How Android App Signing Works: Keys, Certificates and APK Signature Schemes

How Android App Signing Works: Keys, Certificates and APK Signature Schemes

Every Android app is digitally signed by its developer, and the signature lets Android confirm that an update comes from the same source as the original. For anyone checking an APK, the signing certificate is one of the best clues to whether the file is genuine.

Key takeaways
  • Android supports three signing schemes: v1 (JAR signing), v2 (introduced in Android 7.0) and v3 (introduced in Android 9).[1]
  • For maximum compatibility, apps are signed with all schemes.[1]
  • With Play App Signing, the developer signs uploads with an upload key and Google signs the APKs delivered to users with the app signing key.[2]
  • Compare an APK's certificate fingerprint with the one the developer publishes; a mismatch can mean a repackaged app.

Why Android requires signing

A signature ties an APK to a developer's private key. It does two jobs: it shows the file has not been altered since it was signed, and it lets Android recognize the same developer across versions, so an update is accepted only from the source that published the original. An app signed with a different key is treated as a different app.

A signature proves who signed a file and that it was unchanged, not that the app is safe. A malicious developer can sign malware perfectly well.

The signature schemes: v1, v2 and v3

Android's platform documentation lists three app-signing schemes:[1]

SchemeBasisIntroduced
v1JAR signingOriginal scheme
v2APK Signature Scheme v2, which signs the APK as a wholeAndroid 7.0
v3APK Signature Scheme v3Android 9

The same page advises signing with all schemes for maximum compatibility, first with v1, then v2 and later.[1] Newer schemes protect more of the file, which is why an older-only signature on a modern app is worth noticing.

Upload keys and Play App Signing

When a developer publishes through Google Play with an app bundle, two keys are involved:[2]

Android Studio's documentation describes the same arrangement: with app bundles you sign with an upload key and Play App Signing takes care of the rest.[3] Because Google signs the delivered APKs, the certificate on a Play-installed APK is not the developer's upload certificate. See APK vs AAB for the bundle side.

How to verify an APK's signature

The apksigner tool from the Android SDK checks a file's signature and prints its certificate:[4]

apksigner verify --print-certs app.apk

Look at the SHA-256 digest of the signer certificate and compare it with:

A mismatch does not prove malware, because a different distribution channel can legitimately use a different signer, but it is a strong prompt to stop and investigate.

Signing warning signs

Pair the certificate check with a look at the manifest in the APK analyzer: a clone often differs in permissions, too.

Frequently asked questions

What is an APK signing certificate?

It is the public certificate embedded in an APK that matches the developer's private signing key. Android uses it to verify the file and to decide whether an update comes from the same developer.

What is the difference between v1, v2 and v3 signing?

v1 uses JAR signing. v2, introduced in Android 7.0, signs the APK as a whole. v3, introduced in Android 9, builds on that. Apps are usually signed with all of them for compatibility.

How do I check who signed an APK?

Run "apksigner verify --print-certs app.apk" from the Android SDK build tools. It prints the signer's certificate, including the SHA-256 digest you can compare with the developer's published fingerprint.

What is an upload key?

With Play App Signing, it is the key a developer uses to sign their app bundle before uploading it to Google Play. Google verifies the developer's identity with it and can reset it if it is lost.

What is the app signing key?

It is the key Google Play holds and uses to sign the final APKs delivered to users' devices. The developer does not hand out this key when they use Play App Signing.

Does a valid signature mean an app is safe?

No. A signature shows who signed the file and that it was not changed afterwards. Malicious developers can sign malware, so it is evidence of origin, not of safety.

Why do updates fail with "app not installed"?

One common cause is a signature mismatch: Android will not install an update signed with a different certificate over the existing app. You would need to uninstall the original first, which erases its data.

What is a repackaged APK?

It is a real app that someone has modified, often to add malware or ads, and signed again with their own key. The different signer is how you can tell it apart from the original.

Can I see a signature in App Checker?

App Checker's analyzer reads the manifest and does not report the signing certificate. Use apksigner for that, alongside the manifest checks App Checker provides.

References
  1. APK signing — source.android.com — the v1, v2 and v3 signing schemes and when they were introduced.
  2. Use Play App Signing — Play Console Help — upload key versus app signing key.
  3. Sign your app — Android Studio — signing app bundles with an upload key and Play App Signing.
  4. apksigner — Android Developers — verifying signatures and printing certificates.

Analyze an APK →

App Checker FAQ

What is Paxio App Checker?

App Checker is a free tool that shows what an Android app declares before you install it. Search any app to see its Google Play permissions, ads, age rating and privacy policy, or upload an APK to see its manifest: permissions, exported components, deep links and certificate pinning.

Is App Checker free, and do I need an account?

Yes, it is free and there is no signup or account. Searches and APK uploads are rate-limited so the service stays available for everyone.

Where does the data come from?

Play Store results are fetched live from the app's current Google Play listing, not from a curated database, so they reflect what the developer has published right now. APK results are parsed directly from the file you upload.

Is my uploaded APK stored or shared?

No. An uploaded APK is analyzed for that single request and deleted immediately afterward. It is not stored, shared or kept for later.

Does App Checker scan my child's phone?

No. It never touches a device. It reads an app's public Play Store listing or a file you choose to upload, and nothing is installed or run.

Does a result mean an app is safe or unsafe?

No. App Checker reports what an app declares: the permissions it can request, whether it shows ads, its age rating. That is useful evidence, but it is not a review, an endorsement or a safety guarantee, and a permission shows what an app can ask for, not what it does with it.

How is App Checker different from the Paxio app?

App Checker is a standalone lookup tool and does not require the Paxio app. Paxio is a separate parental control app for Android that sets screen time limits, blocks apps and filters content on a child's own device.

Who builds App Checker, and how do I report a problem?

It is built by the team behind Paxio. Write to support@paxio.in with anything that looks wrong and, if you can, the app name or package ID.

See all questions, including APK analysis →