Keep

io.privkey.keep
by PrivKey privkey@NostrVerified.com

FROST threshold signer and Nostr event signer for Android

**Keep is a FROST (Flexible Round-Optimized Schnorr Threshold Signatures) threshold signing app and dedicated Nostr event signer for Android.** It allows users to hold FROST key shares on their phone and sign Nostr events without any single device ever holding the full private key. Keep implements the NIP-55 Android Signer protocol and NIP-46 remote signing, so any compatible Nostr client can request signatures directly. Keep keeps private key material segregated from client apps through NIP-55 and NIP-46, with per-app permissions, background signing, and multiple account support. It splits keys into FROST threshold shares (2-of-3, 3-of-5, etc.) so that no single device ever holds the complete private key. **Features:** - FROST threshold signing (2-of-3, 3-of-5, etc.) - NIP-55 Android Signer protocol (intents + content provider) - NIP-46 remote signing (bunker service) - Import and export FROST shares via QR code or text - Import existing nsec keys - Multiple account support - Per-app signing permissions and policies - Signing history and audit log - Biometric and PIN authentication - Hardware-backed key storage (Android Keystore) - Kill switch for emergency key deletion - SOCKS proxy support (Tor) - NIP-44 encryption and decryption - Background signing with configurable rate limits - Certificate pinning for relay connections - Encrypted backup and restore - Bitcoin wallet descriptor coordination (multisig)

First release: Feb 14, 2026, 11 total releases.

Most recent release: Aug 1, 2026.

Website Repo

Appears in 4 app stacks.

