Guide APK modding

How to Sign an APK (apksigner, jarsigner & MT Manager)

Learn how to sign APK files with apksigner, jarsigner, or MT Manager. Schemes v1 to v4 explained. Verify, then install.

Contents

Signing an APK means stamping the package with your cryptographic key so Android can verify who built it and that nobody altered it afterward. Use apksigner from the SDK build tools, the sign menu in MT Manager, or the rebuild step in APK Editor, then verify the certificate before installing. Sign only packages you own or rebuilt yourself, and guard the keystore like a password.

Part of the modding hub: How to Mod an APK · Came from: Recompile an APK · Verify: Check an APK signature.

By Abdul Emam, APK tester at ApkZena. I once signed three test builds with three different keys in one afternoon, and none of them would update over each other. One keystore per project, backed up twice, ended that mess. One key. Two backups.

This guide covers what signing is, the four signature schemes, keystore creation, the three signing routes, the errors you will meet, and verification. Each command is shown exactly as typed.

What Is APK Signing?

APK signing attaches a cryptographic signature created with a signing key, allowing Android to verify package integrity and compare update identity; Android checks that signature during installation and updates, and rejects an update signed with an incompatible key for the same package.

Why Android Requires It

Without signatures, any repackaged file could silently replace your banking app during an update. The signature binds updates to the original author, which is exactly why your modded rebuild can never update over the store version: different key, different identity.

Debug vs Release Signing

Debug keys are auto-generated per machine for development and must never leave your desk. Release keys live in your keystore and define permanent app identity across years of updates. Mixing them up produces builds that install fine and then strand your users.

APK Signature Schemes

Android APK signing includes v1, v2, v3, and v4 schemes with different compatibility and delivery roles; knowing which schemes your build tool applies helps you verify device support requirements without changing signing options unnecessarily for a local build or test.

v1 (JAR Signing)

Signs each ZIP entry individually, the original Java scheme Android inherited. Slow to verify on large packages and blind to some ZIP-level tampering, but still required for devices predating Android 7. Keep it for maximum compatibility.

v2 (APK Signature Scheme v2)

Signs the entire APK as one block, verifying in one pass during install. Faster and stronger than v1, mandatory on modern targets, and documented in Google’s APK Signature Scheme reference. This is the scheme doing the real work today.

v3 (Key Rotation)

Extends v2 with signed proof of key lineage, so a developer can move to a new key without abandoning existing users. Matters for long-lived apps and Play signing migrations. Irrelevant for personal mod builds, essential knowledge for developers.

v4 (Incremental Delivery)

Supports streaming installs where verification happens as bytes arrive rather than after full download. Tied to newer delivery mechanisms and invisible in manual modding workflows. Know it exists; you will rarely invoke it directly.

Which Schemes to Use

Ship v1 plus v2 for sideloaded builds: v1 covers ancient devices, v2 covers everything else and carries the security weight. Add v3 only when planning key rotation. apksigner enables the right combination by default for your minimum SDK setting.

How to Generate a Keystore

The keytool command creates the keystore and signing identity used by future builds; protect both the file and its passwords, because losing the key can prevent updates to packages that depend on it across later releases and installs on user devices.

The keytool Command

keytool -genkeypair -v -keystore my.keystore -alias mykey -keyalg RSA -keysize 2048 -validity 10000

Answer the prompts honestly, set strong store and key passwords, and confirm the file appears. The SDK’s app-signing documentation walks every flag and the reasoning behind each choice.

Back Up the Keystore

Copy the file to two independent places before signing anything with it: an encrypted USB drive and an offline archive, for example. A keystore with one copy is a keystore you have already half lost, given how rarely anyone touches it until disaster day.

How to Sign With apksigner

apksigner signs APKs, verifies their certificates, and reports supported signature schemes; it ships with the Android SDK build tools, making it the preferred command-line option for modern Android packages requiring schemes beyond v1 for installation on current Android devices.

Sign the Package

apksigner sign --ks my.keystore --out signed.apk unsigned.apk

Enter the keystore password when prompted. The --out flag preserves your unsigned input, which keeps a clean before-and-after pair for debugging signature problems later.

Verify the Signature

apksigner verify --print-certs signed.apk

Confirm the output names your certificate and lists the expected schemes. Verification takes seconds and catches the silent failures, like a build that installed from cache while signing actually failed, that cost hours when skipped.

How to Sign With jarsigner

jarsigner is a JDK utility that applies v1 JAR signatures to APKs, mainly for legacy workflows; it does not create newer APK signature schemes, so use apksigner when modern Android device compatibility is required for installation and updates across supported versions.

Align, Then Sign

zipalign -p 4 unsigned.apk aligned.apk
jarsigner -keystore my.keystore aligned.apk mykey

Alignment must precede v1 signing because it rearranges bytes the signature covers. Then verify with jarsigner -verify -verbose -certs, and prefer apksigner for the final word on modern schemes.

How to Sign With MT Manager

MT Manager can sign from its APK menu on the phone: select the file, choose the sign action, and use its default key or a configured keystore; keep the key consistent if later builds must update this package.

Default Key vs Your Keystore

The default key is fine for throwaway experiments, but builds meant to update each other across sessions need your stable keystore. Configure it once in MT Manager’s settings, then every rebuild carries the same identity automatically.

