{"package_name":"com.pgpony.android","name":"PGPony","summary":"OpenPGP encryption with hardware security keys and password-store support","category":"Password & 2FA","icon_url":"/api/icon/com.pgpony.android","latest_version_code":448,"latest_version_name":"4.5.3","apk_url":"/api/apk/com.pgpony.android","apk_size":9481580,"apk_sha256":"85381b486459b97db61898759e1e9e9b9e6f3e6faf7d2d8bb040480762db16a1","source_kind":"fdroid-repo","repo_slug":"fdroid-main","last_updated":1790132417,"release_timestamp":1790107369,"description":"PGPony is an OpenPGP app for Android. Encrypt, decrypt, sign, and verify messages and files, manage your keyring, and use a hardware security key over NFC, all on device.\n\nFeatures:\n\n- Encrypt, decrypt, sign, and verify text and files\n- Post-quantum encryption: ML-KEM-768 + X25519 (Kyber) composite keys, in both the IETF draft (v6) and LibrePGP / GnuPG 2.5 (v5) formats\n- OpenPGP provider service: use PGPony as the crypto engine for Thunderbird for Android, K-9 Mail, and Password Store (OpenKeychain-compatible API)\n- Generate modern keys, including RFC 9580 (OpenPGP v6) Ed25519 and X25519, with Argon2id passphrase protection\n- Hardware security keys over NFC, including YubiKey 5 NFC and Token2, with on-card key generation, decrypt, sign, PIN management, and factory reset\n- Read your password-store (pass) entries, including those protected by a hardware key\n- Encrypted keyring backup and restore, including OpenKeychain backup import\n- PGP/MIME email: decrypt messages with attachments, compose encrypted .eml\n- Key discovery through WKD and the keys.openpgp.org verifying keyserver; optional Tor routing via Orbot\n- Optional contact integration for choosing recipients\n- QR import and scanning for keys\n- Default signing key, biometric lock, and secure-screen protection\n\nPost-quantum limitations:\n\nPost-quantum OpenPGP is still being standardized, so cross-tool support is limited:\n\n- LibrePGP-format (v5) keys interoperate with GnuPG 2.5+ today: messages encrypt and decrypt in both directions, and public keys import cleanly. GnuPG cannot yet import post-quantum PRIVATE keys from any app — it stores them in a proprietary internal format.\n- IETF-format (v6) keys implement draft-ietf-openpgp-pqc and are verified against the draft's official test vectors, but current Sequoia (sq) preview builds implement a different draft revision and cannot read them yet, and GnuPG does not support this format at all.\n- Classical keys (RSA, Ed25519, v4 and v6) are unaffected.\n\nPGPony does not us","categories":["Password & 2FA","Text Encryption"]}