How Android App Signing Works: Keys, Certificates and APK Signature Schemes
Every Android app is digitally signed by its developer, and the signature lets Android confirm that an update comes from the same source as the original. For anyone checking an APK, the signing certificate is one of the best clues to whether the file is genuine.
- Android supports three signing schemes: v1 (JAR signing), v2 (introduced in Android 7.0) and v3 (introduced in Android 9).[1]
- For maximum compatibility, apps are signed with all schemes.[1]
- With Play App Signing, the developer signs uploads with an upload key and Google signs the APKs delivered to users with the app signing key.[2]
- Compare an APK's certificate fingerprint with the one the developer publishes; a mismatch can mean a repackaged app.
Why Android requires signing
A signature ties an APK to a developer's private key. It does two jobs: it shows the file has not been altered since it was signed, and it lets Android recognize the same developer across versions, so an update is accepted only from the source that published the original. An app signed with a different key is treated as a different app.
A signature proves who signed a file and that it was unchanged, not that the app is safe. A malicious developer can sign malware perfectly well.
The signature schemes: v1, v2 and v3
Android's platform documentation lists three app-signing schemes:[1]
| Scheme | Basis | Introduced |
|---|---|---|
| v1 | JAR signing | Original scheme |
| v2 | APK Signature Scheme v2, which signs the APK as a whole | Android 7.0 |
| v3 | APK Signature Scheme v3 | Android 9 |
The same page advises signing with all schemes for maximum compatibility, first with v1, then v2 and later.[1] Newer schemes protect more of the file, which is why an older-only signature on a modern app is worth noticing.
Upload keys and Play App Signing
When a developer publishes through Google Play with an app bundle, two keys are involved:[2]
- Upload key: held by the developer. They use it to sign the bundle before uploading it to the Play Console, and Google can reset it if it is lost or compromised.
- App signing key: held by Google Play. Google uses it to sign the final APKs delivered to users' devices.
Android Studio's documentation describes the same arrangement: with app bundles you sign with an upload key and Play App Signing takes care of the rest.[3] Because Google signs the delivered APKs, the certificate on a Play-installed APK is not the developer's upload certificate. See APK vs AAB for the bundle side.
How to verify an APK's signature
The apksigner tool from the Android SDK checks a file's signature and prints its certificate:[4]
apksigner verify --print-certs app.apk
Look at the SHA-256 digest of the signer certificate and compare it with:
- the fingerprint the developer publishes on their site or repository, or
- the same app installed from Google Play on a device you trust.
A mismatch does not prove malware, because a different distribution channel can legitimately use a different signer, but it is a strong prompt to stop and investigate.
Signing warning signs
- A debug certificate on a release app. Debug keys exist for development builds and are not a proper identity for a published app.
- A different signer from the official build of a popular app, which is the standard sign of a repackaged clone.
- Old-scheme-only signing on an app that claims to target a recent Android version.
- Unsigned or invalidly signed files, which Android will refuse to install.
Pair the certificate check with a look at the manifest in the APK analyzer: a clone often differs in permissions, too.
Frequently asked questions
What is an APK signing certificate?
It is the public certificate embedded in an APK that matches the developer's private signing key. Android uses it to verify the file and to decide whether an update comes from the same developer.
What is the difference between v1, v2 and v3 signing?
v1 uses JAR signing. v2, introduced in Android 7.0, signs the APK as a whole. v3, introduced in Android 9, builds on that. Apps are usually signed with all of them for compatibility.
How do I check who signed an APK?
Run "apksigner verify --print-certs app.apk" from the Android SDK build tools. It prints the signer's certificate, including the SHA-256 digest you can compare with the developer's published fingerprint.
What is an upload key?
With Play App Signing, it is the key a developer uses to sign their app bundle before uploading it to Google Play. Google verifies the developer's identity with it and can reset it if it is lost.
What is the app signing key?
It is the key Google Play holds and uses to sign the final APKs delivered to users' devices. The developer does not hand out this key when they use Play App Signing.
Does a valid signature mean an app is safe?
No. A signature shows who signed the file and that it was not changed afterwards. Malicious developers can sign malware, so it is evidence of origin, not of safety.
Why do updates fail with "app not installed"?
One common cause is a signature mismatch: Android will not install an update signed with a different certificate over the existing app. You would need to uninstall the original first, which erases its data.
What is a repackaged APK?
It is a real app that someone has modified, often to add malware or ads, and signed again with their own key. The different signer is how you can tell it apart from the original.
Can I see a signature in App Checker?
App Checker's analyzer reads the manifest and does not report the signing certificate. Use apksigner for that, alongside the manifest checks App Checker provides.
- APK signing — source.android.com — the v1, v2 and v3 signing schemes and when they were introduced.
- Use Play App Signing — Play Console Help — upload key versus app signing key.
- Sign your app — Android Studio — signing app bundles with an upload key and Play App Signing.
- apksigner — Android Developers — verifying signatures and printing certificates.