An implementation for SQRL (Secure Quick Reliable Login)
About this app
This app is an implementation for SQRL (Secure Quick Reliable Login) on Android.
Before you begin using SQRL to login to websites, your SQRL private identity must be created. You only need one, probably for life, because it reveals NOTHING about you, and it's highly secure. It's just a very long (77-digit) random number.
From then on, whenever you login with SQRL to a website, your private identity is used to generate another 77-digit number for that one website. Every website you visit sees you as a different number, yet every time you return to the same site, that site's unique number is regenerated.
This allows you to be uniquely and permanently identified, yet completely anonymous.
Since you never need to use an eMail address or a password, you never give a website your actual identity to protect. If the website's SQRL identities are ever stolen, not only would the stolen identities only be valid for that one website, but SQRL's cryptography prevents impersonation using stolen identities.
This is as good as it sounds. It's what we've been waiting for.
Licensed under MIT, by Daniel Persson.
What's New in v1.7.2
Imported from the F-Droid repository index.
Version history
Mar 11, 2021 · 4.4 MB · Android API 16–30 · code 54
Imported from the F-Droid repository index.
SHA-256 5e9b2d6390528c5c697f3831c79ac441124fd47f12ae8892c68d38b8e10c62d8
Jan 21, 2021 · 4.4 MB · Android API 16–30 · code 53
Imported from the F-Droid repository index.
SHA-256 78370932ce1fd22e8e7d1b18b2f04e1b132b4ce6e9ca0a60c4b1d214390d7cee
Apr 30, 2020 · 4.2 MB · Android API 16–28 · code 52
Imported from the F-Droid repository index.
SHA-256 edaa0af9a30d0afc9b91c56bc2df4671a74deb2ad7f56cb6a89f27808732cf46
Will it run on your device?
87%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be org.ea.sqrl is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 1.7.1 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall SQRL Login first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of SQRL Login, and a listing is removed when the evidence for it stops holding up.
Get SQRL Login
Every source we list for org.ea.sqrl is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
5e9b2d6390528c5c697f3831c79ac441124fd47f12ae8892c68d38b8e10c62d8
Signing certificate
212ec0e3e0d78475d24a1271b48cafea9e75a0d585b000194a7a7f3da98d02e5
Permissions Required
What each permission lets SQRL Login do. A highlighted one is worth a second look — not necessarily wrong, just worth asking whether this app needs it.
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
More Security Privacy apps
More from F-DroidReport a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.