Skip to content

Passchain

F-Droid

Open source

Use security key with Bluetooth, NFC, USB or your phone secure element

Version
1.0.1
Size
3.3 MB
Updated
Jun 10, 2026
Get from Download APK (v1.0.1)
Signing certificate on record

About this app

Passchain is a credential provider that allows you to use your USB/NFC security key or your phone secure element for passkeys/fido2/u2f authentication.

Bluetooth keys aren't supported yet.

This app doesn't need the Play Services.

Once installed, go to your system settings > Passwords, passkeys and accounts, then enable Passchain.

Licensed under Apache-2.0, by S1m.

OfficialSignature VerifiedOpen Source

What's New in v1.0.1

Imported from the F-Droid repository index.

  • - Fix authentication on websites with `appid` extension (like Gitlab)
  • - Fix registration on Chromium-based browsers
  • - Authorize WebLibre
  • - Add cs, de, fr, zh translations
  • - Minor bugfixes

Version history

v1.0.1Latest
Signature continuous

Jun 10, 2026 · 3.3 MB · Android API 3436 · code 10

Imported from the F-Droid repository index.

  • - Fix authentication on websites with `appid` extension (like Gitlab)
  • - Fix registration on Chromium-based browsers
  • - Authorize WebLibre
  • - Add cs, de, fr, zh translations
  • - Minor bugfixes
QUERY_ALL_PACKAGESACCESS_FINE_LOCATIONACCESS_COARSE_LOCATIONINTERNETUSE_BIOMETRICUSE_FINGERPRINTNFCMANAGE_USBSTART_ACTIVITIES_FROM_BACKGROUNDBLUETOOTHBLUETOOTH_ADMINBLUETOOTH_ADVERTISEBLUETOOTH_CONNECTBLUETOOTH_SCANINTERACT_ACROSS_PROFILESINTERACT_ACROSS_USERSs1m.hwfido2provider.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 83405624fd0cf981644a10cc2c668b9cf43dee7e27cf828db498b060243cad12

v1.0.0
Signature continuous

Jun 5, 2026 · 3.3 MB · Android API 3436 · code 9

Imported from the F-Droid repository index.

  • - 1.0.0 !
  • - The application is renamed *Passchain*
  • - Add user interface to help setting up the settings
  • - Bump microG library:
  • - Add support for cross-device authentication: you can login on another device, or from another device!
  • - Add entries to directly login with an on-device credential, or another method (NFC/USB)
QUERY_ALL_PACKAGESACCESS_FINE_LOCATIONACCESS_COARSE_LOCATIONINTERNETUSE_BIOMETRICUSE_FINGERPRINTNFCMANAGE_USBSTART_ACTIVITIES_FROM_BACKGROUNDBLUETOOTHBLUETOOTH_ADMINBLUETOOTH_ADVERTISEBLUETOOTH_CONNECTBLUETOOTH_SCANINTERACT_ACROSS_PROFILESINTERACT_ACROSS_USERSs1m.hwfido2provider.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 6b8607c6f7dc3b5a323bd7fbb93b09046a54bc30eea66f3c8f5a02dbe08aaab4

Will it run on your device?

CompatibilityLikely to run

74%

  • Targets newer Android builds, so legacy devices may be excluded.
  • Multiple CPU architectures are covered.
  • Aligned with the latest Android target SDK expectations.
What changed in this release
Size delta
0 MB
Added permissions
None
Removed permissions
None

Installation Guide

1

Open Settings on your Android device

2

Go to Security → Unknown sources (or Install unknown apps)

3

Enable "Allow from this source" for your browser or file manager

4

Open the downloaded APK file from your Downloads folder

5

Tap "Install" and wait for installation to complete

6

Launch the app from your home screen

Make sure to re-enable Unknown Sources restrictions after installation for security.

How to install this safely

How to verify the file you downloaded

Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.

What the signing certificate proves

Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be s1m.hwfido2provider is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.

How to roll back to an earlier version

If the current release misbehaves, 1.0.0 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Passchain first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.

Why we list sources instead of hosting everything

The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Passchain, and a listing is removed when the evidence for it stops holding up.

Get Passchain

Every source we list for s1m.hwfido2provider is legality-reviewed. Pirated or cracked builds are never offered.

Other sources

F-Droid listing

official

F-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.

Source code

verified publisher

The upstream repository this build is compiled from.

We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.

App Information

Developer
F-Droid
Category
Security Privacy
Android
14+
Architectures
arm64-v8a, armeabi-v7a, x86, x86_64
Version
1.0.1 (code 10)
Size
3.3 MB
Updated
Jun 10, 2026
Package name
s1m.hwfido2provider

Security Verification

File integrity
SHA-256 recorded
Signing certificate
Fingerprint on record
Official source
Download APK (v1.0.1)

We record provenance; we do not run malware scans. Verify the hash yourself before installing.

SHA-256 Hash

83405624fd0cf981644a10cc2c668b9cf43dee7e27cf828db498b060243cad12

Signing certificate

94bd36ba4648d38697cdfcf3385b6c0088ff3d551ce9fc16050ee080b9553ec5

Permissions Required

QUERY_ALL_PACKAGES
ACCESS_FINE_LOCATION
ACCESS_COARSE_LOCATION
INTERNET
USE_BIOMETRIC
USE_FINGERPRINT
NFC
MANAGE_USB
START_ACTIVITIES_FROM_BACKGROUND
BLUETOOTH
BLUETOOTH_ADMIN
BLUETOOTH_ADVERTISE
BLUETOOTH_CONNECT
BLUETOOTH_SCAN
INTERACT_ACROSS_PROFILES
INTERACT_ACROSS_USERS
s1m.hwfido2provider.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Previous Versions

Signature verified

The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.

Report a problem with this listing

A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.

Report a problem