How to verify an APK signature before installing.
Signature verification is the single most reliable way to confirm that an APK is the one the developer published. This guide walks through reading the SHA-256 fingerprint on Android and comparing it to the developer entry.
What signature verification proves
An APK signature is a cryptographic seal applied by the developer’s signing key. If the signature matches, the file has not been modified since the developer signed it. If the signature does not match, the file has been altered or was not produced by the listed developer.
Step 1: Get the expected fingerprint
Open the developer entry for the app and look for a Signatures or Verification section. The developer publishes a SHA-256 fingerprint in hexadecimal. Copy it.
Step 2: Read the fingerprint on Android
Install the APK in verification mode by running adb install --apex is not what you want here. Use a fingerprint reader app or, on Android 10 and above, the built-in Package installer details screen. Navigate to Settings → Apps → See all apps → pick the app → Advanced → App details.
Step 3: Compare
Compare the on-device fingerprint to the published fingerprint character-by-character. A mismatch means the file was not produced by the developer who published the expected fingerprint.
What a mismatch means
Either the developer rotated their signing key (rare but documented), or the file was tampered with. In both cases, do not install. Contact the developer through their official channel before continuing.
What a match does not prove
A matching signature proves the file is the one the developer signed. It does not prove that the developer is trustworthy, that the app does what it claims, or that the app is legal in your jurisdiction. Those are separate questions.
What signature verification catches
A signed APK carries a certificate fingerprint that is unique to the signing key. If the file on your device has a different fingerprint from the one on the developer entry, the file was either rebuilt by a different party or corrupted during download. Either way, do not install it.
Reading the fingerprint with the package manager
Connect the device, enable USB debugging, and run adb shell pm list packages -f to find the package path. Then use apksigner verify --print-certs on the file. The SHA-256 fingerprint will appear in the output. Compare it to the fingerprint on the developer entry.
What to do on a mismatch
Delete the file, re-download from the developer entry, and re-run the verification. If the mismatch persists, file an issue with the developer and do not sideload. The download-safety section covers the rest of the checklist.