0 sats / 0 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Aug 1, 2026 1.2.0
    ## Highlights **A share migration cannot lose the share.** The legacy copy was erased once the destination had been resolved, which proves a name exists rather than that the data arrived. The destination is now read back and the share confirmed present before anything is deleted, so an interrupted or partially failed migration leaves the original in place rather than removing the only copy. **Stored values are bound to the key they were stored under.** An entry could previously be read back under a different key than the one it was written with, so a value moved or transplanted between entries would still decrypt and be accepted. Each value is now bound to its own key, and a transplanted entry is rejected instead of silently trusted. The registry entry is resolved in a single pass, so a second probe cannot confuse the lookup. **The co-signing prompt says what is asking, and whether that was proven.** The request label is shown in the prompt, and presented as a claim rather than a bare fact: it is qualified precisely when nothing verified it, so a label that was cryptographically established reads plainly while an unverified one cannot borrow that authority. A name on its own can no longer imply the request was checked. **AES-GCM cannot be handed an IV it did not generate.** `AndroidKeystoreStorage` no longer exposes an encrypt path that accepts a caller-supplied IV, making nonce reuse structurally impossible rather than merely avoided by convention. A `check-rng-hygiene.sh` gate enforces this in CI, counting `Cipher.init` arguments rather than matching a token pair, so a reintroduction fails the build.
    More…
    `keep.version` moves to keep [v0.9.1](https://github.com/privkeyio/keep/releases/tag/v0.9.1). That is load-bearing for this release rather than routine. The pinned core carries the entropy health check that now samples the OS source directly instead of only its mixed output, the FROST nonce replay guard, which previously had no caller marking a nonce used and so never rejected a repeated commitment, and `nostr-relay-pool` 0.44.2, which fixes a verification-cache bypass (RUSTSEC-2026-0224) that let a forged-signature event skip validation and be persisted as though checked. ## What's Changed Five commits since v1.1.9: a degraded RNG path failing closed rather than quietly (#470), legacy share retention until a copy is demonstrably stored (#469), stored values bound to their key (#468), the request label qualified only when nothing verified it (#467), and the request label shown in the co-sign prompt (#466). ## Install Download the APK for your device's architecture from the Assets section below. Min SDK 33 (Android 13+). - `keep-android-v1.2.0-arm64-v8a.apk` for physical devices - `keep-android-v1.2.0-x86_64.apk` for emulators and x86_64 hardware Both per-ABI APKs reproduce bit-for-bit from source: the Reproducibility workflow rebuilds each in a pinned container and compares it against the published artifact with `apksigcopier compare`, so a mismatch fails rather than passing quietly. ## Verify ```bash sha256sum -c SHA256SUMS ``` ## Full changelog https://github.com/privkeyio/keep-android/compare/v1.1.9...v1.2.0
  • Jul 30, 2026 1.1.9
    ## Highlights **Signing history keeps its order.** Entries in the signing audit chain can no longer be recorded with a timestamp earlier than the entry before them. The chain's order was always fixed by its hash linkage, but the recorded times came from the wall clock, so a clock correction or a changed device clock could make one approval read as preceding another. The correction is bounded, so a single entry stamped far in the future cannot silently pin every later one to that time. **Backup restore keeps what the backup recorded.** Restoring a share previously marked it backed up regardless of what the backup said, which suppressed the reminder to back up a share that never had been. Each share now keeps its recorded state, and a restored key is treated as not yet backed up rather than claiming otherwise. **Encrypted preferences recover entries they used to lose.** Stored key names are derived from a per-file key, and when that key could not be persisted the store fell back to a deterministic one. Entries and the key registry written during such a window became unreachable afterwards, and the next write could drop every key it had not touched from the registry. Both are now found and consolidated, with an unreadable copy preserved rather than replaced. **Signer storage reports faults instead of hiding them.** The rate-limiter backend now distinguishes a counter that is absent from one that could not be read, and reports whether a write actually reached disk. The core refuses to auto-sign rather than treating an unreadable ceiling as an empty one, so a storage fault can no longer quietly widen how much gets signed without asking.
    More…
    **NIP-44 v3** is wired across the NIP-55 content-provider and intent transports, surfaced in the bunker approval screen and activity log, and accepted when reopening a signing request from a notification. **Sign policy**, including the Basic tier, is now passed through as selected instead of collapsing onto Auto, and the global selection lives in the core-owned store. `keep.version` moves to keep v0.9.0. Unlike v1.1.8, this release does change signing behavior: the audit ordering fix above is in the pinned core. Both per-ABI APKs continue to reproduce bit-for-bit from source. ## What's Changed Fifty-three commits since v1.1.8. Beyond the above: a rotate-URL action to revoke a leaked bunker URL (#413), NIP-98 method and URL shown in the bunker approval screen (#417), staged and retired backup certificate pins (#419), failing closed rather than connecting without a proxy when proxy start fails (#420), revoking old permissions before activating a new share on switch (#422), private-key exports recorded in the tamper-evident activity log (#412), and a bounded blocking rate-limiter call on the auto-sign path (#448). **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v1.1.8...v1.1.9
  • Jul 11, 2026 1.1.8
    ## Highlights **First-run onboarding.** New installs now get a short first-run flow that introduces FROST key shares and lets you pick a signing policy (Manual, Basic, or Auto) during setup, so the threshold-signing model and per-request approval behavior are clear before the first signature. **F-Droid listing.** The store listing now carries app screenshots and per-release changelogs. F-Droid reads this metadata from the release tag, so v1.1.8 is the first build whose screenshots and "What's New" populate the F-Droid page. No cryptographic or signing changes since v1.1.7 (`keep.version` is unchanged). Both per-ABI APKs continue to reproduce bit-for-bit from source. ## What's Changed * onboarding: add first-run FROST/share guidance and sign-policy choice (#295) by @wksantiago in https://github.com/privkeyio/keep-android/pull/395
    More…
