Conscrypt Provider provides TLS 1.3 to apps supporting older Android devices
About this app
Conscrypt Provider is an APK which can provide the Conscrypt Library to apps that support older Android devices. The Conscrypt Library provides modern TLS capabilities and ciphers, including TLS 1.3, and supports all the way back to Android 2.3 Gingerbread!
I have wrapped it in a standalone APK because not all users will need it (Android 10+ has TLS 1.3 enabled), and because the library is quite large.
Users: will need to install this app. It does not appear in the app drawer as it has no interface.
App Developers: will need to add code to their apps to make use of this provider. For instructions on how to do this, see the README: https://github.com/mendhak/Conscrypt-Provider
---
I have made use of the F-Droid blog post and an associated gist.
This may not be the best or perfect way to provide Conscrypt to applications, but it's a way that works for me. I'm putting it on F-Droid in case it benefits others too.
Licensed under MIT, by Mendhak.
What's New in v3
Imported from the F-Droid repository index.
- * Clearer description and instructions
Version history
Jul 24, 2022 · 5.2 MB · Android API 16–32 · code 3
Imported from the F-Droid repository index.
- * Clearer description and instructions
SHA-256 08ef2e7d0bdfe4aa9c6399ada96b694ace3aa32d6cf8c90fe80320b534ec5126
Jul 18, 2022 · 5.2 MB · Android API 16–32 · code 2
Imported from the F-Droid repository index.
- * Initial release of Conscrypt Provider
SHA-256 9909f242b8974476ab7cc1456c6d0bfa464d6dfb4ae61ba1c8305f4f91f5218e
Will it run on your device?
87%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be com.mendhak.conscryptprovider is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 2 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Conscrypt Provider first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Conscrypt Provider, and a listing is removed when the evidence for it stops holding up.
Get Conscrypt Provider
Every source we list for com.mendhak.conscryptprovider is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
08ef2e7d0bdfe4aa9c6399ada96b694ace3aa32d6cf8c90fe80320b534ec5126
Signing certificate
3396e1fe3ebefe1e344d747722a21a70902a73c6eac31fbe1c5cb0843c384d4b
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.