Every Android app is signed with a developer’s private key before it can be installed. The signature guarantees two things:
If an APK has been repackaged, injected with ad‑ware, or otherwise tampered with, its signature will no longer match the original. Verifying the signature therefore protects you from malicious versions that may appear on third‑party sites.
java -version should work in a terminal.apksigner and adb). You can download the SDK command‑line tools from the official Android developer site.Make sure your device is charged and, if you plan to pull an installed app, enable Developer options → USB debugging on the phone.
When an app is built, the build system creates a .apk archive (essentially a ZIP file). The apksigner tool then adds a META-INF/ directory that contains the certificate chain and a signature block. The most common digest algorithm today is SHA‑256, but older apps may still use SHA‑1.
To verify an APK you need to extract the certificate’s public key fingerprint (SHA‑256 or SHA‑1) and compare it with the fingerprint of the version you trust.
apksigner (recommended)apksignerIf you installed the Android SDK command‑line tools, apksigner lives in the build-tools/<version>/ folder. Add that folder to your PATH or note the full path.
apksigner verify --print-certs /path/to/app.apk
The output shows one or more Signer # blocks. Each block contains a Certificate SHA-256 digest line, e.g.:
Certificate SHA-256 digest: 3A:7F:2B:...:9C
Copy the entire hex string (including colons) – this is the fingerprint you will compare.
Run the same command with the --verbose flag to see warnings such as “WARNING: No v2 signature found”. Modern Play Store apps should have at least v2 (APK Signature Scheme v2) or v3 signatures.
jarsigner (fallback)jarsignerjarsigner -verify -verbose -certs /path/to/app.apk
The command prints each certificate’s SHA1 and SHA256 digests. Look for lines that start with SHA1: or SHA256:. Example:
SHA256: 3A7F2B…9C
If jarsigner reports “jar verified.” the signature is intact. However, jarsigner does not understand the newer v2/v3 schemes, so it may miss a mismatch that apksigner would catch. Use this method only when apksigner is unavailable.
If you already have the app installed on a device, you can extract its signing certificate directly from the system. This is useful for confirming that the APK you downloaded matches what is on your phone.
adb devices
Ensure the device appears as “device”. If not, check USB debugging and driver installation.
adb shell pm list packages | grep -i partial‑name
Replace partial‑name with part of the app’s name (e.g., whatsapp).
adb shell dumpsys package com.example.app | grep -i signing
The output contains a line like:
signingKeySet=SHA256:3A7F2B…9C
Copy the fingerprint; it should match the one you obtained from the APK file.
There are three practical ways:
&hl=en to the URL, and scroll to the “App info” section. Some developers publish the SHA‑256 fingerprint there.APKMirror which verifies signatures) and run apksigner on that file. Use its fingerprint as the baseline.If you cannot find an official fingerprint, the safest approach is to compare the APK you have with the one you can pull directly from a device that obtained the app from the Play Store (Method 3).
| Problem | Cause | Solution |
|---|---|---|
apksigner: command not found | SDK tools not in PATH | Add the build-tools/<version> directory to your PATH or call it with the full path. |
java.lang.UnsupportedClassVersionError | JDK version too old | Install JDK 8 or newer and ensure java -version reports 1.8+. |
| “WARNING: No v2 signature found” | APK built before Android 7.0 or signed only with v1 | Older signatures are still valid, but consider avoiding such APKs unless you trust the source. |
| Fingerprint mismatch after pulling from device | Device has a different build (e.g., a beta channel) or the app was updated from a different source | Confirm you are comparing the exact same version (check versionCode in adb shell dumpsys package). |
adb pull /data/app/… only on a device you own or have explicit permission to access.apksigner verify --print-certs app.apk and copy the SHA‑256 fingerprint.adb shell dumpsys package and cross‑check.