    * fastlane: add missing per-ABI changelogs for v1.1.6 and v1.1.7 by @kwsantiago in https://github.com/privkeyio/keep-android/pull/404 * fastlane: add phone screenshots for F-Droid listing (#405) by @wksantiago in https://github.com/privkeyio/keep-android/pull/406 * Release v1.1.8 by @kwsantiago in https://github.com/privkeyio/keep-android/pull/407 **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v1.1.7...v1.1.8
  • Jun 14, 2026 1.1.4
    ## What's Changed * Release v1.1.4: align reproducible build to F-Droid environment (trixie + JDK 21) by @kwsantiago in https://github.com/privkeyio/keep-android/pull/351 **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v1.1.3...v1.1.4
  • Jun 10, 2026 1.0.5
    ## Highlights - **Pins keep to v0.4.8**: ECDH and signing race fixes, persistent NIP-46 grants CLI, hidden-vault grant support, audit-log expansion. Full keep v0.4.8 notes: https://github.com/privkeyio/keep/releases/tag/v0.4.8. - **Bunker init race fix** (#296): bunker handshake no longer drops the first event under load; pending approvals now trigger a notification. - **UI/UX overhaul** (#293): design tokens, shared components, consistent screens across the app. - **Live activity log** (#292) for relay, bunker, and peer events. - **Authorized Clients populated from bunker onConnect** (#291) with foreground-service and crash fixes. - **onConnect callback** wired up in the bunker FFI binding (#290). - **keep-mobile is now the single source of truth for the kill switch** (#284). - **Share rename writes canonical metadata**, not just prefs (#283).
    More…
    ## Install Download `keep-android-v1.0.5.apk` from the Assets section below. Min SDK 33 (Android 13+). ## Verify ```bash sha256sum -c SHA256SUMS ``` ## Full changelog https://github.com/privkeyio/keep-android/compare/v1.0.4...v1.0.5
  • Apr 21, 2026 1.0.0
    ## What's Changed * Build(deps): bump net.zetetic:sqlcipher-android from 4.14.0 to 4.14.1 in the minor-and-patch group by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/207 * Build(deps): bump the all group with 3 updates by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/208 * Bump version to v0.6.3 by @wksantiago in https://github.com/privkeyio/keep-android/pull/211 * Improve biometric and signing error messages across all flows by @kwsantiago in https://github.com/privkeyio/keep-android/pull/212 * Add create account, mnemonic recovery, and rename Account tab to Keys by @wksantiago in https://github.com/privkeyio/keep-android/pull/213 * Add NIP-49 ncryptsec export for single-key shares by @wksantiago in https://github.com/privkeyio/keep-android/pull/217 * Add seed word backup verification and retrieval by @wksantiago in https://github.com/privkeyio/keep-android/pull/218 * Add export and share logs by @wksantiago in https://github.com/privkeyio/keep-android/pull/220 * Wire build-rust.sh into Gradle preBuild by @kwsantiago in https://github.com/privkeyio/keep-android/pull/221
    More…
    * Enforce exact toolchain versions by @wksantiago in https://github.com/privkeyio/keep-android/pull/231 * Pin keep repo commit SHA with CI and Gradle verification by @wksantiago in https://github.com/privkeyio/keep-android/pull/232 * Add bit-for-bit APK reproducibility by @wksantiago in https://github.com/privkeyio/keep-android/pull/233 * Add automated reproducibility check workflow by @wksantiago in https://github.com/privkeyio/keep-android/pull/235 * Cache Rust build artifacts in CI by @wksantiago in https://github.com/privkeyio/keep-android/pull/237 * Externalize all Compose strings to strings.xml (#229) by @wksantiago in https://github.com/privkeyio/keep-android/pull/236 * Seed initial translations for pt-BR, es, de, ja by @wksantiago in https://github.com/privkeyio/keep-android/pull/240 * Add reproducible build recipe with pinned, verified toolchain by @wksantiago in https://github.com/privkeyio/keep-android/pull/241 * Replace Google ML Kit with ZXing by @wksantiago in https://github.com/privkeyio/keep-android/pull/248 * Build(deps): bump the all group with 4 updates by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/239 * Build(deps): bump com.android.application from 9.1.0 to 9.1.1 in the minor-and-patch group across 1 directory by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/238 * Add exodus-privacy scan report (0 trackers) by @kwsantiago in https://github.com/privkeyio/keep-android/pull/252 * Release v1.0.0 by @kwsantiago in https://github.com/privkeyio/keep-android/pull/253 **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v0.6.3...v1.0.0
  • Apr 8, 2026 0.6.3
    ## What's Changed * Fix nsec import StrongBox fallback by @wksantiago in https://github.com/privkeyio/keep-android/pull/209 **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v0.6.2...v0.6.3
  • Apr 7, 2026 0.6.2
    ## What's Changed * Build(deps): bump taiki-e/install-action from 2.68.18 to 2.68.26 in the all group by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/195 * Build(deps): bump gradle-wrapper from 9.3.1 to 9.4.0 in the minor-and-patch group by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/196 * Security hardening by @kwsantiago in https://github.com/privkeyio/keep-android/pull/197 * Build(deps): bump the all group across 1 directory with 7 updates by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/200 * Build(deps): bump the minor-and-patch group across 1 directory with 9 updates by @dependabot[bot] in https://github.com/privkeyio/keep-android/pull/202 * Fix NIP-55 signer and harden against untrusted input by @wksantiago in https://github.com/privkeyio/keep-android/pull/203 * Add account section features by @wksantiago in https://github.com/privkeyio/keep-android/pull/204 * Bump version to v0.6.2 by @wksantiago in https://github.com/privkeyio/keep-android/pull/206
    More…
    **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v0.6.1...v0.6.2
  • Mar 5, 2026 0.6.1
    ## What's Changed * Switch license from AGPL-3.0 to MIT by @kwsantiago in https://github.com/privkeyio/keep-android/pull/191 * Filter ABIs to arm64-v8a and x86_64 only by @wksantiago in https://github.com/privkeyio/keep-android/pull/192 **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v0.6.0...v0.6.1
  • Mar 5, 2026 0.6.0
    ## What's New ### Wallet Descriptor Management - Add wallet descriptor coordination and management UI - XpubAnnounce and key proof support in WDC flow - Fix descriptor card display after coordination ### Backup & Restore - New backup/restore UI with biometric authentication - Nsec recovery screen for key recovery
    More…
    ### Cross-Platform QR - Animated QR frame generation for cross-platform use ### Signing Audit - Signing audit storage with chain verification and history screen ### Security & Compliance - Security hardening and P10 compliance fixes - Adopt Rust-driven shared state, drop duplicated Kotlin logic ### Other Improvements - Handle bunker URL paste in relay dialog - Fix share-aware decryption in export cipher callback - Dependency updates (Room 2.8, Gradle 9.3, AGP 9.0, Compose BOM 2026.02) **Full Changelog**: https://github.com/privkeyio/keep-android/compare/v0.5.2...v0.6.0
  • Feb 14, 2026 0.5.2