Guide summary
Extract and normalize the SHA-256 fingerprint used to sign an Android release without exposing a private key.
For: Developers comparing local, CI and store-managed signing identities.
Release sequence
- Use apksigner verify --print-certs on the exact production APK.
- Alternatively use keytool -list -v against a certificate or protected keystore.
- Copy the SHA-256 digest and remove separators only if the tool requires it.
- Compare Play App Signing and upload certificate fingerprints before assuming they are the same.
Quick facts
This checker accepts fingerprints with or without colon separators and normalizes them before calling the official API.
Detailed guidance
Extract SHA-256 from the release APK
Run apksigner against the exact APK users receive. Copy the line labelled Signer #1 certificate SHA-256 digest; use the complete digest, which has 64 hexadecimal characters. The shortened value below is only an output-shape example, not a fingerprint you can submit. Do not copy the SHA-1 digest or use a debug artifact.
apksigner verify --print-certs app-release.apk
# Signer #1 certificate SHA-256 digest: d6ac...9e06 (shortened example)Choose the right Play App Signing certificate
Play Console can show both an app signing certificate and an upload certificate. The app signing certificate identifies APKs delivered by Google Play; the upload certificate authenticates the AAB submitted by CI. For a Play-delivered app, compare the app signing certificate. If Play shows an app-signing key upgrade, check which certificate applies to the Android version and APK under investigation.
- App signing key: identity on Play-delivered APKs.
- Upload key: authenticates the bundle or APK submitted to Play.
- Other stores: inspect that channel's production APK.
Normalize without exposing a private key
PkgReady accepts colon-separated or compact SHA-256 and normalizes it to 64 hexadecimal characters. The separator style can change; the hexadecimal value must not. A public certificate digest can be compared safely. Never upload a keystore, password or private signing key to obtain it.
D6:AC:89:ED:...:9E:06
d6ac89ed...9e06Have the production package name and signing certificate ready? Query the official registration state, then use the result to choose your next step.
Run status check →Frequently asked questions
Is SHA-1 sufficient?
No. The registration status workflow uses the public certificate SHA-256 fingerprint.
Why does Play show two certificates?
Play App Signing can show both the app signing certificate and a separate upload certificate. The delivered app identity normally uses the app signing certificate.
Sources and review
Last reviewed: