Guide summary
Extract and normalize the SHA-256 fingerprint used to sign an Android release without exposing a private key.
For: Developers comparing local, CI and store-managed signing identities.
Release sequence
- Use apksigner verify --print-certs on the exact production APK.
- Alternatively use keytool -list -v against a certificate or protected keystore.
- Copy the SHA-256 digest and remove separators only if the tool requires it.
- Compare Play App Signing and upload certificate fingerprints before assuming they are the same.
Quick facts
This checker accepts fingerprints with or without colon separators and normalizes them before calling the official API.
Detailed guidance
Extract SHA-256 from the release APK
Run apksigner against the exact APK users receive. In the output, copy the line labelled Signer #1 certificate SHA-256 digest. Do not substitute the SHA-1 digest or a fingerprint from a debug artifact.
apksigner verify --print-certs app-release.apk
# Signer #1 certificate SHA-256 digest: d6ac...9e06Choose the right Play App Signing certificate
Play Console can show both an app signing certificate and an upload certificate. The app signing certificate identifies APKs delivered by Google Play; the upload certificate authenticates the AAB submitted by CI. A registration check for the delivered app normally needs the app signing certificate.
- App signing key: Play-delivered APK identity.
- Upload key: bundle submission identity.
- Other stores: inspect that channel's production APK.
Normalize without exposing a private key
PkgReady accepts colon-separated or compact SHA-256 and normalizes it to 64 hexadecimal characters. A public certificate digest can be compared safely. Never upload a keystore, password or private signing key to obtain it.
D6:AC:89:ED:...:9E:06
d6ac89ed...9e06Frequently asked questions
Is SHA-1 sufficient?
No. The registration status workflow uses the public certificate SHA-256 fingerprint.
Why does Play show two certificates?
Play App Signing can show both the app signing certificate and a separate upload certificate. The delivered app identity normally uses the app signing certificate.
Sources and review
Last reviewed: