MASTRpass Pro is free to download and use.
It is independently developed and maintained without accounts, advertising, telemetry, trackers or the sale of user data.
Voluntary donations fund continued security maintenance, Android/ Seeker compatibility work, regular updates and the development of new features. If you want MASTRpass to remain private, independent and actively maintained, please consider supporting the project.
-------------
Your secrets belong to you! Not to an account, a cloud or a tracker.
MASTRpass Pro turns your Seeker or Android device into a fully offline, encrypted security suite for credentials, seed phrases, wallet records, passkeys, TOTP accounts, recovery data, private images, documents, backups and other sensitive information.
MASTRpass requests neither the INTERNET nor ACCESS_NETWORK_STATE permission. There is no account, backend, cloud synchronization, telemetry, advertising, tracking, WebView, RPC connection, remote configuration or runtime network access.
ENCRYPTED VAULTS
- Create up to 16 isolated local vaults
- Store wallets, credentials, passkeys, TOTP accounts, secure notes, private attachments and custom secret fields
- Use structured templates for exchanges, bank accounts, identities, payment cards, API keys, servers, Wi-Fi networks, recovery codes and software licences
- Organize entries with folders, tags, favourites, expiration dates, search, filters and eight sorting modes
- Switch between standard, compact and responsive grid views
- Use multi-selection, bulk actions, encrypted trash and undo
- Restore up to five encrypted versions of modified secrets
- Generate strong passwords and passphrases locally
- Choose between Quick and Strict unlock modes
- Protect access with a master password, complete recovery key and device-bound biometric security
- Add optional USB or NFC challenge-response hardware-key protection with compatible preconfigured devices
AUTOFILL, PASSKEYS AND TOTP
MASTRpass provides Android Autofill with hardened package and domain matching. On supported Android 14+ devices, its Credential Provider can create, store, use and delete local ES256 passkeys.
Browser origins are checked against the requesting domain, while native applications remain bound to their package identity. Stored TOTP codes are generated completely offline and can be offered during supported login flows.
PRIVATE WORKSPACE
Create encrypted Markdown notes, tasks, recurring activities, local reminders, journals, mood entries and custom trackers. Connect information with internal links and backlinks, inspect orphaned links, use graph and calendar views and retain an encrypted version history.
Local imports support Markdown, text, JSON, Standard Notes, Google Keep, Apple Notes HTML and carefully bounded Obsidian, UpNote and ZIP structures.
SECURITY CENTER
The local Watchtower identifies weak, common, reused, similar or ageing passwords, missing TOTP or recovery information, expiring entries and overdue backups.
A masked dependency map reveals shared passwords, domains, email addresses and recovery paths without displaying the underlying secrets. Manually imported and signed threat packages enable offline comparisons against password hashes, drainer domains and scam addresses while clearly displaying their age and expiration.
Additional protections include:
- Privacy mode and screenshot protection
- Press-and-hold secret disclosure
- Timed seed-word visibility
- Configurable clipboard clearing
- Automatic background and inactivity locking
- Device-security and Android Keystore reports
- APK signature and installation self-checks
- Encrypted local activity history
- Exposure Ledger for reveal, copy, Autofill and Credential Provider events
- Verifiable Offline Center with package, version, source commit, signer, debug status and network-permission verification
SOLANA TRANSACTION GUARDIAN
The Solana Transaction Guardian locally inspects raw or signed Legacy and v0 transaction messages encoded as Hex, Base64 or Base58 before another wallet signs or submits them.
It reveals exact SHA-256 hashes, readable fingerprints, signer and writable-account roles, program IDs, address-lookup boundaries and supported instruction details for System, SPL Token, Token-2022, Associated Token, Compute Budget, Memo and signature programs.
Embedded Ed25519 signatures can be verified cryptographically against the exact message bytes. Encrypted Guardian baselines help identify new programs, signers, writable accounts or instruction structures during future local comparisons.
BACKUP AND RECOVERY
Create authenticated encrypted exports and maintain up to seven local backup generations for each vault. Backups can be verified without replacing current data, opened in guided recovery tests, compared, selectively merged, partially salvaged and checked using a device-local signed integrity manifest.
Automatic encrypted backups can be written to an explicitly selected system folder. Multipart QR transfers provide an additional bounded offline transfer method.
Recovery Twin models scenarios including device loss, a damaged latest backup, changed biometrics and a lost hardware key while clearly separating verified backup facts from user-confirmed recovery assumptions.
30-FUNCTION OFFLINE TOOLBOX
The built-in toolbox covers encoding and byte inspection, timestamps and identifiers, URL structure and Unicode deception, QR and multipart QR, NFC/NDEF, wallet formats and checksums, address-book comparison, BIP39, BIP32/SLIP-10, SLIP-0039, Bitcoin PSBT, EVM transactions, EIP-712 and permits, Solana messages, SHA-256/SHA-512/BLAKE3 hashes, cryptographic primitives, signature verification, X.509, JWT, CBOR/COSE, APK inspection, archive manifests, image metadata, OTP, password analysis and WebAuthn inspection.
Credential imports support KeePass KDBX, Bitwarden JSON, 1Password 1PUX, Chrome, Firefox and structured CSV files, including a local preview, field mapping, duplicate detection and a detailed import report.
HONEST SECURITY BOUNDARIES
MASTRpass is not a wallet. It never signs, broadcasts or simulates transactions. It does not contact RPC nodes or access live blockchain data.
It cannot determine current balances, on-chain account ownership, revocation status, simulation results, recipient intent or whether a transaction, address or project is trustworthy. Results clearly distinguish structural decoding, cryptographic verification, local comparison and facts that cannot be established offline.
MASTRpass cannot recover a forgotten master password or lost recovery key. A self-check performed inside an already compromised application cannot provide absolute proof of integrity. High-security users should independently compare the APK hash and owner certificate.
Your secrets. Your device. Your control.
Private by design. Verifiable by you. Offline by default.
Built independently by MASTR.
Continued development depends on voluntary support.
Every donation helps fund security maintenance, testing, frequent updates and new privacy-focused features while keeping MASTRpass free, independent and free from advertising or tracking.