
Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted ABLBX backups. Developed by Ebrahim Shafiei (EbraSha).
🌐 Read in your language: 🇬🇧 English | 🇨🇳 中文 | 🇷🇺 Русский | 🇪🇸 Español | 🇯🇵 日本語 | 🇮🇷 فارسی | 🇸🇦 العربية | 🇹🇷 Türkçe | 🇩🇪 Deutsch | 🇮🇳 हिन्दी
Secure. Store. Autofill. — A privacy-first Android password manager by Abdal Security Group.
Abdal LockBox keeps your credentials encrypted on your device, fills logins through the official Android Autofill framework, and backs up your vault with the portable .ablbx encrypted format — without sending vault secrets to a cloud backend.
Most people store passwords in browsers, notes apps, or cloud services they do not fully control. That creates a real risk: one breach, sync leak, or device extraction can expose an entire credential map.
Abdal LockBox was built to solve a practical problem:
.ablbx formatThe goal is a lightweight, security-oriented password manager that respects privacy and follows modern Android engineering practices (Jetpack Compose, Room, DataStore, authenticated encryption).
FLAG_SECURE) across screens, dialogs, and sheetsandroid:allowBackup="false" — Android cloud backup disabled for app data.ablbx file (passphrase-protected)1.3.6.1.4.1.66033.1.2.2.1Abdal LockBox follows a local-first, offline-first security model:
| Principle | How it is applied |
|---|---|
| 🔐 No plaintext secrets on disk | Credentials and settings are encrypted before persistence |
| 🧠 Layered keys | Master Password / Recovery Key derive KEKs; DEK encrypts vault data |
| ✅ Authenticated encryption | AES-256-GCM with AAD bound to vault context |
| 🧩 Separated lookup index | HMAC-SHA-256 domain/package hashes for autofill matching |
| 🚫 No cloud vault sync | Vault workflow does not depend on a remote password server |
| 🪟 Screen protection | Optional secure windows block screenshots and recordings |
| 💣 Duress wipe | Self-Destruct erases vault data without revealing the wipe |
Abdal LockBox uses a layered key model. Passwords and metadata are never stored in plaintext on disk.
flowchart TB
MP[Master Password] -->|KDF| KEK[KEK — Key Encryption Key]
RK[Recovery Key] -->|KDF| RKEK[Recovery KEK]
KEK -->|AES-256-GCM wrap| DEK[DEK — Data Encryption Key]
KEK -->|AES-256-GCM wrap| IK[Index Key]
RKEK -->|AES-256-GCM wrap| DEK
RKEK -->|AES-256-GCM wrap| IK
DEK -->|AES-256-GCM| Items[Vault Items & Settings]
IK -->|HMAC-SHA-256| Lookup[Domain / Package Lookup Hashes]
| Material | Role |
|---|---|
| Master Password | Derives KEK via KDF; unlocks the vault |
| Recovery Key | Derives Recovery KEK; resets Master Password |
| KEK | Wraps DEK and Index Key |
| DEK | Encrypts credential blobs and settings |
| Index Key | Computes HMAC lookup hashes for autofill matching |
Primary KDF: Argon2id (memory 32,768 KiB · iterations 3 · parallelism 2 · 32-byte output)
Fallback KDF: PBKDF2-HMAC-SHA256 (600,000 iterations)
AEAD: AES-256-GCM (32-byte key · 12-byte nonce · 128-bit tag) via Google Tink / JCE
For the full security architecture, see the Whitepaper.
| Task | Where |
|---|---|
| ➕ Add a password | Home or Vault → + |
| 📚 Browse credentials | Vault tab |
| 🔎 Search / filter | Vault search bar and chips |
| 👁️ View / copy details | Eye icon on a credential card |
| 📲 Enable Autofill | Autofill tab + set Abdal LockBox as the system autofill service |
| 📤 Export backup | Settings → Export Vault |
| 📥 Import backup | Settings → Import Vault |
| 💣 Self-Destruct setup | Settings → Self-Destruct |
| 📖 Help topics | Home → Learn More |
.ablbx files in a secure location.Build toolchain
9.3.19.1.12.2.102.3.511Android SDK / API levels
36 (Android 16)3626 (Android 8.0)com.abdal.lockbox · versionName: 1.65 (versionCode 165)Platform APIs used