flutter 3.47 and Dart 3.13.
Key takeaways
- For settings, use
shared_preferences, but throughSharedPreferencesAsyncorSharedPreferencesWithCache. The package README calls the oldSharedPreferencesclass a legacy API - For tokens and other secrets, use
flutter_secure_storage, not preferences - For structured app data,
driftis the strongest default: typed queries, reactive streams, migrations and stable web support - If you want Hive's simple box API, use the
hive_cefork. If you're on Isar, decide betweenisar_community(v3 fixes, no web) andisar_plus(newer, smaller)
The short answer: match the package to the data
Local data in most apps falls into four kinds, and each has a sensible default:
| What you're storing | Use | Why |
|---|---|---|
| Settings and small flags (theme, onboarding seen, last tab) | shared_preferences (Async or WithCache API) |
First-party, every platform, tiny API |
| Secrets (auth tokens, refresh tokens, API keys a user entered) | flutter_secure_storage |
Keychain on Apple platforms, encrypted storage on Android |
| Structured, queryable app data (tasks, messages, orders) | drift |
SQLite with typed queries, streams and migrations; web is stable |
| Simple objects you read by key, no complex queries | hive_ce |
Maintained fork of Hive v2 with the same box model |
Two more cases come up often. If you want plain SQL with no code generation and you only target Android, iOS and macOS, sqflite is what the Flutter cookbook uses. If you need an object database with on-device vector search or a vendor sync product, look at objectbox, but note it has no web support.

What the official Flutter docs recommend
The Flutter docs keep it simple. The persistence cookbook has three recipes: read and write files, store key-value data on disk with shared_preferences, and persist data with SQLite through sqflite. The SQL page in the app architecture guide also points to sqlite3 and drift as alternatives.
The docs don't rank Hive, Isar or ObjectBox, so beyond key-value data and SQLite, the choice is yours.
One detail trips people up. The cookbook's key-value recipe still shows the legacy SharedPreferences.getInstance() API, while the package's own README steers new code to the newer APIs. When the two disagree, follow the package.
Settings and flags: shared_preferences, the new way
shared_preferences (2.5.5, published by flutter.dev) is still the right tool for small key-value data, and it runs on Android, iOS, Linux, macOS, web and Windows. The API you call has changed, though. The package README says plainly: "SharedPreferences is a legacy API that will be deprecated in the future."
It offers two replacements:
SharedPreferencesAsynckeeps no local cache, so every read isawaited and always reflects what's on disk. That makes it safe when several isolates or engine instances touch the same values.SharedPreferencesWithCacheloads an allow-listed set of keys once, then serves synchronous reads from memory. It's convenient for UI code, but the cache can go stale if another isolate writes.
// Async: every call goes to the platform
final asyncPrefs = SharedPreferencesAsync();
await asyncPrefs.setBool('repeat', true);
final bool? repeat = await asyncPrefs.getBool('repeat');
// WithCache: synchronous reads after one async create
final prefsWithCache = await SharedPreferencesWithCache.create(
cacheOptions: const SharedPreferencesWithCacheOptions(
allowList: <String>{'repeat', 'action'},
),
);
final bool? cachedRepeat = prefsWithCache.getBool('repeat');
On Android, the new APIs use Jetpack DataStore Preferences by default. If your app already wrote values with the legacy class, the package ships a one-time migration helper, migrateLegacySharedPreferencesToSharedPreferencesAsyncIfNecessary, in package:shared_preferences/util/legacy_to_async_migration_util.dart.
Don't store anything you can't afford to lose here. The README warns that writes may reach disk asynchronously, so the plugin "must not be used for storing critical data." User content belongs in a database.
The same values often drive app state, so pair this with how your app manages that state. Our Flutter state management guide covers where a settings repository fits.
Secrets: flutter_secure_storage, and what changed in v10
Auth tokens don't belong in shared_preferences, which is plain platform storage. Use flutter_secure_storage (11.2.0 as of September 16, 2026). On iOS and macOS it uses the Keychain.
Android changed in version 10. The README says "the deprecated Jetpack Security library's encryptedSharedPreferences is no longer recommended," and the plugin now defaults to RSA OAEP for key encryption with AES-GCM for the stored data. It includes an automatic migration when the cipher changes. If you're upgrading from v9 or earlier, test that path on a real device with existing data before you ship. The minimum Android SDK is now API 23.
Web support is experimental and built on WebCrypto. The README is explicit that it "only works on HTTPS or localhost environments," so a plain-HTTP staging site will fail.
