What signature verification proves

An APK signature is a cryptographic seal applied by the developer’s signing key. If the signature matches, the file has not been modified since the developer signed it. If the signature does not match, the file has been altered or was not produced by the listed developer.

Step 1: Get the expected fingerprint

Open the developer entry for the app and look for a Signatures or Verification section. The developer publishes a SHA-256 fingerprint in hexadecimal. Copy it.

Step 2: Read the fingerprint on Android

Install the APK in verification mode by running adb install --apex is not what you want here. Use a fingerprint reader app or, on Android 10 and above, the built-in Package installer details screen. Navigate to Settings → Apps → See all apps → pick the app → Advanced → App details.

Step 3: Compare

Compare the on-device fingerprint to the published fingerprint character-by-character. A mismatch means the file was not produced by the developer who published the expected fingerprint.

What a mismatch means

Either the developer rotated their signing key (rare but documented), or the file was tampered with. In both cases, do not install. Contact the developer through their official channel before continuing.

What a match does not prove

A matching signature proves the file is the one the developer signed. It does not prove that the developer is trustworthy, that the app does what it claims, or that the app is legal in your jurisdiction. Those are separate questions.

What signature verification catches

A signed APK carries a certificate fingerprint that is unique to the signing key. If the file on your device has a different fingerprint from the one on the developer entry, the file was either rebuilt by a different party or corrupted during download. Either way, do not install it.

Reading the fingerprint with the package manager

Connect the device, enable USB debugging, and run adb shell pm list packages -f to find the package path. Then use apksigner verify --print-certs on the file. The SHA-256 fingerprint will appear in the output. Compare it to the fingerprint on the developer entry.

What to do on a mismatch

Delete the file, re-download from the developer entry, and re-run the verification. If the mismatch persists, file an issue with the developer and do not sideload. The download-safety section covers the rest of the checklist.