Skip to content

OpenKeychain: Easy PGP

F-Droid

Open source

Encrypt your Files and Communications. Compatible with the OpenPGP Standard.

Version
6.0.4
Size
11.5 MB
Updated
Mar 5, 2024
Get from Download APK (v6.0.4)
Signing certificate on record

About this app

OpenKeychain helps you communicate more privately and securely. It uses encryption to ensure that your messages can be read only by the people you send them to, others can send you messages that only you can read, and these messages can be digitally signed so the people getting them are sure who sent them. OpenKeychain is based on the well established OpenPGP standard making encryption compatible across your devices and systems. For a list of compatible software for Windows, Mac OS, and other operating systems consult http://openpgp.org/software/.

Modern encryption is based on digital “keys”. OpenKeychain stores and manages your keys, and those of the people you communicate with, on your Android smartphone. It also helps you find others’ keys online, and exchange keys. But its most frequent use is in using those keys to encrypt and decrypt messages.

★ Integration with other Apps: • K-9 Mail • Conversations • and many more…

★ Open Source: OpenKeychain is designed to be trustworthy. It’s Free Software with no secrets; anyone can examine and validate every bit of it (Source code available at https://github.com/open-keychain/open-keychain)

★ Independent Security Audit: The auditing company Cure53 performed an intensive security audit of OpenKeychain. The security experts summarize their final result with "[...] none of the spotted issues were considered to be of a critical severity in terms of security implications. The latter is a significant and impressive result for an app of this complexity and relevance."

★ Permissions: Because OpenKeychain is Free Software, anyone can validate that the permissions are indeed only required for the listed features. • In-app purchases: Donate to the developers • Identity: Pre-fill name and email addresses • Contacts: Connect keys to your contacts (only offline) • Photos/Media/Files: Import/export keys from SD card • Camera: Scan QR Codes to add other people's keys • Others: Internet permission to retrieve keys, NFC permission to use YubiKeys

Starting with Android 6, permissions are requested when required in-app!

Licensed under GPL-3.0-or-later, by Dominik Schürmann.

OfficialSignature VerifiedOpen Source

What's New in v6.0.4

Imported from the F-Droid repository index.

Version history

v6.0.4Latest
Signature continuous

Mar 5, 2024 · 11.5 MB · Android API 1534 · code 60400

Imported from the F-Droid repository index.

READ_MEDIA_IMAGESREAD_MEDIA_VIDEOREAD_MEDIA_AUDIOREAD_EXTERNAL_STORAGEPOST_NOTIFICATIONSINTERNETACCESS_NETWORK_STATEACCESS_WIFI_STATENFCREAD_SYNC_SETTINGSWRITE_SYNC_SETTINGSFOREGROUND_SERVICEFOREGROUND_SERVICE_SPECIAL_USEWAKE_LOCKRECEIVE_BOOT_COMPLETEDCAMERAorg.sufficientlysecure.keychain.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 f88374b9113aa9ddba865258bd989eb3ac2ca1577d92e59d6e84228e080674ce

v6.0.2
Signature continuous

Feb 24, 2024 · 12.1 MB · Android API 1534 · code 60200

Imported from the F-Droid repository index.

READ_MEDIA_IMAGESREAD_MEDIA_VIDEOREAD_MEDIA_AUDIOREAD_EXTERNAL_STORAGEPOST_NOTIFICATIONSINTERNETACCESS_NETWORK_STATEACCESS_WIFI_STATENFCREAD_SYNC_SETTINGSWRITE_SYNC_SETTINGSFOREGROUND_SERVICEFOREGROUND_SERVICE_SPECIAL_USEWAKE_LOCKRECEIVE_BOOT_COMPLETEDCAMERAorg.sufficientlysecure.keychain.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 b7459700755510ba03a08a2801bbedebecc3ae3837ac7c0a8d9994c7d016979b

v5.8.2
Signature continuous

Jan 8, 2023 · 10.3 MB · Android API 1531 · code 58902

Imported from the F-Droid repository index.

WRITE_EXTERNAL_STORAGEREAD_EXTERNAL_STORAGEINTERNETACCESS_NETWORK_STATEACCESS_WIFI_STATENFCREAD_SYNC_SETTINGSWRITE_SYNC_SETTINGSFOREGROUND_SERVICECAMERAWAKE_LOCKRECEIVE_BOOT_COMPLETED

SHA-256 03c0ff9d09b547723a13889d221805e47b3279e35828bdb52ad6a1d04d45ea3a

Will it run on your device?

CompatibilityLikely to run

73%

  • Runs on a broad range of modern Android versions.
  • ABI coverage is focused on newer 64-bit devices.
What changed in this release
Size delta
-0.6 MB
Added permissions
None
Removed permissions
None

Installation Guide

1

Open Settings on your Android device

2

Go to Security → Unknown sources (or Install unknown apps)

3

Enable "Allow from this source" for your browser or file manager

4

Open the downloaded APK file from your Downloads folder

5

Tap "Install" and wait for installation to complete

6

Launch the app from your home screen

Make sure to re-enable Unknown Sources restrictions after installation for security.

How to install this safely

How to verify the file you downloaded

Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.

What the signing certificate proves

Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be org.sufficientlysecure.keychain is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.

How to roll back to an earlier version

If the current release misbehaves, 6.0.2 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall OpenKeychain: Easy PGP first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.

Why we list sources instead of hosting everything

The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of OpenKeychain: Easy PGP, and a listing is removed when the evidence for it stops holding up.

Get OpenKeychain: Easy PGP

Every source we list for org.sufficientlysecure.keychain is legality-reviewed. Pirated or cracked builds are never offered.

Other sources

F-Droid listing

official

F-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.

Source code

verified publisher

The upstream repository this build is compiled from.

We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.

App Information

Developer
F-Droid
Category
Security Privacy
Android
API 15+
Architectures
Version
6.0.4 (code 60400)
Size
11.5 MB
Updated
Mar 5, 2024
Package name
org.sufficientlysecure.keychain

Security Verification

File integrity
SHA-256 recorded
Signing certificate
Fingerprint on record
Official source
Download APK (v6.0.4)

We record provenance; we do not run malware scans. Verify the hash yourself before installing.

SHA-256 Hash

f88374b9113aa9ddba865258bd989eb3ac2ca1577d92e59d6e84228e080674ce

Signing certificate

2805a6f465acb923103a2ab3a145e1a97a74c44acf751250b588ebc3f88a0cc9

Permissions Required

READ_MEDIA_IMAGES
READ_MEDIA_VIDEO
READ_MEDIA_AUDIO
READ_EXTERNAL_STORAGE
POST_NOTIFICATIONS
INTERNET
ACCESS_NETWORK_STATE
ACCESS_WIFI_STATE
NFC
READ_SYNC_SETTINGS
WRITE_SYNC_SETTINGS
FOREGROUND_SERVICE
FOREGROUND_SERVICE_SPECIAL_USE
WAKE_LOCK
RECEIVE_BOOT_COMPLETED
CAMERA
org.sufficientlysecure.keychain.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Previous Versions

Signature verified

The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.

Report a problem with this listing

A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.

Report a problem