OpenPGP encryption with hardware security keys and password-store support
About this app
PGPony is an OpenPGP app for Android. Encrypt, decrypt, sign, and verify messages and files, manage your keyring, and use a hardware security key over NFC, all on device.
Features:
- Encrypt, decrypt, sign, and verify text and files - Generate modern keys, including RFC 9580 (OpenPGP v6) Ed25519 and X25519, with Argon2id passphrase protection - Hardware security keys over NFC, including YubiKey 5 NFC and Token2, with on-card key generation, decrypt, sign, PIN management, and factory reset - Read your password-store (pass) entries, including those protected by a hardware key - Key discovery through WKD and the keys.openpgp.org verifying keyserver - Optional contact integration for choosing recipients - QR import and scanning for keys - Biometric lock and secure-screen protection
PGPony does not use accounts, ads, analytics, or tracking. The F-Droid build contains no Google services and runs fully on de-Googled devices.
The cryptographic core is published separately as open source (PGPonyCore-Kotlin), and the full app source is available under the Apache-2.0 license.
Licensed under Apache-2.0, by NorseHorse.
What's New in v3.1.0
Imported from the F-Droid repository index.
- PGP/MIME support: decrypt messages with attachments, compose encrypted bundles (.eml/.asc), share multiple files in at once.
- Hardware keys: remember your card PIN for a chosen duration; full offline-primary support (subkey-only cards link, sign, and verify correctly).
- Also: accepts GnuPG AEAD messages, Send as Email with inline/attachment choice, sign-by-default, four-mode Encrypt screen, more reliable file key import.
Version history
Jul 4, 2026 · 13.6 MB · Android API 26–35 · code 300
Imported from the F-Droid repository index.
- PGP/MIME support: decrypt messages with attachments, compose encrypted bundles (.eml/.asc), share multiple files in at once.
- Hardware keys: remember your card PIN for a chosen duration; full offline-primary support (subkey-only cards link, sign, and verify correctly).
- Also: accepts GnuPG AEAD messages, Send as Email with inline/attachment choice, sign-by-default, four-mode Encrypt screen, more reliable file key import.
SHA-256 482edf9df3802740795de4b3b62a7cbab3bb8c74b2b0a996e1bef7c26a2042e6
Jul 4, 2026 · 13.5 MB · Android API 26–35 · code 204
Imported from the F-Droid repository index.
- Fixed a crash when creating an inline (clear-signed) signature on Android 12 and earlier. Inline signing now works across all supported Android versions.
- Refreshed the app icon.
SHA-256 e6bdf42db17fa568f1b5b8e8acc84396c1897f2b798689488a3002c49827d6b8
Jun 30, 2026 · 13.7 MB · Android API 26–35 · code 203
Imported from the F-Droid repository index.
SHA-256 0683a0b9942b4ee65c3b4f677eb01bb7b95021db472e6a2f52575c8a7578471a
Will it run on your device?
92%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be com.pgpony.android is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 3.0.4 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall PGPony first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of PGPony, and a listing is removed when the evidence for it stops holding up.
Get PGPony
Every source we list for com.pgpony.android is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
482edf9df3802740795de4b3b62a7cbab3bb8c74b2b0a996e1bef7c26a2042e6
Signing certificate
446bf9e621222a40c66cd2476e1a97105ccb2a9b16a01a91c1c7eb90765b50dc
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.