# Mixin Android App: a Kotlin Messenger, Wallet and Light Node You Build From Source

> MixinNetwork/android-app is the GPL-3.0 Kotlin client for Mixin Messenger, combining chat, a crypto wallet and a light node in one Android package. The repository documents a reproducible Docker build and an APK verification script, but not much else.

**MixinNetwork/android-app** — Project brief: Android private messenger, crypto wallet and light node to Mixin Network.

- Repository: https://github.com/MixinNetwork/android-app
- Website: https://play.google.com/store/apps/details?id=one.mixin.messenger
- Stars: 503 · Forks: 112
- Language: Kotlin
- License: GPL-3.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/mixinnetwork-android-app

## What Mixin Android App Actually Is, and Who It Is Built For

The repository describes itself as an Android private messenger, crypto wallet and light node to Mixin Network. Those are three products in one APK. The chat layer is a private messenger; the wallet layer holds keys and signs transactions; the light node is what lets the app talk to the network without running a full node. The README lists the stack plainly: Kotlin, Jetpack components (Room, LiveData, Paging, Lifecycle, ViewModel) and Hilt for dependency injection. That is a conventional modern Android architecture, not a bespoke framework. The audience follows from that. This is for Android engineers who want to read or rebuild a production wallet client, and for people who want to verify that the APK on their phone matches the published source. It is not aimed at someone who wants a chat library to drop into an existing app. The README gives no module-level API documentation, no AAR, no Maven coordinates. Everything here is an application, and the repository layout reflects it: a single app/ module plus flow/, query-codegen/ and fastlane/ as supporting directories.

## How the Kotlin Client Is Structured: Room, Hilt and a Light Node in One APK

The architecture visible in the repository is a standard layered Android app. Room provides the local database, LiveData and ViewModel carry state to the UI, Paging handles long lists such as message history, and Hilt wires the dependencies. The light node is the part that differs from an ordinary messenger: the app participates in Mixin Network rather than delegating everything to a remote backend. That design decision has consequences. A light node has to keep up with network state, which means the app carries protocol logic that a thin client would push to a server. The repository also contains query-codegen/ and flow/, directories that suggest generated query code and a reactive flow layer, though the README does not explain either. The verify-mixin-apk.sh script is the most informative artifact for understanding the build. According to the README, it builds the Google Play app bundle, generates the APK set for the connected device, and compares every installed base and ABI split APK. It downloads a pinned Bundletool release and verifies its checksum before use. That is a supply-chain-aware design: the tool used to inspect the build is itself pinned and checksummed rather than pulled from whatever is current.

## Building the APK Reproducibly with Docker

The README's build instructions assume Docker with at least 6 GB of RAM. The build runs inside the mingc/android-build-box image, which carries the Android toolchain, so you do not need a local Android SDK to produce a release APK. The command mounts the repository at /project and the output directory at the release APK path inside the container. Run it from the repository root:

```bash
mkdir -p ./output-apk
docker run --rm \
  -v $(pwd):/project \
  -v $(pwd)/output-apk:/home/gradle/app/build/outputs/apk/release \
  mingc/android-build-box bash -c 'cd /project; ./gradlew assembleRelease'
```

When it finishes, the release APK appears in ./output-apk on the host, because that directory is mounted over the container's release output path. The 6 GB figure is the README's own minimum, and Gradle builds of this size will use it. If you prefer a local toolchain instead of Docker, the README does not describe that path: it documents the container build and nothing else.

## Verifying an Installed Mixin APK Against the Source

The verification workflow is the second documented procedure, and it is the more interesting one. It requires Docker with at least 6 GB of RAM, ADB, Android SDK Build Tools with ANDROID_HOME configured, and the trusted release signing certificate SHA-256 digest. With those in place, the README gives this invocation:

```bash
EXPECTED_CERT_SHA256=<certificate-sha256> ./verify-mixin-apk.sh
```

The script builds the Google Play app bundle, generates the APK set for the connected device, and compares every installed base and ABI split APK. The phrase every installed base and ABI split matters: a modern Android release is not one file but a set, and comparing only the base APK would miss a tampered split. The certificate digest is supplied by you as an environment variable, so the script does not carry a hardcoded trust anchor. That is a deliberate choice, and it means the verification is only as good as the digest you paste in. If you take the digest from the wrong place, the script will faithfully confirm the wrong thing.

