Integrity Box: a Magisk toolkit for Play Integrity and system signal spoofing
A toolkit for managing Play Integrity & System Environment
At a glance
- What is it?
- Integrity Box is a GPL-3.0 Magisk, KernelSU and APatch module that manages Play Integrity results, keybox handling and system signal masking. It assumes you already run a Zygisk provider and a TEE or keybox module, and it is not the right tool for a locked, unrooted phone.
- Who is it for?
- Integrity Box is for rooted users on clean, enforcing AOSP-based ROMs who already understand Zygisk and TEE modules and want keybox rotation, target.txt maintenance and signal spoofing in one flashable package. It is not for unrooted devices, and not for anyone unwilling to install Tricky Store OOS or TEE Simulator and Zygisk Next or Meow Zygisk first, because the module depends on them for DEVICE and STRONG verdicts.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 10 days ago.
- What is it written in?
- Mainly HTML, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 24, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem Integrity Box addresses on rooted Android
Play Integrity verdicts are not a single check. Google's attestation path looks at the boot state, the build fingerprint, the security patch level, whether the environment looks like a development build, and whether the device's hardware-backed keys are usable. A rooted phone fails several of these at once, and each failure has its own fix. Integrity Box exists to bundle those fixes into one module rather than asking the user to hand-edit properties and target lists.
The README states the project started because keyboxes were being sold, and the author wanted free access to them. That origin explains the shape of the feature list: keybox management, target.txt automation and fingerprint spoofing sit at the centre, with log cleanup and detection masking around them. The audience is narrow and clearly stated: rooted users and custom ROM users who care about Play Integrity reliability.
How the module is structured inside the flashable zip
The repository layout shows a standard Magisk module skeleton. customize.sh runs at install time, post-fs-data.sh and service.sh run at boot, common_func.sh and common_setup.sh hold shared shell logic, and action.sh is the entry point for the module action button in the manager app. The webroot/ directory holds the WebUI, which is consistent with the README pointing users at a WebUI report option and with the module's HTML-heavy language mix.
The PlayIntegrityFork directory is the bundled Play Integrity Fix code, and the README states PIF has been fully integrated since v28. The module ID was changed to playintegrityfix so the two do not collide. keybox/ holds keybox material, toolkit/ holds the helper tooling, and auto-pilot/ suggests an automation path. The README describes the runtime behaviour in terms of what the module touches: it updates keybox.xml, rewrites target.txt based on current TEE status, and blacklists packages from that list to cut CPU work. Nothing in the README describes a background daemon, and the FAQ states the module does not run constantly in the background.
Installing Integrity Box and getting a first verdict
The README is explicit that Integrity Box is not standalone. Two prerequisites must be installed first: either Tricky Store OOS or TEE Simulator, and either Zygisk Next or Meow Zygisk. The README recommends Zygisk Next for Magisk. The module is then flashed through the usual manager flow.
# Prerequisites, per the README:
# 1) Tricky Store OOS or TEE Simulator
# 2) Zygisk Next (recommended on Magisk) or Meow Zygisk
# Then flash the Integrity Box zip in your module managerThere is one documented exception. On Google Pixel stock ROM, or on a custom ROM whose built-in spoofing you want to keep, the README says you do not need Zygisk. Instead you create a file or folder named zygisk at /sdcard/zygisk, in exact lowercase, and then flash the module. The README states this disables all Zygisk-related components and avoids conflicts.
# Pixel stock ROM or ROM with built-in spoofing:
# create the marker before flashing
mkdir -p /sdcard/zygiskAfter flashing, the README says a reboot is required. After that, configuration happens in the WebUI. The settings the README documents most concretely are Safe Mode, Debug Fingerprint, Debug Build, Build Tag and Storage Encryption. Safe Mode is the recovery lever: the README says to enable it and reboot if you hit problems after flashing, and that it disables all experimental settings. The Debug Fingerprint setting strips the debug tag from the fingerprint so a stock fingerprint can be used, and Build Tag spoofs the build tag to avoid custom ROM detection.
Where Integrity Box breaks down or is the wrong choice
The README's own compatibility line is the most important limitation: it works best on clean, enforcing AOSP-based ROMs. That is not a hedge, it is a scope statement. A ROM that already spoofs fingerprints, patch levels or build tags will fight the module unless you take the /sdcard/zygisk path, and the README treats disabling the ROM's inbuilt PIF spoofing as a feature precisely because the conflict is real.
