AgePony: Encrypt & Sign
Post-quantum file & message encryption with age. On-device, private, no ads.
NorseHorse File Encryption & Vault
Screenshots
Description
AgePony is a fast, private encryption app for your phone, built on the modern age encryption format. Lock your files and messages so only the right person can open them, sign them so recipients know the file really came from you, and keep your keys and data on your device. No accounts, no tracking, no analytics.
POST-QUANTUM ENCRYPTION
Protect your data against "harvest now, decrypt later" attacks. AgePony generates quantum-safe hybrid keys (ML-KEM-768 combined with X25519) that stay secure even against a future quantum computer, while staying fully interoperable with the age command-line tool. Anything encrypted to a quantum-safe recipient is clearly badged, so you always know the protection you are using.
Also included:
- Encrypt and sign in a single step, so recipients can both open your file and confirm it is really from you.
- A built-in migration tool to upgrade older files to quantum-safe encryption. Batch re-encrypt your existing files to a new quantum-safe key, with your originals kept until the new copy is verified.
WHY AGEPONY
- Standard age encryption. AgePony reads and writes the same format as the age CLI, so your files work with other age tools on desktop and server.
- Public key or passphrase. Encrypt to someone's public key, or lock a file with a passphrase you share separately.
- SSH signing, done properly. Sign and verify files from a dedicated Sign tab using SSH Ed25519 or RSA keys, a hardware key, or a security key over NFC, and keep a list of trusted signers. Signatures use the SSHSIG standard, so ssh-keygen verifies them.
- On device by default. Encryption, decryption, signing, and key generation all happen locally on your phone, and your private keys never leave your device.
- One optional online step. When you import a recipient from GitHub, AgePony fetches that person's public SSH keys from github.com. That is the only network request the app makes, it happens only when you tap Fetch, and nothing about you is sent.
- No tracking, no ads, no account required. AgePony does not collect analytics or personal data.
- Open source. The full source is available for review.
FEATURES
- Generate and store age key pairs in an app vault, unlocked with your device biometrics.
- Quantum-safe hybrid keys (ML-KEM-768 + X25519) alongside classic X25519 keys.
- Encrypt and decrypt files and text messages.
- Passphrase encryption for quick, key-free sharing.
- Sign and verify files (SSHSIG) with SSH Ed25519 or RSA keys, hardware keys, or a security key over NFC, with a trusted-signers list.
- Unlock with your biometric, a password, or a PIN, so the app works even with no screen lock set up.
- Optional duress password that wipes the vault when entered.
- Scan recipient keys with your camera by QR code.
- Import a recipient from a GitHub username, fetching their public SSH keys from github.com.
- Batch migrate existing files to quantum-safe encryption.
Whether you are a journalist, an activist, a developer, or simply someone who wants real control over their private files, AgePony gives you strong, standard encryption without the complexity.
AgePony is an independent app built on the open age encryption format and is not affiliated with the age project.
What’s new (4.1.1)
AgePony 4.1.1 fixes a lockout on password and PIN vaults.
- A vault protected by a password or device PIN, rather than a fingerprint, could fail to reopen after the app locked itself, showing a decryption error. The vault key was cleared from memory right after setup, so the first thing you saved was written under a blank key. It is fixed and covered by a test. A vault already affected by this cannot be opened by the new build and must be reset and set up again.
Versions
Permissions
What the app asks the system for. Android only grants sensitive access after you confirm it.
- Internet accessSend and receive data over the internet.
- CameraTake photos and videos.
- NFCExchange data via near field communication.
- BiometricsUnlock with fingerprint or face.
- FingerprintUnlock with a fingerprint.
- app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Comments