HostSpica Identity 1.0.0: dependency and permission inventory
SHORT ANSWER
What libraries and permissions does HostSpica Identity 1.0.0 use?
It uses Android's own libraries (Compose, Room, Biometric, CameraX, Credentials), the ZXing QR library, and two Google Play libraries for update and review prompts. It has no analytics, advertising or crash-reporting libraries and no internet permission. The permissions are camera, biometric, Bluetooth and, on old Android only, storage.
Key takeaways
- There is no analytics, advertising, crash-reporting or Firebase library in the app.
- The two Google Play libraries talk to the Play Store app on your phone, not to us.
- The permission list is short and each one has a stated reason.
- This page describes version 1.0.0 and will be updated with each release.
Build
| Item | Value |
|---|---|
| Application ID | com.hostspica.identity |
| Version | 1.0.0 (code 1) |
| Minimum / target / compile SDK | Android 10 (API 29) / API 36 / API 36 |
| Language and build tools | Kotlin 2.1.0, Android Gradle Plugin 8.7.3, KSP 2.1.0-1.0.29 |
| Release build | Minified with R8, signed with the HostSpica release key |
Libraries in the app
| Library | Version | What it is for |
|---|---|---|
| Jetpack Compose (BOM) | 2024.12.01 | The user interface |
| AndroidX Core, Lifecycle, Activity, Fragment | 1.15.0 / 2.8.7 / 1.9.3 / 1.8.5 | Standard Android building blocks |
| AndroidX Room | 2.6.1 | The local database (accounts, Vault entries, passkey metadata) |
| AndroidX Biometric | 1.1.0 | Fingerprint, face and screen-lock prompts |
| AndroidX CameraX | 1.4.1 | The camera for scanning QR codes |
| AndroidX Credentials | 1.6.0 | The passkey provider interface to Android's Credential Manager |
| AndroidX Core SplashScreen | 1.0.1 | The start-up screen |
| ZXing core | 3.5.3 | Reading and drawing QR codes |
| Kotlin coroutines | 1.9.0 | Background work |
| Google Play App Update and Review | 2.1.0 / 2.0.2 | Update and review prompts shown by the Play Store app |
| org.json (JSON-java) | 20231013 | JSON parsing in the AirAuth and Passkey modules |
JUnit 4.13.2 is used for tests only and is not in the release app.
What is not in the app
- No analytics, tracking or attribution library.
- No advertising library.
- No crash-reporting library and no Firebase.
- No networking library for the app's own use, and no internet permission to use one with.
Permissions in the merged manifest
| Permission | Why |
|---|---|
| CAMERA | Scan QR codes on screen. Nothing is stored or sent. |
| USEBIOMETRIC, USEFINGERPRINT | Unlock the app, fill passwords, approve sign-ins and sign with passkeys. |
| BLUETOOTHADVERTISE, BLUETOOTHCONNECT | Android 12 and newer: the direct link AirAuth uses to approve a sign-in. |
| BLUETOOTH, BLUETOOTH_ADMIN (up to Android 11) | The same AirAuth link on Android 10 and 11. |
| WRITEEXTERNALSTORAGE, READEXTERNALSTORAGE (Android 9 and below only) | Saving an exported QR image on those versions. |
| DYNAMICRECEIVERNOTEXPORTEDPERMISSION | Added by AndroidX to protect the app's own broadcast receivers; gives no access to data. |
The app also declares two services that you switch on yourself in Android settings: a credential provider for passkeys and an autofill service for Vault.
How to check it yourself
- Install the app, find its APK with
adb shell pm path com.hostspica.identityand pull it withadb pull. - Run
aapt2 dump permissions app.apkand compare with the table.android.permission.INTERNETmust not be in the list. The full method is in how to check an Android app has no internet permission. - To see libraries, unzip the APK and inspect its classes with a tool such as
apkanalyzer; names are shortened by R8, but package roots such asandroidxandcom.google.zxingremain.
Frequently asked questions
Why does a no-internet app include Play libraries?
They hand a request to the Play Store app on your phone, which does the network work itself. Our app has no network permission.
Where can I see the full list of transitive dependencies?
We have not published it yet. It is planned together with the formats and test vectors.
Is any of this code open source?
The libraries are open source. HostSpica Identity's own source is not public at the moment.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED