Air-gapped hardware wallet companion
Your keys stay on the card.
Keycard Pal signs Ethereum and Bitcoin with a Status Keycard over NFC. It talks to your wallet through animated QR codes, so nothing you sign has to pass through an internet-connected device. Free, open source, no telemetry.

- Private keys never leave the card
- No accounts, no analytics, no telemetry
- MIT licensed
- Reproducible release builds
- Offline Android build with no internet permission
How it works
Four steps, no cable.
Your everyday wallet stays watch-only. Keycard Pal holds nothing and connects to nothing.
Wallet shows a request
Ambire, MetaMask, Sparrow or any wallet that speaks the same UR format renders the transaction as a QR code. Keycard keeps a list of wallets that support it.
Scan and review
Keycard Pal decodes it and lays out what you are actually signing, in words.
Tap the Keycard
Enter your PIN, hold the card to the phone. The card signs; the key never moves.
Show the signature back
The signature goes back as an animated QR code. Your wallet broadcasts it.
Features
Read it before you sign it.
Requests the app can decode are laid out in full before the card is ever asked to sign. Everything below works with no network connection.
Ethereum transactions
Legacy, EIP-1559 and EIP-2930. Chain name, amount in the native currency, recipient, fees and decoded calldata.
EIP-712 typed data
Decoded review with dedicated screens for Permit, PermitSingle and Safe transactions, plus
the digests the card signs.
Coming soon
Clear signing
EIP-7730 descriptors will turn any contract call into plain rows from a bundled registry snapshot. Today a built-in parser covers ERC-20 and the Uniswap Universal Router.
Personal messages
EIP-191 and Sign-In with Ethereum requests are signed on the card. The payload is shown as its raw bytes; a readable message review is still to come.
Bitcoin
PSBT signing with a row per output and the fee, and BIP-322 message signing.
Wallet export
Watch-only keys out to Ambire, MetaMask, Ledger Live and Bitget as UR QR codes, plus standard Bitcoin account exports other watch-only wallets can import.
Key material
Generate a key pair on the card, import a BIP-39 phrase of 12 or 24 words with an optional passphrase, SLIP-39 shares, or scan a SeedQR.
Genuine card check
The card's certificate is verified before pairing, and an unrecognised one is brought to you before anything is written.
Card management
PIN, PUK and duress PIN, pairing slots, card name, factory reset. Nothing about your card is stored on the phone.
Online extras, off until you turn them on.
The standard build can reach the network for these four. Each one ships disabled, and none of them ever sees a private key.
Opt-in
WalletConnect
Connect a dApp straight to Keycard Pal instead of scanning codes, and approve its signing requests on the same review screens. You supply your own Reown Project ID.
Opt-in
Tenderly simulation
Simulate a transaction before you sign and see the balance changes it would cause. You supply your own Tenderly account and API key.
Opt-in
ENS names
Reverse-resolve addresses to .eth names. A public RPC endpoint is filled in when you turn it
on, and you can change it to any endpoint you like.
Opt-in
Token images
Fetch token logos from the URLs in the bundled token list. Token symbols and decimals are bundled either way.
Nothing here is enabled by default, no key or credential is shipped with the app, and no traffic reaches the developer. If you would rather not have the option at all, install Keycard Pal Offline on Android, which has no internet permission in its manifest.
Two Android builds
Pick how much network you want.
Both sign and manage keys identically. They differ in one line of the Android manifest. The iOS app is the standard build.
Keycard Pal
com.keycardpal
- Everything in the offline build
- WalletConnect, Tenderly simulation, ENS names and token images available
- Each of them off until you turn it on in Settings
Keycard Pal Offline
com.keycardpal.offline
- No
INTERNETpermission in the manifest - The online code is not in the build, not merely switched off
- Signing, key management and wallet export, unchanged
Screenshots
What it looks like.








Install
Available on Android and iOS.
Google Play carries the standard Android build and the App Store carries the iOS app. The developer-signed APKs on GitHub and in the F-Droid repository below carry both Android builds, including Keycard Pal Offline.
F-Droid main repository — coming soon
The Play copy is re-signed by Google Play App Signing; the GitHub and F-Droid copies are signed by the developer. Two different signatures means one cannot update the other, so pick a source and stay with it. The F-Droid repository above is the developer's own, serving the same APKs that are attached to each GitHub release.
- F-Droid repository URL
- https://fdroid.keycardpal.com/repo/
- Repository fingerprint
- 24EB891A8A617F8BF20892CB0CF9267709BA94056E64242AD9EDF638C2FED3D2
- Signing certificate SHA-256
- A8:3C:11:4B:1F:42:01:DA:FB:D0:3E:22:1F:1C:29:28:EC:B5:2B:78:BD:A5:E9:3F:29:6F:ED:F2:29:8E:54:6B
- Requirements
- Android 7.0 (API 24) with NFC, or an iPhone 7 or later on iOS 15.1. A Keycard.
Every release attaches SHA256SUMS.txt so you can check an APK before installing it, plus
per-architecture splits for a smaller download. For most people the universal APK is the right
one.
The hardware
Keycard Pal needs a Keycard.
The app is the companion, not the wallet. Signing happens on a Status Keycard, an NFC smart card you hold to the back of the phone. No USB, no Bluetooth, no battery. Cards are sold at keycard.tech.
Advertisement
The link above, and the Buy a Keycard links in the Android app, are affiliate links: the developer earns a commission on purchases made through them. No feature depends on buying through them, every feature of the app is free, and a Keycard bought anywhere works exactly the same. The iOS app carries no affiliate link and points at the product site instead.
How it is built
Stated up front.
Keycard Pal is developed with substantial help from AI coding assistants (Claude and Codex). I decide what gets built, read and test what goes in, and maintain it myself.
What keeps that honest is in the repository: a Jest suite that runs on every pull request, architecture decision records explaining why things are the way they are, a check that the offline build carries no online code, and release APKs that anyone can rebuild byte for byte. Fixes that belonged upstream were sent upstream. Every release is tested on real Keycards and real phones before it ships.
Donations
Voluntary, and nothing in return.
If Keycard Pal keeps your funds safe, you can send a coffee my way. Addresses are in DONATE.md and on the app's About screen. Donations are voluntary and nothing is unlocked, changed or promised in return.



