NextPass

NextPass

by Barry de Graaff

App

Client for Nextcloud Passwords on Ubuntu Touch

About NextPass

NextPass is a native, independent and unofficial Ubuntu Touch client for the **Passwords** app for Nextcloud.

It is designed for an Ubuntu Touch browser workflow: search for an account, open the url, copy the username or password, and paste it into Morph Browser. NextPass does not run a background sync and does not maintain a local password-vault database.

Before you start

NextPass requires a **dedicated Nextcloud app password**. Do not enter your normal Nextcloud account password.
https://barrydegraaff.nl/ubuntu-touch/how-to-make-app-password.mp4

Create a new app password in your Nextcloud security settings specifically for NextPass. The app password should have the usual Nextcloud form, for example: g8RMo-8P9WA-c2tEB-B8g4G-4jXfY

For that NextPass app password, **disable filesystem access** in Nextcloud. NextPass only needs access to the Passwords API and has no reason to access your Nextcloud files.

NextPass verifies this before use. If the app password can create a temporary WebDAV folder, NextPass treats filesystem access as enabled, removes its temporary probe folder, and refuses to continue. Disable filesystem access for that app password and press **Retry**. The entered app password remains in the dialog so it does not need to be entered again.

How NextPass behaves

• Opening NextPass does not connect to your Nextcloud server.
• A network connection is made only after an explicit action such as Test, Retry, Search, or Copy password.
• Searches are performed on demand. There is no search-as-you-type or background synchronization.
• The Passwords API does not provide server-side text search for account labels, usernames and URLs. NextPass therefore retrieves password models over HTTPS and searches them locally, processing entries individually instead of retaining the complete vault as a local database.
• Search results keep only the information needed to display matches. A password is retrieved again when **Copy password** is explicitly pressed.
• Each result provides **Copy user**, **Copy password**, and **Open site** for a practical Morph Browser workflow.
• The **Clipboard/search timeout** is configurable from 15 seconds to 2 minutes. When it expires, the search field and results are cleared. If the clipboard still contains the value copied by NextPass, it is overwritten with `[NextPass clipboard expired]`. Clipboard content copied afterward by another app is left untouched.
• **Remember app password** is optional and disabled by default. When enabled, the revocable app password is stored in NextPass's private application settings. This storage is private to the app but is not a hardware-backed or encrypted secret store.
• HTTPS is required. TLS certificate errors and ambiguous filesystem checks are rejected rather than bypassed.

Current limitation

NextPass 0.1.5 detects Passwords entries using client-side encryption such as CSEv1r1, but does not decrypt them yet. Such entries are skipped or rejected rather than handled incorrectly.

Privacy

NextPass contains no advertising, analytics, tracking or telemetry. It uses no developer-operated cloud service. Communication is directly between NextPass and the Nextcloud server configured by the user.

For the complete design rationale, security decisions, filesystem-access verification, API behavior, memory-handling choices, clipboard behavior, CSE limitation, confinement model and build information, see **README.md** in the NextPass source code.

NextPass is not affiliated with or endorsed by Nextcloud GmbH or the Passwords project. The Passwords app for Nextcloud is an AGPL-3.0 project by Marius David Wieschollek and contributors. NextPass independently implements the HTTP interoperability surface and is released under MIT-0.

This app was vibe coded with AI. The source code is published for inspection and improvement.

License

MIT No Attribution

Copyright 2026 Barry de Graaff

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Recent Changes

release

Permissions

  • Networking
  • Content Exchange
  • Content Exchange Source

Community Built

This app has been released under the Public Domain license.It is developed in the open and you can review the source code.

Content Rating

This app has not been rated

Self reported rating using Open Age Rating Service

Info

  • Published Date

    Aug 17, 2026

  • Updated Date

    Sep 11, 2026

  • Current Version

    0.1.9

  • Total Downloads

    87

  • Latest Version Downloads

    35

  • Supported Architectures

    arm64

Links

Reviews

No reviews yet!