Signing identity

APK signing certificate SHA-256 fingerprint

The fingerprint is a public digest of the signing certificate. It is safe to use for identity matching, while the keystore and private key must remain protected.

Guide summary

Extract and normalize the SHA-256 fingerprint used to sign an Android release without exposing a private key.

For: Developers comparing local, CI and store-managed signing identities.

Release sequence

  1. Use apksigner verify --print-certs on the exact production APK.
  2. Alternatively use keytool -list -v against a certificate or protected keystore.
  3. Copy the SHA-256 digest and remove separators only if the tool requires it.
  4. Compare Play App Signing and upload certificate fingerprints before assuming they are the same.

Quick facts

Normalized length64 hexadecimal characters
Safe inputPublic certificate fingerprint
Never submitKeystore, password or private key
Field note

This checker accepts fingerprints with or without colon separators and normalizes them before calling the official API.

Detailed guidance

Extract SHA-256 from the release APK

Run apksigner against the exact APK users receive. In the output, copy the line labelled Signer #1 certificate SHA-256 digest. Do not substitute the SHA-1 digest or a fingerprint from a debug artifact.

Android build-tools
apksigner verify --print-certs app-release.apk
# Signer #1 certificate SHA-256 digest: d6ac...9e06

Choose the right Play App Signing certificate

Play Console can show both an app signing certificate and an upload certificate. The app signing certificate identifies APKs delivered by Google Play; the upload certificate authenticates the AAB submitted by CI. A registration check for the delivered app normally needs the app signing certificate.

  • App signing key: Play-delivered APK identity.
  • Upload key: bundle submission identity.
  • Other stores: inspect that channel's production APK.

Normalize without exposing a private key

PkgReady accepts colon-separated or compact SHA-256 and normalizes it to 64 hexadecimal characters. A public certificate digest can be compared safely. Never upload a keystore, password or private signing key to obtain it.

Accepted shapes
D6:AC:89:ED:...:9E:06
d6ac89ed...9e06

Frequently asked questions

Is SHA-1 sufficient?

No. The registration status workflow uses the public certificate SHA-256 fingerprint.

Why does Play show two certificates?

Play App Signing can show both the app signing certificate and a separate upload certificate. The delivered app identity normally uses the app signing certificate.

Sources and review

Last reviewed: