PGPony
OpenPGP encryption with hardware security keys and password-store support
新版本 4.2.1
Fixes encrypting to a key by one of its extra identities. Multiple identities per key shipped in 4.2.0, but a mail client could only find a key by its primary address, so encrypting to a secondary identity failed to find the key. It now matches any identity on the key.
PGPony is an OpenPGP app for Android. Encrypt, decrypt, sign, and verify messages and files, manage your keyring, and use a hardware security key over NFC, all on device.
Features:
- Encrypt, decrypt, sign, and verify text and files
- Post-quantum encryption: ML-KEM-768 + X25519 (Kyber) composite keys, in both the IETF draft (v6) and LibrePGP / GnuPG 2.5 (v5) formats
- OpenPGP provider service: use PGPony as the crypto engine for Thunderbird for Android, K-9 Mail, and Password Store (OpenKeychain-compatible API)
- Generate modern keys, including RFC 9580 (OpenPGP v6) Ed25519 and X25519, with Argon2id passphrase protection
- Hardware security keys over NFC, including YubiKey 5 NFC and Token2, with on-card key generation, decrypt, sign, PIN management, and factory reset
- Read your password-store (pass) entries, including those protected by a hardware key
- Encrypted keyring backup and restore, including OpenKeychain backup import
- PGP/MIME email: decrypt messages with attachments, compose encrypted .eml
- Key discovery through WKD and the keys.openpgp.org verifying keyserver; optional Tor routing via Orbot
- Optional contact integration for choosing recipients
- QR import and scanning for keys
- Default signing key, biometric lock, and secure-screen protection
Post-quantum limitations:
Post-quantum OpenPGP is still being standardized, so cross-tool support is limited:
- LibrePGP-format (v5) keys interoperate with GnuPG 2.5+ today: messages encrypt and decrypt in both directions, and public keys import cleanly. GnuPG cannot yet import post-quantum PRIVATE keys from any app — it stores them in a proprietary internal format.
- IETF-format (v6) keys implement draft-ietf-openpgp-pqc and are verified against the draft's official test vectors, but current Sequoia (sq) preview builds implement a different draft revision and cannot read them yet, and GnuPG does not support this format at all.
- Classical keys (RSA, Ed25519, v4 and v6) are unaffected.
PGPony does not use accounts, ads, analytics, or tracking. The F-Droid build contains no Google services and runs fully on de-Googled devices.
The cryptographic core is published separately as open source (PGPonyCore-Kotlin), and the full app source is available under the Apache-2.0 license.
Features:
- Encrypt, decrypt, sign, and verify text and files
- Post-quantum encryption: ML-KEM-768 + X25519 (Kyber) composite keys, in both the IETF draft (v6) and LibrePGP / GnuPG 2.5 (v5) formats
- OpenPGP provider service: use PGPony as the crypto engine for Thunderbird for Android, K-9 Mail, and Password Store (OpenKeychain-compatible API)
- Generate modern keys, including RFC 9580 (OpenPGP v6) Ed25519 and X25519, with Argon2id passphrase protection
- Hardware security keys over NFC, including YubiKey 5 NFC and Token2, with on-card key generation, decrypt, sign, PIN management, and factory reset
- Read your password-store (pass) entries, including those protected by a hardware key
- Encrypted keyring backup and restore, including OpenKeychain backup import
- PGP/MIME email: decrypt messages with attachments, compose encrypted .eml
- Key discovery through WKD and the keys.openpgp.org verifying keyserver; optional Tor routing via Orbot
- Optional contact integration for choosing recipients
- QR import and scanning for keys
- Default signing key, biometric lock, and secure-screen protection
Post-quantum limitations:
Post-quantum OpenPGP is still being standardized, so cross-tool support is limited:
- LibrePGP-format (v5) keys interoperate with GnuPG 2.5+ today: messages encrypt and decrypt in both directions, and public keys import cleanly. GnuPG cannot yet import post-quantum PRIVATE keys from any app — it stores them in a proprietary internal format.
- IETF-format (v6) keys implement draft-ietf-openpgp-pqc and are verified against the draft's official test vectors, but current Sequoia (sq) preview builds implement a different draft revision and cannot read them yet, and GnuPG does not support this format at all.
- Classical keys (RSA, Ed25519, v4 and v6) are unaffected.
PGPony does not use accounts, ads, analytics, or tracking. The F-Droid build contains no Google services and runs fully on de-Googled devices.
The cryptographic core is published separately as open source (PGPonyCore-Kotlin), and the full app source is available under the Apache-2.0 license.
版本
雖然在下方可選擇下載 APK 檔案,但要留意這樣的安裝方式將不會收到更新通知,是一種較不安全的下載方法。建議您先安裝 F-Droid 用戶端使用。
下載 F-Droid-
arm64-v8aarmeabi-v7ax86x86_64此版本需要 Android 8.0 或更高的版本。
此套件包由原開發者建置和簽署,並保證與此原始碼 Tarball 保持一致。
-
arm64-v8aarmeabi-v7ax86x86_64此版本需要 Android 8.0 或更高的版本。
此套件包由原開發者建置和簽署,並保證與此原始碼 Tarball 保持一致。
-
arm64-v8aarmeabi-v7ax86x86_64此版本需要 Android 8.0 或更高的版本。
此套件包由原開發者建置和簽署,並保證與此原始碼 Tarball 保持一致。
新版本 4.2.0
PGPony 4.2.0 adds the ML-KEM 1024 hybrid suite beside 768, multiple identities per key, subkey display and creation, per-key fallback decryption keys and signing defaults, and reorganized Settings. Files and bundles of any size now stream without crashes. Deleting keys and clearing data are heavily safeguarded. If you generated a 768 key before 4.2.0, the app will suggest regenerating it for gpg compatibility. Mail clients without v6 support need a classical signing default. iOS parity lands in
新版本 4.1.1
Fixes creating a key at a large display or font size. The onboarding slides could not scroll, so on phones set to a bigger display or font scale the Create Key button could sit below the screen edge with no way to reach it. The bundle encryption result and the biometric lock screen had the same missing scroll and got the same fix. Nothing changes at default display settings.