How to Sign With Android Studio

Android Studio’s Generate Signed Bundle or APK wizard can sign a release build after you select the module and keystore; Gradle signingConfigs handles the same settings for repeat builds when you want the process automated from your project configuration and CI pipeline.

When the Wizard Fits

First-time keystore creation and one-off releases benefit from the guided flow and its password validation. Scripted or repeated modding builds belong with apksigner on the command line, where the step is visible and version-controlled.

Common Signing Errors

Missing keystores, incompatible update signatures, verification mismatches, and unsigned outputs are common signing failures; identify the exact message first, because each points to a different key, input file, or workflow step to investigate before rebuilding the package again for installation.

Keystore Not Found

The path is wrong, the file moved, or you typed the alias incorrectly. Re-check the path with your file manager, confirm the alias with keytool -list, and keep keystores in a fixed folder so this never recurs.

INSTALL_FAILED_UPDATE_INCOMPATIBLE

The device holds the same package under a different key. Uninstall the existing app, accept the local-data loss, and install your build fresh. No flag or trick overrides this: it is the signature system working as designed.

Signature Mismatch on Verify

apksigner verify fails or shows an unexpected certificate. You signed with the wrong keystore, signed an already-signed file with conflicting settings, or verified the unsigned input by mistake. Re-sign the correct file with the correct key.

Unsigned Package Refused

The installer rejects the file before any signature logic runs. The sign step was skipped, usually because a tool rebuilt without its signing pass enabled. Sign manually and verify before returning to the installer.

Wrong Keystore, Right Password

Signing succeeds but verification shows a stranger’s certificate: you pointed at an old or borrowed keystore. Builds signed under different keys can never update over each other, so stop and re-sign with the key that owns the installed app’s lineage before going further.

Keystore Discipline for Modders

For private test projects, keep one clearly named key per package line and make separate backups of each keystore; dated filenames and a record of which APK uses each key make later updates easier to manage across devices and builds.

Name Keys by Project

game-mod-2026.keystore tells future you exactly what it signs. Generic names invite reuse across unrelated builds, and unrelated builds sharing a key inherit each other’s update constraints. Clarity now prevents uninstalls later.

How to Verify an APK Signature

Verification checks the signed output independently before installation, confirming the certificate and schemes you expect; use the signature check guide to read fingerprints and compare them with a trusted official build for the same package.

Generate one keystore, back it up twice, and sign every rebuild with the same key. When the next build refuses to install, the recompile guide and the install troubleshooting in the modding pillar pick up from there.

Key Takeaways

  • Sign every rebuild with your own keystore; Android installs nothing unsigned.
  • Ship v1 plus v2 signatures, add v3 when key rotation matters, and always verify after signing.
  • Losing a keystore permanently orphans the app identity, so back it up twice.

Frequently Asked Questions

How do I sign an APK?

Run apksigner sign with your keystore against the package, or use the sign menu in MT Manager or the rebuild step in APK Editor. Then verify the certificate with apksigner verify before installing. An unsigned or wrongly signed package fails at install every time.

What is apksigner?

apksigner is Google's official command-line signing tool, shipped with the Android SDK build tools. It applies v1 through v4 signature schemes, verifies existing signatures, and rotates keys under v3. Prefer it over jarsigner for anything targeting modern Android versions.

What is a keystore?

A keystore is an encrypted file holding your private signing key and its certificate, protected by passwords you set at creation. Android trusts the key, not you, so losing the keystore permanently orphans every app signed with it. Back it up in two places.

What are v1, v2, v3, and v4 signatures?

v1 signs individual ZIP entries the old JAR way; v2 signs the whole APK for faster, stronger verification; v3 adds key rotation for key loss recovery; v4 supports incremental delivery. Modern builds carry v1 plus v2, with v3 when rotation matters.

Do I need to zipalign before signing?

Yes for v1-only packages: zipalign first, then sign, because alignment changes bytes the v1 signature covers. With v2 and newer, apksigner handles alignment itself and warns when it must adjust. When in doubt, align first; the order never hurts.

Can I sign an APK without Android Studio?

Yes. apksigner runs standalone from the SDK build-tools folder with no IDE involved, and MT Manager signs on the phone itself. Android Studio only wraps the same operations in a wizard. Command-line signing is the norm for modding workflows.

How do I fix a signature mismatch?

Uninstall the app carrying the other signature, then install your build fresh, accepting that local data goes with the uninstall. Mismatches are not repairable by re-signing tricks: two different keys can never update over each other by Android design.

What is the difference between debug and release signing?

Debug builds use an auto-generated key every developer machine creates, good for testing and never for distribution. Release builds use your private keystore key, which defines the app's permanent identity. Never ship anything signed with a debug key.

Can I use one keystore for several apps?

Yes. A developer can use one keystore across multiple apps, although losing or exposing it affects every package that depends on that key. Separate keys can limit that impact. Whichever approach you choose, back up each keystore and record which key signed each package.

What happens if I lose my keystore?

You lose the ability to publish updates for every app it signed, permanently, with no recovery path from Google for sideloaded packages. Users must uninstall and reinstall under a new key, losing local data. This is why keystore backup outranks every other precaution.

Part of the complete guide

How to Mod an APK (Games): Methods, Tools and Risks (2026)

Also in APK modding: