
Note: For what a PGP ID identity is and what it is for, see the page devoted to it . To keep up, join our mailing lists .
foodjis no longer asks for a computer. The assistant that gives birth to a digital identity, writes it into a security key and lets it circulate now exists on Android, with the same journeys and the same words as on Djibian. A phone, a YubiKey or NitroKey held against its back, and that is all.
There is a reason for this port, and it is not convenience: an identity that requires a desktop computer is an identity reserved for those who own one. In most of the world, the phone is the computer.
Generating an identity. Your entity identifier β the EID β is computed
from a civil status of birth: a place, an instant. Not from a key, not from an
account, not from a number somebody hands you. The map is there to put down the
point, and the Here button to take the one you are standing on; the instant is
entered in your local time. A person falls under variant u4, another entity β
association, company, piece of software β under variant u5.
The identity’s secrets are then printed as QR fragments on sheets of paper, of which only some will be needed to put it back together. That is your backup, and it depends on no service at all.
Setting up a key. The phone reads the printed fragments with its camera, then writes the identity into the security key held against its back. The secrets travel over the key’s own radio, never over a network. At the end, the application shows the key’s PIN and Admin codes, once, on the only screen of the whole journey that the system forbids photographing.
The key keeps the secrets; the phone keeps none. That is the property that makes the object worth having: losing the phone costs nothing, losing the key costs what a key costs β and the sheets of paper are there for that.


Holding your own card. Present the key and the application reads what it carries: usual name, portrait, EID, certificate fingerprint, validity dates, certifications received, addresses and other details. Everything is changed from there β adding an address, withdrawing one, choosing the one mail software will put forward, moving the date the certificate stops being true. Every change is signed by the key, therefore by you, then published to the keyservers: a certificate is a public thing, and a change that stayed inside one phone would be a change nobody can act on.
Certifying others. This is the gesture a web of trust is made of: confirming that a certificate does belong to the entity it names. There is no central office to do it in your place, and that is on purpose β the parties sign, third parties verify. The application says so before offering it: it puts your own credibility on the line, and more still for an entity that is not a person, whose responsibilities you take upon yourself.


Keeping your contacts. A local keyring, fed by the keyservers, by a QR code shown face to face, or by a file you were sent. Each card can be handed over in five ways β QR code, vCard or certificate, sent to another application or imported into the phone’s address book. The slider at the bottom is the credibility you grant that identity; it stays on your phone as long as you do not share it.


The identity on the key is not only there to be shown inside foodjis. Two things work today, from the phone:
If your OpenPGP keys already live on an NFC security key β a YubiKey 5 NFC, a Nitrokey 3A NFC β then foodjis does the job you used to open OpenKeychain for: it is what the system now offers to mail applications, and it needs no secret on the phone at all. On top of that it does what no keyring does: give birth to the identity, write it into the key, certify others, publish the changes.
And if you do not have a key yet: the association does not sell them, it provides them to its members as soon as their cumulative subscriptions have reached the threshold β YubiKey 5 NFC or Nitrokey 3A NFC, at your choice and according to stock.
This version installs beside any future store version rather than replacing it: it carries our development key, so it is called foodjis-dev, and that is a name of its own.
03a6c328d6d56ad115fa7aec05037cdbe619dd5c9dbf06205bbcc8cb3c5d0ec7.mneme@foopgp.org. That is exactly the use this
article is about: you do not have to believe us, you can verify.A brand-new security key wants three seconds of power from any USB port before it will answer over radio β a charger will do. It is the one moment in the whole journey where another device is needed, and it asks for no software.
The store account is being verified. The version distributed there will carry a different signature from this one: it will therefore not install over it, and this one will have to be uninstalled first β that is Android’s rule, and we will say so plainly on the day it happens.
The rest is written in our assembly reports, week after week: the identity on the key is the first stage, signing , mail and the Ι accounts are the ones above it.