Android-pass is the Kotlin source repository for the Proton Pass Android password manager, a GPL-3.0-licensed client published by Proton for Android developers, security reviewers, translators and anyone who wants to build, inspect or audit the application rather than trust a compiled binary from an app store.
What it is
This repository contains the source code for the Proton Pass Android application. The code is written in Kotlin and released under the GNU General Public License, version 3 or later; the README states that both the code and the data files in the distribution carry that licence. The registry files it under Security & Privacy / Identity & Access Management (IAM), and the project's own topics place it in the Proton ecosystem alongside end-to-end-encryption and password-manager. It is distributed through two channels that share the same upstream source: a Google Play listing at proton.android.pass and an F-Droid package at proton.android.pass.fdroid.
The concrete problem it addresses is source availability for an app that holds credentials. What a user installs from a store is a compiled artefact; what this repository provides is the code that artefact was built from, together with the instructions to reproduce the build. It replaces the store-only model in which a password manager's behaviour on the device can be taken only on the vendor's word. The repository root is deliberately thin: the README does not attempt a feature tour, and instead routes readers to docs/public/BUILD.md for local builds, CONTRIBUTING.md for contributions, and Proton's translation community blog post for localisation work. The substance is the code itself.
Key capabilities
- Full Kotlin source for the Proton Pass Android client, with local build steps documented in
docs/public/BUILD.md.
- Two independent distribution paths: the Google Play package
proton.android.pass and the F-Droid package proton.android.pass.fdroid.
- Tagged with end-to-end-encryption, reflecting the design property applied to the data the client handles.
- Licensed under GPL-3.0-or-later, covering both source code and data files in the distribution.
- A contributor workflow described in
CONTRIBUTING.md, so external patches have a defined route in.
- A translation programme run through Proton's community process rather than through the code repository alone.
- A small public backlog of four open issues, indicating a tidy tracker rather than an overflowing one.
Who uses it and how
- Android developers who want to compile the client themselves, following the build documentation rather than installing a store build.
- Security reviewers and auditors who read the Kotlin source to check how a credential-holding app behaves on the device.
- Translators contributing localisations through Proton's community translation programme.
- F-Droid users who prefer a catalogue that does not depend on Google Play, installing
proton.android.pass.fdroid.
- Fork maintainers — the repository has 75 forks — who build on the client code under the terms of the GPL.
Getting started
Build the app locally by following the instructions in docs/public/BUILD.md, as the README directs. For everyday use rather than development, the README points to the Google Play and F-Droid listings, where the compiled application is available.
How it compares
No comparable tool is named in the facts provided for this registry entry, so android-pass stands alone here. It is the official upstream Android client for Proton Pass rather than a third-party reimplementation of another product.
When to use it — and when not to
A self-builder needs a working Android toolchain and has to treat docs/public/BUILD.md as the real entry point, because the README itself is sparse and offers no architecture overview. Anyone who simply wants a password manager on a phone should install from Google Play or F-Droid instead of building, and anyone looking for the server side, a desktop client or an iOS client will not find it in this repository. The GPL-3.0 terms also mean that redistributed forks carry copyleft obligations.