qwq233

OhMyKeymint

v1.2.0-67dc5e7guide

OhMyKeymint active root module.

★449 stars
•Root Management•by qwq233•AGPL-3.0•Updated Jun 16, 2026
Platforms:
✓ Magisk✓ KernelSU
Download v1.2.0-67dc5e7Starting download...GitHub Source
OhMyKeymint-release-arm64-v8a-1.2.0-67dc5e7.zip

Overview

Developed by qwq233, OhMyKeymint is an advanced attestation interception framework written in Rust for modern Android versions (Android 12+).

As Google transitioned from legacy Keymaster HIDL services to AIDL-based Keystore 2.0 (keystore2), the mechanisms used by applications to request hardware-backed key attestations were redesigned. OhMyKeymint hooks directly into the keystore2 process, allowing users to define flexible, programmatically generated KeyMint profiles that satisfy Play Integrity while preserving device hardware keys for standard biometric authentication.


Technical Architecture & How It Works

Keystore 2.0 Daemon Hooking

OhMyKeymint operates within the system keystore process address space:

  1. Binder Transaction Interception: Hooks Android’s android.system.keystore2 AIDL interface within the keystore2 daemon.
  2. Selective Policy Evaluation: When a client application calls generateKey with attestation parameters, OhMyKeymint consults its TOML configuration to determine whether the calling UID matches a declared target.
  3. KeyMint Simulation: Intercepted requests are redirected to an authentic software KeyMint instance, signing the resulting certificate chain with configured credentials.

Installation & Setup

  1. Verify your device runs Android 12 or newer on a 64-bit platform.
  2. Download the latest OhMyKeymint-*.zip release.
  3. Flash the module in your root manager (Magisk, KernelSU, or APatch).
  4. Reboot the device.

Configuration & Usage

Configure target packages and profiles in:

/data/adb/ohmykeymint/config.toml

Review the sample configuration in the repository documentation to define package names and security patch levels.


Troubleshooting & Common Issues

  • Keystore Daemon Crashing: If the keystore daemon restarts repeatedly, verify that your config.toml contains valid TOML syntax and that no other keystore hooks are conflicting.

Frequently Asked Questions

Why does OhMyKeymint require Android 12 or higher?

OhMyKeymint is specifically architected to hook Android's Keystore 2.0 system daemon (keystore2) and its AIDL KeyMint HAL interfaces. Devices on Android 11 and older use the legacy C++ keystore daemon and HIDL Keymaster HAL, which are not targeted by this engine.

How do I configure target applications in OhMyKeymint?

Configuration is managed in /data/adb/ohmykeymint/config.toml, where you can define application package names, spoofed security patch levels, and keybox credential parameters.