圖標

PGPony

OpenPGP encryption with hardware security keys and password-store support
新版本 4.2.1
Fixes encrypting to a key by one of its extra identities. Multiple identities per key shipped in 4.2.0, but a mail client could only find a key by its primary address, so encrypting to a secondary identity failed to find the key. It now matches any identity on the key.
PGPony is an OpenPGP app for Android. Encrypt, decrypt, sign, and verify messages and files, manage your keyring, and use a hardware security key over NFC, all on device.

Features:

- Encrypt, decrypt, sign, and verify text and files
- Post-quantum encryption: ML-KEM-768 + X25519 (Kyber) composite keys, in both the IETF draft (v6) and LibrePGP / GnuPG 2.5 (v5) formats
- OpenPGP provider service: use PGPony as the crypto engine for Thunderbird for Android, K-9 Mail, and Password Store (OpenKeychain-compatible API)
- Generate modern keys, including RFC 9580 (OpenPGP v6) Ed25519 and X25519, with Argon2id passphrase protection
- Hardware security keys over NFC, including YubiKey 5 NFC and Token2, with on-card key generation, decrypt, sign, PIN management, and factory reset
- Read your password-store (pass) entries, including those protected by a hardware key
- Encrypted keyring backup and restore, including OpenKeychain backup import
- PGP/MIME email: decrypt messages with attachments, compose encrypted .eml
- Key discovery through WKD and the keys.openpgp.org verifying keyserver; optional Tor routing via Orbot
- Optional contact integration for choosing recipients
- QR import and scanning for keys
- Default signing key, biometric lock, and secure-screen protection

Post-quantum limitations:

Post-quantum OpenPGP is still being standardized, so cross-tool support is limited:

- LibrePGP-format (v5) keys interoperate with GnuPG 2.5+ today: messages encrypt and decrypt in both directions, and public keys import cleanly. GnuPG cannot yet import post-quantum PRIVATE keys from any app — it stores them in a proprietary internal format.
- IETF-format (v6) keys implement draft-ietf-openpgp-pqc and are verified against the draft's official test vectors, but current Sequoia (sq) preview builds implement a different draft revision and cannot read them yet, and GnuPG does not support this format at all.
- Classical keys (RSA, Ed25519, v4 and v6) are unaffected.

PGPony does not use accounts, ads, analytics, or tracking. The F-Droid build contains no Google services and runs fully on de-Googled devices.

The cryptographic core is published separately as open source (PGPonyCore-Kotlin), and the full app source is available under the Apache-2.0 license.

版本

雖然在下方可選擇下載 APK 檔案,但要留意這樣的安裝方式將不會收到更新通知,是一種較不安全的下載方法。建議您先安裝 F-Droid 用戶端使用。

下載 F-Droid
  • 版本 4.2.1 (421) 建議 於 2026 年 8 月 19 日新增

    arm64-v8a armeabi-v7a x86 x86_64

    此版本需要 Android 8.0 或更高的版本。

    此套件包由原開發者建置和簽署,並保證與此原始碼 Tarball 保持一致。

    權限
    • 查看網路連線
      允許應用程式查看網路連線相關資訊,像是有哪些網路,以及有沒有連上。
    • 拍攝相片和影片
      這個應用程式在使用期間可以使用相機拍照及錄影。
    • 執行前景服務
      允許應用程式使用前景服務。
    • 擁有完整的網路存取權
      允許應用程式建立網路通訊端及使用自訂網路通訊協定。瀏覽器和其他應用程式會提供將資料傳輸到網際網路的方法,因此不需要這項權限也能將資料傳輸到網際網路。
    • 控制近距離無線通訊
      允許應用程式與近距離無線通訊 (NFC) 電子感應標籤、卡片及感應器進行通訊。
    • 顯示通知
      允許應用程式顯示通知
    • 讀取你的聯絡人
      允許應用程式讀取手機上儲存的聯絡人資料。如果你已在手機上的帳戶建立聯絡人,應用程式也將可以存取這些帳戶,當中可能包括你安裝的應用程式所建立的帳戶。這項權限可讓應用程式儲存你的聯絡人資料,惡意應用程式也可能在你不知情的情況下外洩你的聯絡人資料。
    • 啟動時執行
      允許應用程式在系統完成開機程序後立刻自行啟動。這會增加手機的開機時間,而且會因為系統一直執行該應用程式導致手機的整體運作速度變慢。
    • 使用生物識別硬體
      允許應用程式使用生物特徵硬體進行驗證
    • 使用指紋硬體
      允許應用程式使用指紋硬體進行驗證
    • 防止手機休眠
      允許應用程式防止手機進入休眠狀態。
    • com.pgpony.android.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

