SymbifoxUser guide Français

Part 7 · Platform, hosting and artificial intelligence

Mobile apps and browser extension

The three Symbifox Android apps and the browser extension: what they provide, how to install and pair them, and how to revoke their access.

Symbifox 18.0 (September 2026 catalogue) · Revised 2026-09-12

You can use Symbifox from a phone in two ways: in the phone's browser, which shows the full interface, and through Android apps published by Blue Fox. A browser extension completes the picture on the workstation. This chapter describes what each one provides, how to install it, how to give it access to your instance and how to take that access away. It is written for the person who receives a phone and has to use it.

The three apps and the extension#

Product What it provides What your instance needs
Symbifox Mobile (Android) Calendar, tasks, emails and text messages in a single app The email, SMS and calendar applications
Symbifox Tokens (Android) Your one-time codes, generated offline The one-time code application
Symbifox Compte (Android) A device account that grants access to the other apps An up-to-date instance
Symbifox Tokens (browser extension) The same codes, in the workstation's toolbar The one-time code application

The three apps require a version of Android that is still supported, Android 8 or later. There is no version for iPhone or iPad: on those devices, use Symbifox in the browser.

Install the apps#

The apps are not on Google Play yet. They are distributed through an F-Droid repository maintained by Blue Fox: once the repository is added, updates show up as they would in any app store.

  1. Install F-Droid on the phone, from the project's website.
  2. In F-Droid, open SettingsRepositories, then add a repository.
  3. Paste the address of the Symbifox repository, provided by Blue Fox, in full, fingerprint included.
  4. Go back to the list of apps and refresh it.
  5. Install Symbifox Mobile, Symbifox Tokens or Symbifox Compte, depending on what you need.

The current version of each app is shown on its page in the repository. A Google Play release is in preparation. When it happens, it replaces this repository, and apps already installed update through the store.

Pair an app with your instance#

The three apps pair the same way.

  1. Open the app.
  2. Enter your instance's address, starting with “https”. It is the only thing the app asks for.
  3. The sign-in page opens in the phone's browser. Sign in as usual, with your password, your identity provider or your second factor.
  4. Grant the access requested.

The app comes back to the foreground, paired. The page may reopen a second time without asking you anything. This is not a defect: a second access is being granted while your session is already open. One sign-in, two accesses.

Symbifox Mobile day to day#

Symbifox Mobile carries the working day, not the whole instance:

  • Calendar by day, week or list, in your calendar's colours, with the agenda and the meeting report of each meeting. You can snooze a reminder, mark a meeting as seen, confirm your attendance and create a meeting.
  • Tasks with their tags, stage, priority and completion, including creating tasks on the spot.
  • Unified inbox for emails and text messages, in two tabs: reply, forward, compose, attach a file. Archiving a message in the app really moves it on the mail server.
  • Routing a message to a record: task, ticket, lead, invoice or expense, without leaving the phone.
  • Assistant and softphone, when the instance offers them.

Notifications require neither a Google account nor any third-party service. The theme is dark by default, in the colours of the connected instance; the button in the calendar header cycles through dark, light and system.

Symbifox Tokens, on the phone and in the browser#

Generating a one-time code requires the plain-text seed at the moment the code is generated, and that moment never happens on the server. Your instance holds only encrypted data and cannot generate a code. The app asks it only for the vault and the list of tokens, both encrypted; the codes are then calculated without any network.

On the phone, the vault key is sealed in the device hardware and asks for your fingerprint each time you open it. The vault closes as soon as the app goes to the background.

  1. Open Symbifox Tokens and enter your instance's address.
  2. Sign in through the browser, as for the other apps.
  3. Open the vault, with a passkey or a passphrase.
  4. Check the remember-on-this-device option if you want the vault to reopen with your fingerprint rather than the passphrase.

To add a token, the camera reads the service's QR code: the seed is parsed, encrypted and erased in the app, so what goes to your instance is already encrypted. The scanning screen blocks screenshots: at that moment, an image is as good as the seed.

The browser extension provides the same codes in the workstation's toolbar. It is not in the stores yet: you install it by hand, from the package provided by Blue Fox. On Brave, Chrome and Edge, unzip the package, open the extensions page, and turn on Developer mode. Then load the unpacked extension, pin its icon, and add your instance in its settings. On Firefox, installing from a file is refused with a corrupted extension message. Mozilla's signature is required, and nothing gets around it on a standard Firefox. To try it right away, load a temporary add-on from the debugging page, knowing it disappears on restart along with its local storage. To make it last, you need a signed package, and obtaining one is up to Blue Fox. Firefox Extended Support Release is not supported.

Everything the extension keeps stays on your workstation, in the browser's local storage: the address of your instances and, only if you check remember on this device, your vault key, in a form the browser does not allow to be exported. Your passphrase is never stored, and uninstalling erases everything. Its privacy policy is at symbifox.com/tokens/confidentialite.html.

Symbifox Compte#

Symbifox Compte (account) holds the device's Symbifox account. Once added, it appears in the phone's SettingsAccounts, with one account per instance and per person. The other apps ask it for their access instead of each opening its own sign-in, and the server issues one device record per calling app: no access is shared, and each is revoked on its own. The app shows the list of access granted and the button that removes them.

There are three things it does not do, by design. It reads none of your data: it grants access, it does not use it. It does not serve the token vault, which keeps its own pairing, because a vault must not depend on a messaging app. And it is not mandatory for anyone.

Your devices, and cutting off access#

The Mes appareils page in the portal, at /my/appareils, gathers all your pairings. It shows one device per line, the module it opens and its last activity. A button removes a device's access, and another removes everything at once.

The calendar and tasks have no line of their own: they accept the messaging access or the email access, and so appear under one of those two labels.

Known limitations#

  • The repository forces no update. A published fix reaches a phone only when the person installs it, which is why an urgent fix is announced and not just published.
  • Unlocking with a passkey requires a password manager able to return a secret. A manager that can only prove your identity opens nothing, for lack of material: the app says so and names the methods that work.
  • On a device without Google services, passkey unlocking is hidden, but everything else works, offline codes included.
  • The apps do nothing without the matching applications on the instance. An instance without one-time codes has nothing to show Symbifox Tokens.

Troubleshooting#

Symptom Likely cause Fix
The app refuses the address entered. The address does not start with “https”, or the host name is incomplete. Enter the full address, as you use it in your browser.
Symbifox Tokens shows no code. The instance does not have the codes application, or no token is shared with you. See OTP tokens with your administration.
Passkey unlocking is missing or refused. The key manager returns no secret, or the device lacks the required services. Open the vault with your passphrase.
Firefox reports a corrupted extension. Mozilla's signature is required to install from a file. Load a temporary add-on to try it, and ask Blue Fox for the signed package.
An announced fix does not install. The repository pushes no update. Refresh the list in F-Droid, then install the update.

See also#