The second limitation is the dependency chain. DEVICE and STRONG verdicts require Tricky Store OOS or TEE Simulator. Integrity Box manages keyboxes and target.txt, but it does not supply the TEE attestation layer itself. If you flash it alone, you have a configuration the README does not describe.
Third, the feature list is broad and the README admits it grew past the point of easy description, including a line where the author says he forgets half the features. A module that spoofs SELinux status, storage encryption state, custom recovery detection and debug fingerprints is doing a lot of surface-level masking. Each of those is a signal a detection vendor can change, and the README does not document a per-feature failure mode or a rollback path beyond Safe Mode. If you need a small, auditable change, this is the wrong tool.
Integrity Box versus Tricky Store and the PIF fork
The comparison people search for is Integrity Box versus Tricky Store, but the README does not treat them as alternatives. It lists Tricky Store OOS as a prerequisite. Tricky Store handles the TEE and keybox side; Integrity Box sits above it and manages the surrounding environment, including rotating keybox.xml and rewriting target.txt from the TEE status. So the honest framing is that Tricky Store is a component and Integrity Box is the orchestration layer.
The real alternative is the standalone Play Integrity Fix module. The README states that from v28 PIF is fully integrated into Integrity Box and that running both makes no sense, which is why the module ID became playintegrityfix. If you only want fingerprint spoofing and nothing else, a plain PIF install is a smaller change. If you want keybox rotation, target.txt automation and the masking features together, Integrity Box is the package that ships them as one unit.
Maintenance, updates and licence terms
The last push to the repository was on 2026-09-22, and the most recent release listed is v42 on 2026-09-05, following v41 on 2026-08-22 and v40 on 2026-08-05. The release cadence over that window is roughly every two to three weeks. The repository is not archived.
Upgrade cost is low in the mechanical sense: it is a flashable module, and the README says it is safe to uninstall. The real cost is re-verification. Every release can change the keybox, the target list or the spoofed signals, and the README does not document a changelog policy beyond the presence of changelog.md and release.json in the repository. The README also states that downloads are verified using hash verification, which matters because the optional download path fetches tools from official release sources.
The project is GPL-3.0. That means if you redistribute the module or a modified build, the licence obligations travel with it. The README does not discuss licence terms, and nothing here is legal advice; read the LICENSE file in the repository if you plan to ship a fork.
Editorial conclusion
Integrity Box is for rooted users on clean, enforcing AOSP-based ROMs who already understand Zygisk and TEE modules and want keybox rotation, target.txt maintenance and signal spoofing in one flashable package. It is not for unrooted devices, and not for anyone unwilling to install Tricky Store OOS or TEE Simulator and Zygisk Next or Meow Zygisk first, because the module depends on them for DEVICE and STRONG verdicts. Before flashing, check the release notes for v42 and confirm the module ID playintegrityfix does not collide with an existing Play Integrity Fix installation, since the README states PIF was folded in from v28 onward and the ID was changed to avoid conflicts. If you keep a second integrity module active alongside it, you are outside the configuration the project documents.
Frequently asked questions
What is Integrity Box?
The README describes it as a complete Play Integrity compatibility and system-signal management toolkit, distributed as a Magisk, KernelSU and APatch module. It handles keybox management, target.txt automation, fingerprint and build tag spoofing, and log cleanup.
How do I install Integrity Box?
Install either Tricky Store OOS or TEE Simulator, and either Zygisk Next or Meow Zygisk, then flash the module and reboot. On Pixel stock ROM or a ROM with built-in spoofing, the README says to create a lowercase zygisk folder at /sdcard/zygisk first instead of using Zygisk.
How do I use the Integrity Box module?
After flashing and rebooting, configuration happens through the WebUI, where settings such as Safe Mode, Debug Fingerprint, Debug Build, Build Tag and Storage Encryption are exposed. The README says to reboot only when a popup tells you to reboot to apply changes.
Is Integrity Box safe to use?
The README answers yes to this, and states that the module does not modify user data, does not modify installed apps, does not collect data and includes no telemetry or tracking. It also states downloads are verified using hash verification.
What is the difference between Integrity Box and Tricky Store?
The README does not present them as alternatives: Tricky Store OOS or TEE Simulator is a prerequisite. Integrity Box manages keybox.xml, target.txt and the surrounding system signals on top of that TEE layer.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/meowdump-integrity-box)