Verify an Android App’s Signature and Detect Modified APKs

10 min read Learn step‑by‑step how to check an Android APK’s digital signature, compare it with the official version, and spot tampering using free tools on Windows, macOS or Linux. September 28, 2026 20:30 How to Verify an Android App’s Signature and Detect Modified APKs

Why verifying an APK’s signature matters

Every Android app is signed with a developer’s private key before it can be installed. The signature guarantees two things:

  • Authenticity – the app really comes from the claimed developer.
  • Integrity – the APK has not been altered after it was signed.

If an APK has been repackaged, injected with ad‑ware, or otherwise tampered with, its signature will no longer match the original. Verifying the signature therefore protects you from malicious versions that may appear on third‑party sites.

Appitika tip: Even if you download an APK from the Play Store, checking the signature is a good habit when you later share the file with friends or keep a backup.

Before you start

  • Computer with Windows, macOS or Linux.
  • Java Development Kit (JDK) 8 or newer – java -version should work in a terminal.
  • Android SDK Platform‑Tools (for apksigner and adb). You can download the SDK command‑line tools from the official Android developer site.
  • The APK file you want to inspect.
  • Optional: a second copy of the same app from the Google Play Store (or the Play Store’s fingerprint) for comparison.

Make sure your device is charged and, if you plan to pull an installed app, enable Developer options → USB debugging on the phone.

Understanding Android app signatures

When an app is built, the build system creates a .apk archive (essentially a ZIP file). The apksigner tool then adds a META-INF/ directory that contains the certificate chain and a signature block. The most common digest algorithm today is SHA‑256, but older apps may still use SHA‑1.

To verify an APK you need to extract the certificate’s public key fingerprint (SHA‑256 or SHA‑1) and compare it with the fingerprint of the version you trust.

Method 1 – Verify with apksigner (recommended)

Step 1 – Locate apksigner

If you installed the Android SDK command‑line tools, apksigner lives in the build-tools/<version>/ folder. Add that folder to your PATH or note the full path.

Step 2 – Run the verification command

apksigner verify --print-certs /path/to/app.apk

The output shows one or more Signer # blocks. Each block contains a Certificate SHA-256 digest line, e.g.:

Certificate SHA-256 digest: 3A:7F:2B:...:9C

Copy the entire hex string (including colons) – this is the fingerprint you will compare.

Step 3 – Optional – Verify that the APK is fully signed

Run the same command with the --verbose flag to see warnings such as “WARNING: No v2 signature found”. Modern Play Store apps should have at least v2 (APK Signature Scheme v2) or v3 signatures.

Method 2 – Verify with jarsigner (fallback)

Step 1 – Use the JDK’s jarsigner

jarsigner -verify -verbose -certs /path/to/app.apk

The command prints each certificate’s SHA1 and SHA256 digests. Look for lines that start with SHA1: or SHA256:. Example:

SHA256: 3A7F2B…9C

Step 2 – Interpret the result

If jarsigner reports “jar verified.” the signature is intact. However, jarsigner does not understand the newer v2/v3 schemes, so it may miss a mismatch that apksigner would catch. Use this method only when apksigner is unavailable.

Method 3 – Pull the installed app’s signature via ADB

If you already have the app installed on a device, you can extract its signing certificate directly from the system. This is useful for confirming that the APK you downloaded matches what is on your phone.

Step 1 – Connect the device

adb devices

Ensure the device appears as “device”. If not, check USB debugging and driver installation.

Step 2 – Find the package name

adb shell pm list packages | grep -i partial‑name

Replace partial‑name with part of the app’s name (e.g., whatsapp).

Step 3 – Dump the package’s signatures

adb shell dumpsys package com.example.app | grep -i signing

The output contains a line like:

signingKeySet=SHA256:3A7F2B…9C

Copy the fingerprint; it should match the one you obtained from the APK file.

How to get the official fingerprint for comparison

There are three practical ways:

  1. Play Store “App details” page – Open the app’s page in a browser, add &hl=en to the URL, and scroll to the “App info” section. Some developers publish the SHA‑256 fingerprint there.
  2. Developer’s website or GitHub – Many open‑source apps publish their signing key fingerprint in the README or release notes.
  3. Extract from a trusted APK – Download the official APK from a reputable source (e.g., APKMirror which verifies signatures) and run apksigner on that file. Use its fingerprint as the baseline.

If you cannot find an official fingerprint, the safest approach is to compare the APK you have with the one you can pull directly from a device that obtained the app from the Play Store (Method 3).

Interpreting the results

  • Fingerprints match – The APK is signed with the same key as the trusted version. This does not guarantee the app is safe, but it means it has not been re‑signed.
  • Fingerprints differ – The APK has been signed with a different key. Either the app is a completely different build (e.g., a fork) or it has been tampered with. Do not install it unless you explicitly trust the new signer.
  • No signature found – The APK is unsigned or the signing block is corrupted. Android will refuse to install such an APK on devices running Android 7.0+ (except for development builds). Treat it as suspicious.

Troubleshooting common issues

ProblemCauseSolution
apksigner: command not foundSDK tools not in PATHAdd the build-tools/<version> directory to your PATH or call it with the full path.
java.lang.UnsupportedClassVersionErrorJDK version too oldInstall JDK 8 or newer and ensure java -version reports 1.8+.
“WARNING: No v2 signature found”APK built before Android 7.0 or signed only with v1Older signatures are still valid, but consider avoiding such APKs unless you trust the source.
Fingerprint mismatch after pulling from deviceDevice has a different build (e.g., a beta channel) or the app was updated from a different sourceConfirm you are comparing the exact same version (check versionCode in adb shell dumpsys package).

Safety warnings

  • Never install an APK whose signature you cannot verify – it may contain hidden malware.
  • Do not share your private signing key. The guide only works with public certificates; exposing the private key would compromise all future updates.
  • If you are extracting an APK from a device, use adb pull /data/app/… only on a device you own or have explicit permission to access.

Quick verification checklist

  1. Install JDK and Android SDK command‑line tools.
  2. Run apksigner verify --print-certs app.apk and copy the SHA‑256 fingerprint.
  3. Obtain the official fingerprint (Play Store, developer site, or trusted APK).
  4. Compare the two strings – they must be identical.
  5. If you have a device, pull the installed app’s fingerprint with adb shell dumpsys package and cross‑check.
  6. Abort installation if any mismatch appears.
Bottom line: Verifying an APK’s signature is a quick, free, and reliable way to ensure the app you are about to install truly comes from its claimed developer. The steps above work on any modern desktop OS and require only the free tools that Google already provides.

User Comments (0)

Add Comment
We'll never share your email with anyone else.