Structured data: why drift is the default to beat
For anything you filter, sort or join, use a real database. In 2026, drift is the most complete option for Flutter. Version 2.35.1 shipped on September 30, 2026, its fourth minor release since June.
What you get:
- Typed queries. Write queries in Dart or in SQL. Drift's code generator checks them at build time.
- Reactive streams. Any query can become a
Streamthat emits again when the underlying tables change, which fits aStreamBuilderor a stream-based state manager. - Migrations. Drift has built-in schema migration support. You bump
schemaVersionand describe the steps. - Threading. Drift describes itself as "the only major persistence library with builtin threading support," so heavy queries can run off the UI isolate.
- Web. The drift web docs state: "Web support is now stable."
A table and database definition looks like this. It's adapted from drift's setup guide and uses drift_flutter's driftDatabase() to open the file. Web builds also need the WebAssembly and worker files described in drift's web docs:
class Habits extends Table {
IntColumn get id => integer().autoIncrement()();
TextColumn get name => text().withLength(min: 1, max: 60)();
DateTimeColumn get createdAt => dateTime().nullable()();
}
@DriftDatabase(tables: [Habits])
class AppDatabase extends _$AppDatabase {
AppDatabase([QueryExecutor? executor])
: super(executor ?? driftDatabase(name: 'app_db'));
@override
int get schemaVersion => 1;
// Emits a fresh list whenever the habits table changes.
Stream<List<Habit>> watchHabits() => select(habits).watch();
}
The cost is a build step. Drift needs drift_dev and build_runner, and you regenerate code when the schema changes. For most production apps, that's a fair trade for compile-time-checked queries.
Web needs one more decision. Drift picks the best storage the browser offers. Its fastest options use the Origin Private File System. One of them, opfsLocks, requires your server to send Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Embedder-Policy: require-corp (or credentialless). Without those headers, drift falls back to a slightly slower IndexedDB-based implementation. It still works, so you can add the headers later.
For encryption, drift's encryption page points to SQLite3MultipleCiphers, "a fork of SQLite with added encryption support."
When plain sqflite is enough
sqflite (2.4.4, September 10, 2026) is the package the Flutter cookbook uses. You write raw SQL and manage migrations through onCreate and onUpgrade callbacks. It's maintained and well understood. Its limits are worth knowing:
- The core package supports Android, iOS and macOS. Desktop goes through
sqflite_common_ffi, and web support throughsqflite_common_ffi_webis experimental. - Its README notes that "concurrent read and write transaction are not supported."
- You map rows to objects yourself, and SQLite has no native
DateTimetype, so you store timestamps as integers or strings.
If your app has a handful of tables, targets mobile only and your team likes writing SQL, sqflite is fine. Once you want streams, typed queries or web, you'll end up rebuilding parts of drift.
Hive and Isar in 2026: use the forks, or don't
This is the section most "best Flutter database" lists leave out. Both are published on pub.dev under the same isar.dev publisher, both were popular, and both went quiet. The release history we pulled from pub.dev looks like this:

Hive → hive_ce
The original hive package's latest stable version is still 2.2.3 from June 2022. Its last prerelease, 4.0.0-dev.2, came out in August 2023. The community fork hive_ce describes itself as "a spiritual continuation of Hive v2" and shipped 2.20.1 on September 27, 2026.
Hive CE keeps the box model people liked: pure Dart, fast reads by key, built-in encryption, and every platform including web. It adds features the original never had, including "Flutter web WASM support" and isolate support through IsolatedHive. Moving over is mostly a dependency and import change (package:hive_ce/hive_ce.dart), but run it against a copy of real user data before you ship, because these are files your users already have on disk.
Hive was never a query engine. The original README even sent people elsewhere: "If you need queries, multi-isolate support or links between objects check out Isar." If you need filtering across thousands of records, use drift.
Isar → isar_community or isar_plus
The original isar package's last stable release is 3.1.0+1 from April 2023. The 4.0 line stopped at a dev release in August 2023, and the GitHub README still says: "ISAR V4 IS NOT READY FOR PRODUCTION USE."
If your app already depends on Isar, you have two community forks:
isar_community(3.3.2, March 2026) focuses "primarily on bug fixes and small updates for version 3." pub.dev lists Android, iOS, Linux, macOS and Windows, with no web.isar_plus(1.3.9, August 2026) is "an enhanced fork of the original Isar database" with web support. It's newer, has a single maintainer and much lower adoption on pub.dev.
