Contents
To check an APK signature, run apksigner verify --print-certs app.apk on a PC and compare the certificate fingerprint to a known-good copy of the same app. A fingerprint match confirms the developer signer and shows the bytes are intact. A mismatch means the file was re-signed by someone else.
By Abdul Emam, APK tester at ApkZena. I compared signer fingerprints on 40 APKs in August and September 2026. Six mismatched the official build, and all six were repacks. This guide shows the exact commands and the errors a mismatch causes.
You want to know whether a file really came from the developer, and you have heard that signatures are the proof. That is correct. I once chased an update failure for an hour before checking the signer, which was the whole problem. I promise real commands and clear checks. You will learn the signature schemes, why they matter, how to check on Android and PC, and how to read mismatches.
What Is an APK Signature?
An APK signature is a cryptographic seal applied to the package with the developer’s private key. Android verifies it before install and requires every update to use the same key. The signature proves which certificate signed the file and that the bytes have not changed since signing.
Definition
Signing hashes the APK contents and encrypts that hash with the developer’s private key. Android decrypts it with the matching public certificate and compares the hash. If one byte changed, the hash differs and verification fails. That is why a modified file cannot keep the original signature.
Why Android Requires It
Android requires signatures to prove app identity and to block tampering. Every update must be signed with the key that signed the installed copy. Without that rule, a malicious build could install itself as an update to a trusted app and take over its data and permissions.
v1, v2, and v3 Signature Schemes
v1 is the older JAR signing scheme, which signs individual files. v2 signs the whole APK and verifies faster and more completely. v3 adds key rotation, so a developer can move to a new key without breaking updates. Most apps ship v2 and v3 together, and Android uses the strongest scheme it supports. Google documents the formats in the APK signature scheme reference.
Why Signature Verification Matters
Signature verification answers three practical questions: who signed this file, was it modified after signing, and will it install over my current copy. Each answer changes how you proceed.
Confirms Developer Identity
A matching fingerprint means the same certificate that signed the official app also signed this file. That is the closest thing to proof that the code is the developer’s, not a stranger’s. It is the check I run first on any sideload.
Detects Repacks
A repack is an app that was opened, changed, and re-signed. Re-signing replaces the certificate, so a fingerprint mismatch is the clearest sign of a repack. My six mismatched files in 2026 were all premium-bypass repacks with extra permissions.
Prevents Update Failures
Android will not install an update signed with a different key. If you mix a Play build with a mirror build and the signers differ, the update fails with INSTALL_FAILED_UPDATE_INCOMPATIBLE. Checking the signer before you download saves the wasted install, as the APK not installing fix explains.
How to Check APK Signature on Android
You can read the signer on the phone without a PC. These apps show certificate details, though the fingerprint is easier to compare on a larger screen.
Method 1: APK Analyzer App
Install APK Analyzer from the Play Store, open it, and pick the APK file. The app shows the signer certificate and its fingerprint. Read the SHA-256 line and compare it to the official copy. It handles split APKs too, which is useful for XAPK bundles.
Method 2: App Manager
App Manager is an open-source tool that lists installed apps and APK files with signature details. Open the app, navigate to the APK, and view its signature. It shows the certificate hash and the signature scheme versions. It is a strong option for privacy-minded users.
Method 3: Apktool
Apktool decodes an APK and can dump signature information, though it is aimed at reverse engineering rather than quick checks. It is heavier than the two apps above. Use it when you already work with APK internals and want a full breakdown of the package.
How to Check APK Signature on PC
The PC path gives you the official tool and the easiest way to compare fingerprints. apksigner is the standard, and it comes with the Android SDK build tools.
Method 1: apksigner verify
Install Android SDK build tools, then run apksigner verify --print-certs app.apk in a terminal from the build-tools folder. The output lists the signer’s distinguished name and the certificate SHA-256 digest. Copy that digest and compare it to the official app. The apksigner reference covers the options.
Method 2: jarsigner -verify
The JDK tool jarsigner -verify -verbose -certs app.apk verifies v1 signatures and prints certificate details. It does not check v2 or v3 schemes on its own, so it is a partial view. Use apksigner for the full result, and jarsigner as a quick cross-check on older files.
Method 3: APK Studio
APK Studio is a graphical tool that opens an APK and shows its certificate, manifest, and resources. It suits people who prefer a window over a terminal. Open the APK, open the certificate panel, and read the fingerprint. Compare it the same way you would with apksigner.
How to Compare Signatures
Checking the signature is only useful if you compare it to a trusted reference. A fingerprint by itself means nothing until you match it against the official app.
Match Against the Official Listing
Download the same version from Play or the developer site, then extract its certificate. Compare the two fingerprints. Identical strings mean the file is the developer’s build. This is the reference I use for every app I update often.
Check the Certificate Fingerprint
A certificate fingerprint is a hash of the signing certificate. Compare the SHA-256 digest, character by character. Do not compare the common name alone, because two certificates can share a name. The digest is the part that must match exactly.
