Verify decentralized cryptographic identities on the go
About this app
A modern, secure and privacy-friendly platform to establish your decentralized online identity
Keyoxide allows you to prove “ownership” of accounts on websites, domain names, IM, etc., regardless of your username.
That last part is important: you could, for example, be ‘alice’ on Lobste.rs, but ‘@alice24’ on Twitter. And if your website is ‘thatcoder.tld’, how are people supposed to know that all that online property is yours?
Of course, one could opt for full anonymity! In which case, keep these properties as separated as possible. But if you’d like these properties to be linked and, by doing so, establish an online identity, you’ll need a clever solution.
Enter Keyoxide.
When you visit someone’s Keyoxide profile and see a green tick next to an account on some website, it was proven beyond doubt that the same person who set up this profile also holds that account.
App features
* Simple and straightforward UI * Onboarding * Guided tour * Fully open source * Built with Flutter * Supports fingerprint and email address as identifiers * Supports fetching, identities via keyservers and Web Key Directory * Search history * Contacts feature * ASP Profile management, create, edit, delete, import, export profiles, add claims directly within the app * Hide sensitive user profiles and protect with authentication * Disable animations and update check * Add multiple PGP or ASP profiles * Custom domain validation and support for profile upload and look-up * Check and display server update availability * Biometric, password, PIN or pattern authentication for profile management * User defined settings and data is saved in encrypted form * Deep linking with 'openpgp4fpr' and 'aspe' URL schemes * Localization, current available languages: German, English, Dutch, French, Galician, Polish, Spanish, Turkish, Portuguese, Chinese, Japanese * Material 3 design * Adaptive themeable icons for Android * Accessibility enhancements such as semantic labels, dyslexic font, choice of seed color.
About Keyoxide
* Identity => verification using bidirectional linking * Secure => use of trusted cryptography * Decentralized => user data sovereignty * Privacy-friendly => data explicitly provided by identity holder
Licensed under AGPL-3.0-or-later, by Berker Sen.
What's New in v2.4.3
Imported from the F-Droid repository index.
Version history
Apr 17, 2025 · 35.5 MB · Android API 24–35 · code 219
Imported from the F-Droid repository index.
SHA-256 4851550c2b1cfcc2bacf6942c39994b65fb3001293d0a8343be77e7f0427f600
Aug 15, 2024 · 35.2 MB · Android API 24–34 · code 216
Imported from the F-Droid repository index.
SHA-256 1887672f852ea85f10d3a033ad88505b1bf2f5f5ea73207d83878c1374738975
Jul 21, 2024 · 35.2 MB · Android API 24–34 · code 214
Imported from the F-Droid repository index.
SHA-256 a674e75dadeeb34b21539a2fbb6379c815cc1ff74a693e096e4d2358f727eaa9
Will it run on your device?
92%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be org.keyoxide.keyoxide is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 2.4.2 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Keyoxide first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Keyoxide, and a listing is removed when the evidence for it stops holding up.
Get Keyoxide
Every source we list for org.keyoxide.keyoxide is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
4851550c2b1cfcc2bacf6942c39994b65fb3001293d0a8343be77e7f0427f600
Signing certificate
10169647006af402960a68cc44ce53df1bd3ffdaa19ded2e5aa0710c659ac9b3
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.