For an existing Isar 3 app, isar_community is the conservative choice. For a new app, we wouldn't start on either. Pick drift for queried data or hive_ce for simple keyed data.
ObjectBox and sembast
objectbox (5.3.2, May 2026) is a native object database from a commercial vendor. It has built-in relations, on-device vector search for AI features, and an optional sync product. The vendor says it's "10X faster than SQLite" based on its own benchmarks, so test with your own data before you rely on that. The key limit for Flutter teams: pub.dev lists Android, iOS, Linux, macOS and Windows, but not web.
sembast (3.8.11, September 2026) is a pure-Dart NoSQL document store with query finders and change listeners. Its README states that the database "resides in a single file and is loaded in memory when opened." That design is simple and portable, including web through sembast_web, but it suits small to medium datasets, not large ones.
Platform support at a glance
Web support is where these packages differ most. This table lists the platforms each package declares on pub.dev (October 2, 2026):
| Package | Latest | Android/iOS | macOS | Windows/Linux | Web |
|---|---|---|---|---|---|
| shared_preferences | 2.5.5 | Yes | Yes | Yes | Yes |
| flutter_secure_storage | 11.2.0 | Yes | Yes | Yes | Experimental (HTTPS/localhost) |
| sqflite | 2.4.4 | Yes | Yes | Via sqflite_common_ffi | Experimental (ffi_web) |
| drift | 2.35.1 | Yes | Yes | Yes | Yes (stable) |
| hive_ce | 2.20.1 | Yes | Yes | Yes | Yes |
| isar_community | 3.3.2 | Yes | Yes | Yes | Not listed |
| isar_plus | 1.3.9 | Yes | Yes | Yes | Yes |
| objectbox | 5.3.2 | Yes | Yes | Yes | No |
| sembast | 3.8.11 | Yes | Yes | Yes | Via sembast_web |
A checklist before you commit to one
- Write down the data shapes. Settings, secrets, records you query, blobs. Most apps need two packages: preferences plus secure storage, or preferences plus a database.
- Check the platforms you ship. If web is on the roadmap, rule out ObjectBox and
isar_communitynow. - Open the package's pub.dev versions tab. A recent stable release and a verified publisher tell you more than a benchmark chart.
- Plan the first migration on day one. With drift that means
schemaVersionand migration steps. With sqflite it'sonUpgrade. With Hive CE it's keeping type adapter IDs stable. - Keep storage behind a repository. If your widgets call one class instead of the package directly, you can swap the package later without touching UI code.
How FlutterGo handles local storage
FlutterGo generates standard Flutter projects, so you can add any of these packages to the code it gives you. Whether a build uses local persistence at all depends on what you ask for. In our habit tracker tutorial, the first build kept everything in memory, and one follow-up prompt moved it to SharedPreferencesAsync. When you start a project, the studio also asks whether to connect a backend like Supabase or skip it for now. For a hosted database with auth, see our Supabase and FlutterGo guide.
If you'd rather start from a working app than an empty project, describe it in FlutterGo and review the storage code it writes before you add more features.
FAQ
What is the best local database for Flutter in 2026?
For structured data you query, drift is the strongest default. It's actively maintained, gives you typed queries and reactive streams, handles migrations and supports web. For small settings, use shared_preferences through its Async or WithCache API. For secrets, use flutter_secure_storage.
Is Hive still maintained?
The original hive package has had no stable release since 2.2.3 in June 2022. The maintained continuation is the community fork hive_ce, which released 2.20.1 on September 27, 2026.
Should I use Isar for a new Flutter app?
We wouldn't. The original Isar's last stable release was in April 2023, and its README says v4 isn't ready for production. Existing Isar 3 apps can move to isar_community. New apps are better served by drift or hive_ce.
Can I store a login token in shared_preferences?
You shouldn't. It's plain platform storage, and the package warns it isn't for critical data. Use flutter_secure_storage, which uses the Keychain on iOS and macOS and encrypted storage on Android.
Which Flutter local databases work on the web?
shared_preferences, drift (stable), hive_ce, isar_plus and sembast (via sembast_web) all support web. flutter_secure_storage and sqflite have experimental web support. objectbox has none, and pub.dev lists no web support for isar_community.
Versions and dates checked on pub.dev on October 2, 2026. The code samples are adapted from each package's documentation and were checked against those docs, not compiled for this article.


