GpgFrontend

Saturneric·Saturneric.GpgFrontend

A modern, cross-platform, open-source GUI for OpenPGP encryption.

winget install --id Saturneric.GpgFrontend --exact --source winget

Latest 2.2.2·August 10, 2026

Release Notes

v2.2.2 continues the 2.2.x series and is recommended for all users. Upgrading from 2.2.1 is a drop-in replacement: existing key databases and settings are migrated automatically.

Highlights

Profiles. Maintain several independent setups, each with its own key databases, settings, and secure key, and switch between them from the new Profile menu. Portable profile packages (.gfp). Export an entire profile into a single passphrase-encrypted file and open it anywhere with a double-click. It runs as a temporary profile that leaves nothing behind and asks on close whether to save your changes back into the package. Instant Messaging Steganography. Encrypt and sign a message into a single Base58 word that survives being pasted into any chat app. Tokens carry no visible marker: whitened with a shared password book, they look like random text to anyone who does not have the same book phrase. The book phrase itself is now stored encrypted and can be generated and fingerprinted from settings. Key categories and a better key list. Coloured, reorderable category tabs replace the old favourites list. The key list also gains Status and Expire Date columns with a configurable expiry warning, plus search and sorting, and it remembers column widths and checked keys across restarts. More control over keys. Change the passphrase of a single subkey, pin which encryption subkey is used for a recipient, export keys to a location of your choice, start a keyserver search from the selected key, and see at a glance whether a key is v4, v5, or v6. Move a key to a smart card, powered by a rebuilt smart card controller and a dedicated card picker. A refreshed interface. Settings are now a searchable sidebar with new rPGP and Advanced pages, and with room for pages provided by modules. The file browser gains a breadcrumb path bar and OpenPGP badges, the module controller has been redesigned, appearance changes apply instantly, and the setup wizard can switch languages on the spot.

Security

Application key protection. Choose between no protection, the system keychain, or a PIN, backed by the macOS Keychain, the Windows Credential Manager, or libsecret. A Change PIN action is included, along with a reset path in case you forget it. rPGP: forged self-signatures are rejected. Revocations, expiry dates, and key capabilities are only honoured when their self-signature verifies, so a forged revocation can no longer be attached to a key. rPGP: weak and hostile inputs are refused. MD5, SHA-1, and RIPEMD-160 are never accepted as valid, cleartext signing is pinned to SHA-512, unauthenticated SED packets are rejected before decryption, and compression bombs are bounded. rPGP: weak key generation removed. RSA below 2048 bits and DSA are no longer offered, as required by RFC 9580. Existing keys keep working, and GnuPG is unaffected. Archive extraction hardened against path traversal, symlinks, oversized contents, and setuid bits. User ID validation is also stricter.

Engines

rPGP: key expiration management, plus interoperability fixes for v6 messages, expiry handling, revoked primary keys, and signer attribution. All of this is verified against sq and GnuPG using an RFC 9580 test corpus that now ships with the test suite. GnuPG: connections recover properly. Failed connection attempts back off instead of re-probing on every operation, overly long home paths produce a clear error instead of failing opaquely, and a missing gpgconf falls back to rPGP rather than refusing to start. GnuPG: maintenance actions in settings let you clear the password cache, reload the configuration, and restart gpg-agent, with real error messages replacing generic failures and correct smart card serial validation.

[!IMPORTANT] AppImage users: check which file you download. The portable build is now a separate download: pick the AppImage with portable in its name, or any other one for the normal version. The ENV.ini file that used to enable portable mode no longer has any effect, so if you relied on it, download the portable AppImage from now on. The same split applies to the Windows downloads.

Full Changelog: https://github.com/saturneric/GpgFrontend/compare/v2.2.1...v2.2.2

Installer type: msix

x648D20EDEE6A22425D27892AF16B4E52543E0078CB706E67038CA8D0F9EE75833A

Details

Homepage
https://github.com/saturneric/GpgFrontend
License
GPL-3.0
Publisher
Saturneric
Support
https://github.com/saturneric/GpgFrontend/issues
Privacy Policy
https://github.com/saturneric/GpgFrontend/blob/main/PrivacyPolicy.md

Tags

communicationcryptodecryptdsaeccecdhecdsaencryptencryption-decryptiongpgopenpgprsasecuritysecurity-toolssignaturesignature-verification

Older versions (10)

2.1.12
x64D928A2399DD510FC30304159D897F546B8837638EE025BA48B6B43F5C0BCD08B
2.1.9
x643501A9C6CF211008A40B7B03025D095BD753F95625DB50A5BCD50A087DE189E3
2.1.8
x6450D8B264FC985620132F5ACB626784126DC1FC9A5EAEB5651440954D18F1C89E
2.1.7
x6447C5FF866B5CF132C64B6CD7E2AA5D696B4A99DF9181705E60E8304883A8AF0A
2.1.6
x648B680B2A544E6F8B7EA591BBBFC12B6398E836805A8365373A1A147A62C7A121
2.1.3
x64CC05E11C5035BB3311A3968CB9D7A506CCC33E2E7391630BBD95B4851B639EEC
2.1.2
x64BA9FF427FC0926A9102ECCCA7677530966A67E04C898F23A860D630A55274C5A
2.1.1
x6418D574D3A1C81E7A20657FCDD7B941528B8538865DCBCAA266252C6F27DA3BE0
2.1.0
x64E9AE869B8F4CF95206FBEC5771DAD9C60BF4D879847A295A9512AA46218E5C0C
2.0.8
x64009E642303AC3DE76E29F9EF1239481A2757F6CE472CBAE121B5D746C8952611