Security and backup
Open Settings → Security and backup to choose how Agentknock authenticates you and inspect protection of stored data.
Device authentication
Section titled “Device authentication”| Mode | Behavior |
|---|---|
| Rely on device lock | The default. Relies on Android’s screen lock, with no additional Agentknock prompts for protected actions. |
| Protect sensitive actions | Allows ordinary browsing, but requires an authenticated session to view, copy, or edit sensitive values, create non-sensitive values, reduce value sensitivity, or accept a new client. |
| Lock Agentknock | Requires an authenticated session before displaying app content. The same session authorizes protected actions. |
Agentknock uses Android authentication rather than a separate app password. On Android 11 and later, the prompt accepts a supported strong biometric or device credential. Earlier supported Android versions use the screen-lock credential.
Android screen lock reports Configured or Not configured. If Android cannot authenticate you, the app reports the problem; set up an Android screen lock or supported authentication method before retrying.
Changing modes and session reuse
Section titled “Changing modes and session reuse”Selecting a different mode requires authentication unless you already have an authenticated session. Cancelling or failing authentication leaves the previous mode selected. Selecting the current mode makes no change.
A successful authentication is reused while the app stays in the foreground. The session expires after 15 seconds in the background; returning sooner keeps it active. Restarting the app’s process also starts without an authenticated session. With Lock Agentknock, an expired session leads to the app lock screen.
These modes control access to the app and protected actions. They do not pause background request processing or change a secret’s approval mode. Automatic approval and temporary access continue to follow their own rules. Ordinary Allow once and Deny once decisions do not require an additional Agentknock authentication prompt after you can access the request.
Sensitive content when leaving the app
Section titled “Sensitive content when leaving the app”Revealed sensitive values and sensitive editor drafts are cleared when the app actually enters the background. This happens independently of the 15-second authentication grace period, so returning quickly can preserve authentication while still discarding sensitive content. An Android authentication handoff preserves drafts only when it returns to the foreground in under 15 seconds.
Leaving the Secrets tab also hides revealed values. See the secret editor and individual value editors for draft behavior.
On Android 13 and later, Agentknock disables its screenshot in the recent-apps view. On earlier supported versions, it uses Android’s secure-window protection, which also blocks ordinary screenshots of the app.
Encryption status
Section titled “Encryption status”The Encryption section contains three read-only rows:
| Field | Meaning |
|---|---|
| Algorithm | Secret values and encrypted device state use AES-128-GCM encryption. |
| Current key storage | How Android protects the installation’s current encryption keys. It initially shows Checking this device…. |
| Stored encrypted data | Whether the installation can decrypt its stored data, initially Checking this device… and normally Available on this device. |
Key storage can report Android StrongBox, Trusted execution environment, Secure hardware, or Android Keystore, software-backed. Mixed Android Keystore protection means the app’s keys have different kinds of backing. Android may instead report backing not reported or protection not reported; those labels do not confirm a particular hardware protection level.
Current key unavailable on this device means the current encryption key cannot be used. The stored-data row separately identifies whether existing data is readable; having a current key does not imply that it can decrypt data restored from an earlier installation.
Unavailable stored data
Section titled “Unavailable stored data”Some stored data cannot be decrypted identifies the affected category and recovery action:
- Secret values: replace the affected values from another source.
- Client pairings, device credentials, or in-progress requests: pair clients again, completing device setup first if the app requires it.
- Both categories: replace the values and pair clients again.
Authenticating or changing the authentication mode cannot recreate missing encryption keys. A secret’s metadata can remain visible even when its encrypted value is unavailable.
Android backup and restore
Section titled “Android backup and restore”Metadata, history, encrypted values, and the authentication-mode preference are eligible for Android backup and device transfer. Encryption keys stay with this installation and are excluded. This screen explains backup behavior; it has no Agentknock backup toggle or export action.
After a restore, metadata and history can return, but the backup cannot recover readable secret values. Replace those values and pair clients again. Restored encryption-key warnings are therefore different from a temporary failure to unlock the app.
For the wider security model, see Are my secrets safe?.