What Is an APK Signature? How to Check Whether an APK Was Tampered With
Learn why Android APKs need signatures, how certificates and update checks work, and how to verify an APK with apksigner, SHA-256, and certificate fingerprints.

Android requires installable APKs to be digitally signed. A signature helps establish that a version was issued by someone holding a particular private key, lets the system verify file integrity, and determines whether a new APK can replace an installed app.
First, an important distinction: a valid signature shows that the protected APK contents have not changed since signing. It does not, by itself, prove that the signer is the official developer you trust. To assess the source, compare the APK's certificate fingerprint with a known official version or another trusted reference.
What is an APK signature?
A developer creates a cryptographic key pair. The private key is kept by the developer and used to sign the app; public-key information is placed in a signing certificate distributed with the APK. During installation, Android uses the certificate's public key to verify the signature and content digests.
Digital signatures address three main questions:
- Integrity: Have the APK's protected contents changed after signing?
- Update identity: Was the new version issued by the same signer as the installed version, or by an accepted successor?
- Relationships between apps: Can the system grant certain trust relationships based on their signing identities?
Android's documentation states that every APK must be cryptographically signed with an app-signing key to install. The system records the signing identity at first installation and checks it again during updates.
What can an APK signature prevent?
If someone replaces code, inserts ads, removes resources, or changes the manifest after signing, the file digests change. With APK Signature Scheme v2 and later, changes to the protected parts of the overall file invalidate the signature.
An attacker can modify an APK and sign it with their own private key, but the certificate fingerprint changes. Such a package normally cannot replace the official app directly; the user may be asked to uninstall the original first or install it under another package name. That is why a signature-mismatch warning matters.

How do v1, v2, v3, and v4 signatures differ?
| Scheme | Main characteristic | Primary use |
|---|---|---|
| v1 | JAR signing protects ZIP entries individually | Compatibility with older Android versions |
| v2 | Signs the file as a whole, improving integrity protection and verification speed | Supported from Android 7.0 |
| v3 | Adds capabilities such as signing-key rotation to v2 | Newer Android versions |
| v4 | Produces separate signing data for incremental installation | Used with incremental installs; cannot replace v2/v3 on its own |
An APK can contain multiple signature schemes to support both older and newer systems. Seeing "v1: true" alone does not establish safety, and a higher scheme number does not make the source more trustworthy.
A valid signature is not the same as a trusted source
Anyone can generate a key and sign an APK they made. Keep two checks separate:
- Integrity verification: Are the signature structure and content digests valid?
- Identity comparison: Does the signing certificate match a known official fingerprint?
The first asks whether the file changed after it was signed. The second helps determine whether it came from the same developer.
How do you verify an APK with apksigner?
Android SDK Build Tools provides apksigner. Run this in a terminal:
apksigner verify --verbose --print-certs app.apk
Pay particular attention to:
- whether
Verifiedsucceeds; - the verification results for v1, v2, v3, and other schemes;
- the Signer certificate SHA-256 digest;
- supporting details such as the signer certificate DN and serial number.
Do not install an APK if verification fails. If it passes, compare the certificate's SHA-256 digest with a trusted official sample.
Print certificate information only
apksigner verify --print-certs app.apk
Compare the certificate SHA-256 fingerprint character by character. Colons, capitalization, and display formatting may differ, but the hexadecimal value must match.
How can you tell whether a downloaded APK was tampered with?
Method 1: Compare it with an installed official app
If the phone already has a version installed from an official store, extract its APK or use a reliable tool to read its signing certificate. Compare that certificate's SHA-256 fingerprint with the downloaded package. A match shows the same signing identity or a valid rotation lineage; if they differ, do not attempt to install it over the existing app.
Method 2: Compare a fingerprint published by the developer
Some open-source projects publish signing fingerprints on their official website, code repository, or release notes. Obtain the fingerprint through an independent official channel rather than trusting only a value shown on the APK download page.
Method 3: Check the file's SHA-256 hash
On macOS or Linux, run:
shasum -a 256 app.apk
In Windows PowerShell, run:
Get-FileHash .\app.apk -Algorithm SHA256
A file hash can confirm byte-for-byte agreement with the file a publisher specified. It is not a signature: another release, recompression, or any byte change produces a different hash, and a matching hash alone does not prove the publisher's identity.
Method 4: Observe the update result
Android's refusal to install an update with an incompatible signature is a useful warning. But being able to install a package is not an absolute safety guarantee: a first installation has no earlier certificate to compare, and an attacker-signed package may still install as a new app.
Why does Android report a signature mismatch?
Common reasons include:
- a third-party modified or re-signed package;
- an existing app installed from another signing channel;
- a developer changing keys without a valid signing-rotation lineage;
- trying to replace a debug build with a release build;
- different vendor channels using different signatures for the same package name.
Do not immediately uninstall the existing app merely to bypass the conflict. Uninstalling may erase local data and removes the installation whose signature Android can compare. Back up data and verify the new package's actual source first.
Can multi-engine malware scanning replace signature checks?
No. Malware scanning looks for known threats, behavior, or patterns; signature comparison addresses file integrity and publishing identity. They answer different questions and each has limitations.
A stronger combination is a trusted source, a matching certificate fingerprint, a matching file hash, reasonable permissions, and security scanning. No single successful check is an absolute safety guarantee.
A pre-installation checklist for everyday users
- Prefer an official app store or the developer's website.
- Check the domain, package name, version number, and release date.
- When updating an installed app, compare its certificate SHA-256 fingerprint.
- Compare a file hash when the official publisher provides one.
- Check whether requested sensitive permissions fit the app's purpose.
- Stop and investigate if Android reports a signature conflict.
- Be wary of files that demand you disable system protection or uninstall the official version first.
Frequently asked questions
Can an unsigned APK be installed?
The normal Android installation process requires a verifiable signature. Development debug packages are signed too, usually with a debug key.
Does a successful APK signature check prove it is official?
No. It proves only that the signature structure and protected contents are consistent. Compare the certificate fingerprint with a trusted official release to assess signing identity.
Do different SHA-256 hashes mean one of two APKs was tampered with?
Not necessarily. Different versions, architectures, or builds naturally have different file hashes. A difference shows a mismatch only when the publisher says the two should be the exact same file.
Why must an APK be re-signed after modification?
Modifying it breaks the original content digest and invalidates its signature. Re-signing makes the modified file verify under a new signature, but changes its certificate identity; it cannot masquerade as an update from the original developer.
Can a developer really change signing keys?
Newer Android signing schemes support controlled key rotation, but the system needs a valid signing lineage. Simply signing a new APK with an unrelated key cannot replace an installed older version.
Summary
APK signatures underpin Android app integrity and update trust. To check for tampering, first verify the signature with apksigner, then compare the certificate SHA-256 fingerprint with a trusted official release. File SHA-256 hashes, permission review, and security scans provide useful additional evidence, but cannot replace certificate identity checks.