    下載 APK 14 MiB PGP 簽章 | 建置紀錄

  • 新版本 4.2.0
    PGPony 4.2.0 adds the ML-KEM 1024 hybrid suite beside 768, multiple identities per key, subkey display and creation, per-key fallback decryption keys and signing defaults, and reorganized Settings. Files and bundles of any size now stream without crashes. Deleting keys and clearing data are heavily safeguarded. If you generated a 768 key before 4.2.0, the app will suggest regenerating it for gpg compatibility. Mail clients without v6 support need a classical signing default. iOS parity lands in
  • 版本 4.2.0 (420) - 於 2026 年 8 月 17 日新增

    arm64-v8a armeabi-v7a x86 x86_64

    此版本需要 Android 8.0 或更高的版本。

    此套件包由原開發者建置和簽署,並保證與此原始碼 Tarball 保持一致。

    權限
    • 查看網路連線
      允許應用程式查看網路連線相關資訊,像是有哪些網路,以及有沒有連上。
    • 拍攝相片和影片
      這個應用程式在使用期間可以使用相機拍照及錄影。
    • 執行前景服務
      允許應用程式使用前景服務。
    • 擁有完整的網路存取權
      允許應用程式建立網路通訊端及使用自訂網路通訊協定。瀏覽器和其他應用程式會提供將資料傳輸到網際網路的方法,因此不需要這項權限也能將資料傳輸到網際網路。
    • 控制近距離無線通訊
      允許應用程式與近距離無線通訊 (NFC) 電子感應標籤、卡片及感應器進行通訊。
    • 顯示通知
      允許應用程式顯示通知
    • 讀取你的聯絡人
      允許應用程式讀取手機上儲存的聯絡人資料。如果你已在手機上的帳戶建立聯絡人,應用程式也將可以存取這些帳戶,當中可能包括你安裝的應用程式所建立的帳戶。這項權限可讓應用程式儲存你的聯絡人資料,惡意應用程式也可能在你不知情的情況下外洩你的聯絡人資料。
    • 啟動時執行
      允許應用程式在系統完成開機程序後立刻自行啟動。這會增加手機的開機時間,而且會因為系統一直執行該應用程式導致手機的整體運作速度變慢。
    • 使用生物識別硬體
      允許應用程式使用生物特徵硬體進行驗證
    • 使用指紋硬體
      允許應用程式使用指紋硬體進行驗證
    • 防止手機休眠
      允許應用程式防止手機進入休眠狀態。
    • com.pgpony.android.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

    下載 APK 14 MiB PGP 簽章 | 建置紀錄

  • 新版本 4.1.1
    Fixes creating a key at a large display or font size. The onboarding slides could not scroll, so on phones set to a bigger display or font scale the Create Key button could sit below the screen edge with no way to reach it. The bundle encryption result and the biometric lock screen had the same missing scroll and got the same fix. Nothing changes at default display settings.
  • 版本 4.1.1 (411) - 於 2026 年 8 月 14 日新增

    arm64-v8a armeabi-v7a x86 x86_64

    此版本需要 Android 8.0 或更高的版本。

    此套件包由原開發者建置和簽署,並保證與此原始碼 Tarball 保持一致。

    權限
    • 查看網路連線
      允許應用程式查看網路連線相關資訊,像是有哪些網路,以及有沒有連上。
    • 拍攝相片和影片
      這個應用程式在使用期間可以使用相機拍照及錄影。
    • 執行前景服務
      允許應用程式使用前景服務。
    • 擁有完整的網路存取權
      允許應用程式建立網路通訊端及使用自訂網路通訊協定。瀏覽器和其他應用程式會提供將資料傳輸到網際網路的方法,因此不需要這項權限也能將資料傳輸到網際網路。
    • 控制近距離無線通訊
      允許應用程式與近距離無線通訊 (NFC) 電子感應標籤、卡片及感應器進行通訊。
    • 顯示通知
      允許應用程式顯示通知
    • 讀取你的聯絡人
      允許應用程式讀取手機上儲存的聯絡人資料。如果你已在手機上的帳戶建立聯絡人,應用程式也將可以存取這些帳戶,當中可能包括你安裝的應用程式所建立的帳戶。這項權限可讓應用程式儲存你的聯絡人資料,惡意應用程式也可能在你不知情的情況下外洩你的聯絡人資料。
    • 啟動時執行
      允許應用程式在系統完成開機程序後立刻自行啟動。這會增加手機的開機時間,而且會因為系統一直執行該應用程式導致手機的整體運作速度變慢。
    • 使用生物識別硬體
      允許應用程式使用生物特徵硬體進行驗證
    • 使用指紋硬體
      允許應用程式使用指紋硬體進行驗證
    • 防止手機休眠
      允許應用程式防止手機進入休眠狀態。
    • com.pgpony.android.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

    下載 APK 14 MiB PGP 簽章 | 建置紀錄