{"package_name":"com.roufsyed.onekey","name":"1Key Password Manager","summary":"Offline password manager. 2FA + notes. No account, no network, no telemetry.","category":"Password & 2FA","icon_url":"/api/icon/com.roufsyed.onekey","latest_version_code":3,"latest_version_name":"1.1.1","apk_url":"/api/apk/com.roufsyed.onekey","apk_size":4738420,"apk_sha256":"690a58bb75780d9f835183ae6deb563e06db659218a4275ddd40ba15353d66ce","source_kind":"fdroid-repo","repo_slug":"fdroid-main","last_updated":1784397646,"release_timestamp":1784362608,"description":"1Key is a local-first password manager for Android. Your vault lives on your device, encrypted with a key only you hold, and never moves unless you export it yourself. There is no account to create, no server to breach, and no network connection of any kind — the INTERNET permission is stripped from the manifest, so the operating system itself enforces the offline guarantee.\n\n<b>Security</b>\n\n• Vault key derived from your master password with Argon2id (m=64 MiB, t=3, p=1 by default; configurable up to m=256 MiB, t=16)\n• Every credential field encrypted separately with AES-256-GCM, bound to its row and column via additional authenticated data — an attacker with raw database write access cannot swap ciphertexts between rows\n• Master-password verifier stored in EncryptedSharedPreferences, itself wrapped by an Android Keystore-bound key (TEE or StrongBox where available), so offline brute-force of a leaked device image is not possible\n• Optional 128-bit Secret Key mixed into the KDF for defense-in-depth against a compromised master password\n• Biometric unlock backed by hardware-secure key; requires master-password confirmation to enable\n• Tiered attempt limiting: 3, 5, and 10 wrong attempts trigger 30-second, 5-minute, and 1-hour cooldowns; counters survive process kills\n\n<b>Vault</b>\n\n• Store credentials with title, username, password, URL, notes, and custom fields\n• Tag-based organisation, favourites, full-text search\n• TOTP / 2FA codes stored in the same entry as the password they protect — no app switching\n• Live-preview Markdown in notes with a helper bar; disable in Settings if you prefer plain text\n• Soft-delete recycle bin (toggle off if you prefer immediate deletion)\n• Credential history preserves previous values on edit\n\n<b>Autofill</b>\n\n• System-level Autofill Service — fill logins into any app or browser without leaving them\n• URL-only matching by default (no fuzzy suggestions) to keep phishing risk down\n• Save prompt on submit; per-action confirmation for c","categories":["Password & 2FA","Security"]}