Skip to content

Password Store

F-Droid

Open source

Manage your passwords

Version
1.16.4
Size
8.2 MB
Updated
Jul 11, 2026
Get from Download APK (v1.16.4)
Signing certificate on record

About this app

Simple password manager that is compatible with pass: Passwords are stored in simple text files which are encrypted with OpenPGP.

Features:

• Clone an existing pass repository or start a new one

• Create and organize password files

• Sync with a remote Git repository

• Decrypt and copy passwords

• Automatically fill and save credentials in apps and supported browsers

• Supports time-based one-time passwords (TOTP) for two-step authentication

Licensed under GPL-3.0-only, by Alexander Grahn.

OfficialSignature VerifiedOpen Source

What's New in v1.16.4

Imported from the F-Droid repository index.

  • Added:
  • - Search result filter options "exact match" and "fuzzy" in Settings --> General
  • - PGP Manager now imports all keys from multi-key backups, such as those produced with OpenKeychain (previously, only the first key was imported)
  • - Option to generate Ed25519 SSH keys restored
  • Changed:
  • - When moving files or directories, conclude action with listing the content of the destination directory

Version history

v1.16.4Latest
Signature continuous

Jul 11, 2026 · 8.2 MB · Android API 2637 · code 11604

Imported from the F-Droid repository index.

  • Added:
  • - Search result filter options "exact match" and "fuzzy" in Settings --> General
  • - PGP Manager now imports all keys from multi-key backups, such as those produced with OpenKeychain (previously, only the first key was imported)
  • - Option to generate Ed25519 SSH keys restored
  • Changed:
  • - When moving files or directories, conclude action with listing the content of the destination directory
INTERNETFOREGROUND_SERVICEQUERY_ALL_PACKAGESCAMERAUSE_BIOMETRICUSE_FINGERPRINTWAKE_LOCKACCESS_NETWORK_STATERECEIVE_BOOT_COMPLETEDapp.passwordstore.agrahn.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 6c6c9d21e70471f31ff58e03dc7be67cc977d806f3401dcc6d275e13dd6e1c41

v1.16.3
Signature continuous

Apr 16, 2026 · 7.8 MB · Android API 2636 · code 11603

Imported from the F-Droid repository index.

  • Added:
  • - The host key fingerprint is displayed when connecting to the Git server for the first time, so that the user can decide whether to establish the connection
  • - Diceware passphrase generator options for capitalising words and embedding a numeral
  • - Floating sync button on the password list that is shown if there are local commits to be pushed to remote
  • - Enhanced folder selection when moving password items, allow navigating upwards, floating button for creating new subfolder
  • Fixed:
INTERNETFOREGROUND_SERVICEQUERY_ALL_PACKAGESCAMERAUSE_BIOMETRICUSE_FINGERPRINTapp.passwordstore.agrahn.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 0a78500e1b92fe99e346b0553e140d5f529b0f3feb399dab645fb26b41f6d429

v1.16.2
Signature continuous

Mar 2, 2026 · 7.8 MB · Android API 2636 · code 11602

Imported from the F-Droid repository index.

  • Fixed:
  • - decryption failure if PGP key contained revoked encryption subkey
INTERNETFOREGROUND_SERVICEQUERY_ALL_PACKAGESCAMERAUSE_BIOMETRICUSE_FINGERPRINTapp.passwordstore.agrahn.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 6e93fb48d53d35f173530da14dba90c60dd5aa74a4d6823c003dc162344706ac

Will it run on your device?

CompatibilityVery likely to run

92%

  • Runs on a broad range of modern Android versions.
  • Multiple CPU architectures are covered.
  • Aligned with the latest Android target SDK expectations.
What changed in this release
Size delta
+0.4 MB
Added permissions
WAKE_LOCK, ACCESS_NETWORK_STATE, RECEIVE_BOOT_COMPLETED
Removed permissions
None

Installation Guide

1

Open Settings on your Android device

2

Go to Security → Unknown sources (or Install unknown apps)

3

Enable "Allow from this source" for your browser or file manager

4

Open the downloaded APK file from your Downloads folder

5

Tap "Install" and wait for installation to complete

6

Launch the app from your home screen

Make sure to re-enable Unknown Sources restrictions after installation for security.

How to install this safely

How to verify the file you downloaded

Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.

What the signing certificate proves

Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be app.passwordstore.agrahn is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.

How to roll back to an earlier version

If the current release misbehaves, 1.16.3 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Password Store first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.

Why we list sources instead of hosting everything

The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Password Store, and a listing is removed when the evidence for it stops holding up.

Get Password Store

Every source we list for app.passwordstore.agrahn is legality-reviewed. Pirated or cracked builds are never offered.

Other sources

F-Droid listing

official

F-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.

Source code

verified publisher

The upstream repository this build is compiled from.

We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.

App Information

Developer
F-Droid
Category
Security Privacy
Android
8.0+
Architectures
arm64-v8a, armeabi-v7a, x86, x86_64
Version
1.16.4 (code 11604)
Size
8.2 MB
Updated
Jul 11, 2026
Package name
app.passwordstore.agrahn

Security Verification

File integrity
SHA-256 recorded
Signing certificate
Fingerprint on record
Official source
Download APK (v1.16.4)

We record provenance; we do not run malware scans. Verify the hash yourself before installing.

SHA-256 Hash

6c6c9d21e70471f31ff58e03dc7be67cc977d806f3401dcc6d275e13dd6e1c41

Signing certificate

6e664c960c27ea35db9f91bd33ce3e9f7a2f7d88b620c44f5953626111e2b9fd

Permissions Required

INTERNET
FOREGROUND_SERVICE
QUERY_ALL_PACKAGES
CAMERA
USE_BIOMETRIC
USE_FINGERPRINT
WAKE_LOCK
ACCESS_NETWORK_STATE
RECEIVE_BOOT_COMPLETED
app.passwordstore.agrahn.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Previous Versions

Signature verified

The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.

Report a problem with this listing

A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.

Report a problem