## What the Repository Does Not Tell You

The README is short, and the gaps are real. There is no documented minimum Android Studio version, no JDK requirement, no Gradle version statement in the prose, and no description of how to build without Docker. The development setup section covers exactly one topic: code style, which uses ktlint. Nothing explains how to run the app against a test network, how to configure endpoints, or what the app/ module's internal boundaries are. The directories query-codegen/ and flow/ appear in the repository listing with no accompanying explanation. For a wallet, the absence of documented key-handling and backup behaviour in the README is the most significant omission. You can read the source, but the repository does not tell you where to look. Treat the README as a build and verification guide, not as an architecture document.

## When This Repository Is the Wrong Tool

If you need a messaging component to embed in your own Android product, this is the wrong repository. It is a complete application under GPL-3.0, not a library, and the README offers no integration surface. If you are targeting iOS or the web, nothing here transfers; the code is Kotlin and Android-specific. If you want to run a Mixin node on a server, this is a light node inside a phone app, not a server deployment. And if your goal is simply to use Mixin Messenger, the README points to the Play Store listing at one.mixin.messenger, which is a different thing from building the source. The verification script exists precisely because those two paths can diverge. A reasonable alternative for a chat-plus-wallet product is to assemble the pieces yourself: an existing messaging protocol for transport and a separate wallet library for keys, accepting that you now own the integration and the security review. The difference in approach is that Mixin ships the integration as one reviewed artifact, while the assemble-it-yourself route gives you control over each layer at the cost of having no single thing to verify.

## Licence and the Cost of Keeping Up

The repository is GPL-3.0. If you distribute a modified version, the licence's copyleft terms apply to the distributed work, and this is a statement about the licence text, not legal advice; consult a lawyer for your situation. On maintenance, the last push was on 2026-08-25, and the three most recent releases are v6.1.1 on 2026-08-25, v6.0.0 on 2026-08-14 and v5.3.2 on 2026-08-10. That is a fast release cadence across a single month. Upgrading costs follow from the stack: Jetpack, Hilt and Gradle versions move together, and the README does not pin them in prose, so a rebuild months later may pull different toolchain versions than the ones the release was cut with. The Docker image tag mingc/android-build-box is likewise not version-pinned in the documented command, which means the reproducible build is reproducible only as long as that tag resolves the same way.

## Conclusion

Adopt this repository if you want to inspect or rebuild the Mixin Messenger client yourself, or if you are auditing how a wallet and light node coexist in one Android app; the reproducible Docker build and verify-mixin-apk.sh are the parts worth starting with. Do not adopt it as a general chat SDK, because the README documents no library API, and do not treat the Play Store listing as equivalent to the source build. Before you commit, confirm you can supply the trusted release signing certificate SHA-256 digest that verify-mixin-apk.sh expects, and check whether the Gradle and Hilt versions in gradle/ match your toolchain, since the README does not state a minimum Android Studio or JDK version.

## FAQ

### How do I download the Mixin Android app?

The README points to the Google Play listing at one.mixin.messenger for the published app. If you want the source build instead, the repository documents a Docker command that runs ./gradlew assembleRelease and writes the APK into ./output-apk.

### How do I install the Mixin Android app from source?

The README does not document installing a locally built APK. It documents building the release APK with Docker and, separately, verifying an installed APK against the source using verify-mixin-apk.sh with ADB and an EXPECTED_CERT_SHA256 value.

### What is the Mixin Android app built with?

The README states it is written in Kotlin and uses Jetpack components including Room, LiveData, Paging, Lifecycle and ViewModel, with Hilt for dependency injection. Code style is enforced with ktlint.

### Can I verify that the Mixin app on my phone matches the source code?

Yes, the repository includes verify-mixin-apk.sh. According to the README it builds the Google Play app bundle, generates the APK set for the connected device, and compares every installed base and ABI split APK, downloading a pinned Bundletool release and checking its checksum first.

## Sources

- [Official documentation](https://play.google.com/store/apps/details?id=one.mixin.messenger)
- [Official README](https://github.com/MixinNetwork/android-app#readme)
- [Project repository](https://github.com/MixinNetwork/android-app)
- [Release notes](https://github.com/MixinNetwork/android-app/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/mixinnetwork-android-app