Verify SHA-256
The APK file also has its own SHA-256 hash, separate from the certificate. The certificate proves the signer, and the file hash proves the download is intact. Check both. The hash verification guide covers generating a file hash on Windows, Mac, Linux, and Android.
Common Signature Errors
Signature problems surface as specific errors. The message tells you what happened, and each one has a clear cause.
Signature Mismatch
A mismatch sometimes appears without an error string of its own. It is still the root cause behind the next two. A mismatch means the new file has a different certificate than the installed copy. It comes from a repack or from mixing sources. There is no bypass.
INSTALL_FAILED_UPDATE_INCOMPATIBLE
This ADB error appears when the new APK’s signer differs from the installed app. The fix is to install from the original source or to back up, uninstall, and install fresh. The install error guide lists the exact recovery steps.
“App Not Installed” on Update
A plain App not installed message on an update often hides a signer clash. It can also mean low storage or a corrupt file, so check those too. Rule out the signer first, because it is the one cause you cannot work around.
What a Signature Mismatch Tells You
A mismatch is information. It tells you the file in your hand was signed by someone other than the developer you expected. That has three likely explanations.
Different Developer
Some apps are signed by a publisher rather than the studio you expected, or a rebranded app has a new signer. Confirm the certificate against the current Play listing, not an old note. A legitimate signer change is documented by the developer.
Modified APK
A mismatch can mean the file was opened and changed. Any edit, even a small one, breaks the original signature, so the editor re-signs it with a new key. That is common on mod sites and rare on reputable mirrors.
Repacked Malware
The worst case is a repack that carries malware. The signer is new because the attacker signed their payload. This is why a mismatch is a stop signal, not a puzzle to solve. Scan the file, and if it carries detections, delete it. See mod APK risks.
Tools to Check APK Signatures
A short list covers almost every case. Keep the first two on hand.
- apksigner: the official command-line tool, best for accurate fingerprints.
- APK Analyzer: an on-device app for quick certificate checks.
- App Manager: an open-source on-device tool with detailed signatures.
- ClassyShark: a desktop tool for browsing APK internals and certificates.
- jarsigner: a JDK tool for v1 verification as a cross-check.
Next, download one app you already trust, run apksigner verify --print-certs on the trusted copy and the new file, and compare the fingerprints before you install. If they match, move on to the virus scan.
Key Takeaways
- An APK signature proves which certificate signed the file and that the bytes are intact.
- Check it with apksigner verify --print-certs and compare fingerprints.
- A mismatch means a different signer, which usually means a repack.
- You cannot install across different signers without a clean reinstall.
Frequently Asked Questions
How do I check an APK signature?
On a PC run apksigner verify --print-certs app.apk from Android build tools, then compare the certificate fingerprint to a known-good copy of the app. On Android, open the APK in App Manager or APK Analyzer and read the signer details. A match confirms the same developer.
What is an APK signature?
An APK signature is a cryptographic seal applied to the package with the developer's private key. Android verifies it before install and refuses updates signed with a different key. It proves which certificate signed the file and that the bytes have not changed since signing.
What does signature mismatch mean?
A signature mismatch means the new APK was signed with a different certificate than the installed copy. That happens when the file was repacked by a third party, or when you mixed a Play build with a mirror build. Android blocks the update because the signer changed.
How do I compare APK certificates?
Extract the signing certificate from each APK with apksigner verify --print-certs, then compare the SHA-256 fingerprint strings. Identical fingerprints mean the same signer. One character different means a different certificate, so treat the file as a repack.
Can I install an APK with a different signature?
Not over an existing install. Android blocks it with INSTALL_FAILED_UPDATE_INCOMPATIBLE. The only path is to back up app data, uninstall the current copy, and install the new build fresh. There is no safe way to force a different signer over the old app.
What is apksigner?
apksigner is the official Android command-line tool for signing APKs and verifying their signatures. It comes with Android SDK build tools. Run apksigner verify --print-certs to see the signer, and apksigner sign to sign a build yourself.
How do I know if an APK is repacked?
Check the signer. If the certificate fingerprint differs from the official app's, the file was re-signed by someone else, which is the definition of a repack. Other signs include a package name mismatch and a file size that does not match the official release.
What are v1, v2, and v3 signatures?
v1 is the older JAR signing scheme. v2 signs the whole APK and is faster and stronger. v3 adds key rotation and supports signing certificates that can change over time. Modern apps include v2 and v3, and Android picks the strongest scheme it supports.
Can I forge an APK signature?
No. Forging a signature would require the developer's private key, and the scheme is built so a changed byte breaks verification. Anyone can re-sign an APK with their own key, but that produces a different signer, which is exactly what a signature mismatch reveals.
Why does Android check signatures?
Android checks signatures to prove the identity of the app author and to stop tampered files from installing. Every update must be signed with the same key as the installed copy, so malware cannot masquerade as an update to a real app.