Signing identity

APK signing certificate SHA-256 fingerprint

The fingerprint is a public digest of the signing certificate. It is safe to use for identity matching, while the keystore and private key must remain protected.

Guide summary

Extract and normalize the SHA-256 fingerprint used to sign an Android release without exposing a private key.

For: Developers comparing local, CI and store-managed signing identities.

Release sequence

  1. Use apksigner verify --print-certs on the exact production APK.
  2. Alternatively use keytool -list -v against a certificate or protected keystore.
  3. Copy the SHA-256 digest and remove separators only if the tool requires it.
  4. Compare Play App Signing and upload certificate fingerprints before assuming they are the same.

Quick facts

Normalized length64 hexadecimal characters
Safe inputPublic certificate fingerprint
Never submitKeystore, password or private key
Field note

This checker accepts fingerprints with or without colon separators and normalizes them before calling the official API.

Detailed guidance

Extract SHA-256 from the release APK

Run apksigner against the exact APK users receive. Copy the line labelled Signer #1 certificate SHA-256 digest; use the complete digest, which has 64 hexadecimal characters. The shortened value below is only an output-shape example, not a fingerprint you can submit. Do not copy the SHA-1 digest or use a debug artifact.

Illustrative shortened output
apksigner verify --print-certs app-release.apk
# Signer #1 certificate SHA-256 digest: d6ac...9e06 (shortened example)

Choose the right Play App Signing certificate

Play Console can show both an app signing certificate and an upload certificate. The app signing certificate identifies APKs delivered by Google Play; the upload certificate authenticates the AAB submitted by CI. For a Play-delivered app, compare the app signing certificate. If Play shows an app-signing key upgrade, check which certificate applies to the Android version and APK under investigation.

  • App signing key: identity on Play-delivered APKs.
  • Upload key: authenticates the bundle or APK submitted to Play.
  • Other stores: inspect that channel's production APK.

Normalize without exposing a private key

PkgReady accepts colon-separated or compact SHA-256 and normalizes it to 64 hexadecimal characters. The separator style can change; the hexadecimal value must not. A public certificate digest can be compared safely. Never upload a keystore, password or private signing key to obtain it.

Shortened shape examples; not valid inputs
D6:AC:89:ED:...:9E:06
d6ac89ed...9e06

Have the production package name and signing certificate ready? Query the official registration state, then use the result to choose your next step.

Run status check →

Frequently asked questions

Is SHA-1 sufficient?

No. The registration status workflow uses the public certificate SHA-256 fingerprint.

Why does Play show two certificates?

Play App Signing can show both the app signing certificate and a separate upload certificate. The delivered app identity normally uses the app signing certificate.

Sources and review

Last reviewed: