How Android Autofill works, and how HostSpica Vault gates every fill
SHORT ANSWER
How does HostSpica Vault fill a password into another app or browser?
Android shows the Vault service the structure of the login form. Vault finds entries for that exact site, and offers each one as a suggestion that holds no password yet. When you pick one, a fingerprint, face or screen-lock prompt appears, and only after it succeeds is the password decrypted and handed to Android.
Key takeaways
- The suggestion Android shows contains placeholders, not secrets. The password is decrypted only inside our own check screen, after you authenticate.
- For web pages an entry is offered only when its registered domain, including the ending such as .com, equals the page's. Matching by name alone would offer a github.com password on github.xyz.
- If the phone has no screen lock or biometric at all, there is nothing to ask, and Autofill fills without a check.
- Autofill depends on the browser or app telling Android the truth about the page it shows.
How Autofill works on Android
Turning on an Autofill service in Android settings lets that app see the layout of the screen you are on, but only when a login form is focused. The service returns a list of datasets, each saying "I can fill these fields with these values". Android shows them as suggestions near the field, and fills the one you choose. Chrome and some other browsers also have their own setting for using an Autofill service.
The flow in HostSpica Vault
- Read the form. Our service receives the screen structure and looks for a password field (by autofill hint, input type, or HTML
type=password) and the username field before it. If there is no password field, we offer nothing. - Find entries. We take the page's web domain when the browser reports one, or the app's package name for a native app, and compare it to your saved entries. Rules are below.
- Offer placeholders. For each match we create a dataset whose fields are empty and whose display shows only the entry's title and username. The dataset is marked as needing authentication.
- Authenticate. Picking a suggestion launches our
AutofillAuthActivity, which shows a fingerprint, face or screen-lock prompt (title "Fill from HostSpica Vault"). - Release. Only after success do we decrypt the entry and return a dataset with the real username and password to Android. Cancel or failure fills nothing.
The effect is that decrypted passwords never sit in the Autofill framework waiting to be used: they appear only after the check, and only for the entry you chose.
Saving a new login
When you submit a login form, Android can ask the service to save it. HostSpica asks if you want to save, stores the new entry encrypted in your Vault, and updates the password instead when the same site and username already exist.
Which entries are offered where
- Web pages: the entry must have a web address, and its registered domain, such as
github.comorbbc.co.uk, must equal the page's. Subdomains match their parent:gist.github.comgetsgithub.comentries. An entry with only a title is never offered on a web page. - Native apps: Android packages carry no real domain, so we compare names: an entry for
github.comis offered tocom.github.android.
Limits
Our service never fills our own screens, except in debug builds, where a test form is the only target available.
Frequently asked questions
Does Vault Autofill work in every browser?
It works wherever Android's Autofill framework or a browser's third-party Autofill support is available. Some browsers need a setting turned on. We test mainly with Chrome.
Can I use a passkey and Autofill together?
Yes, they are separate. HostSpica Identity can be your passkey provider and your Autofill service at once.
Why is a fingerprint asked every time?
It is the point of the design: the password is decrypted only after you authenticate for that fill. You can lengthen how long the app stays unlocked in Settings, but the per-fill check stays.
References
Review status
Last technical self-review by the author on 3 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED