{"id":1565,"date":"2026-09-17T15:50:09","date_gmt":"2026-09-17T15:50:09","guid":{"rendered":"https:\/\/www.netexl.com\/blog\/?p=1565"},"modified":"2026-09-17T15:56:07","modified_gmt":"2026-09-17T15:56:07","slug":"android-developer-verification","status":"publish","type":"post","link":"https:\/\/www.netexl.com\/blog\/android-developer-verification\/","title":{"rendered":"Android Developer Verification on Google Play Console"},"content":{"rendered":"\n<p>The purpose of this is to register package names and signing keys for all apps that you distribute for Android. In most cases, Google automatically registers package names and certificates used to sign the package from its developer console. In case where it fails to do it, or in cases where some apps are using different package names or different certificates for different stores, we may need to manually finish the process.<\/p>\n\n\n\n<p>The first step is to find out your app\u2019s SHA-256 certificate fingerprint. We will use Keytool utility to retreive this information. Keytool is a built-in Java utility included in the JDK\/JRE used to manage cryptographic keys, X.509 certificate chains, and trusted certificates. On windows, this tool (keytool.exe) can be located inside the bin directory of your Java installation. Add this location to the system PATH in widnows so that this tool can be executed from any directory. There are multiple ways to get your apps&#8217; SHA-256 certificate fingerprint as described in the article below<\/p>\n\n\n\n<p><a href=\"https:\/\/support.google.com\/googleplay\/android-developer\/answer\/16641489\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">https:\/\/support.google.com\/googleplay\/android-developer\/answer\/16641489<\/a><\/p>\n\n\n\n<p>We will retreive this information from our APK file<\/p>\n\n\n\n<p><code>keytool -printcert -jarfile \"D:\\Releases\\Android\\MyApp\\MyApp.v1.apk\"<\/code><\/p>\n\n\n\n<p>The output will include the Certificate fingerprints section. Look for the SHA-256 line.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"226\" src=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-1-1024x226.png\" alt=\"\" class=\"wp-image-1569\" srcset=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-1-1024x226.png 1024w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-1-300x66.png 300w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-1-768x169.png 768w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-1-280x62.png 280w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-1.png 1162w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>If you are getting error &#8220;Not a signed jar file&#8221; when using keytool, try apksigner tool which is the most reliable way to extract signature information from an APK. There is only one issue with it. It does not give the SHA-256 certificate fingerprint in colon separated format which is expected by Google Play Store so you will have to use other means to format it.<\/p>\n\n\n\n<p>apksigner verify &#8211;verbose &#8211;print-certs &#8220;D:\\Releases\\Android\\MyApp\\MyApp.v1.apk&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"276\" src=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-2-1024x276.png\" alt=\"\" class=\"wp-image-1570\" srcset=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-2-1024x276.png 1024w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-2-300x81.png 300w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-2-768x207.png 768w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-2-280x76.png 280w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-2.png 1082w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>apksigner tool can be found in %LOCALAPPDATA%\\Android\\Sdk\\build-tools\\&lt;version-number> in your Android SDK. On windows powershell we can format the string using following command<\/p>\n\n\n\n<p>(apksigner verify &#8211;print-certs &#8220;D:\\Releases\\Android\\MyApp1\\MyApp1.v1.apk&#8221; | Select-String &#8220;Signer #1 certificate SHA-256 digest:&#8221;).Line.Split(&#8220;:&#8221;)[1].Trim() -replace &#8216;..(?=.)&#8217;, &#8216;$&amp;:&#8217;<\/p>\n\n\n\n<p>In order to add the key to Google Play Console, go to the Android Developer Verification section on developer console and click on the app to add the key<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"330\" src=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-5-1024x330.png\" alt=\"\" class=\"wp-image-1577\" srcset=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-5-1024x330.png 1024w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-5-300x97.png 300w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-5-768x247.png 768w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-5-1536x495.png 1536w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-5-280x90.png 280w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-5.png 1831w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Click on &#8220;Add Key&#8221; which opens a popup as follwing<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"205\" src=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-4-1024x205.png\" alt=\"\" class=\"wp-image-1574\" srcset=\"https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-4-1024x205.png 1024w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-4-300x60.png 300w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-4-768x153.png 768w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-4-1536x307.png 1536w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-4-280x56.png 280w, https:\/\/www.netexl.com\/blog\/wp-content\/uploads\/2026\/09\/image-4.png 1837w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Copy the SHA-256 certificate fingerprint there and press &#8220;Add Key&#8221; which adds the the certificate fingerprint and the status of added key is shown as &#8220;In Review&#8221; which changes to &#8220;Verified&#8221; after successful verification.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The purpose of this is to register package names and signing keys for all apps that you distribute for Android. In most cases, Google automatically registers package names and certificates used to sign the package from its developer console. In case where it fails to do it, or in cases where some apps are using different package names or different certificates for different stores, we may need to manually finish the process. The first step is to find out your app\u2019s SHA-256 certificate fingerprint. We will use Keytool utility to retreive this information. Keytool is a built-in Java utility included in the JDK\/JRE used to manage cryptographic keys, X.509 certificate chains, and trusted certificates. On windows, this tool (keytool.exe) can be located inside the bin directory of your Java installation. Add this location to the system PATH in widnows so that this tool can be executed from any directory. There[&#8230;]<\/p>\n","protected":false},"author":5,"featured_media":1537,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,34],"tags":[],"class_list":["post-1565","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","category-useful"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/posts\/1565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/comments?post=1565"}],"version-history":[{"count":4,"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/posts\/1565\/revisions"}],"predecessor-version":[{"id":1579,"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/posts\/1565\/revisions\/1579"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/media\/1537"}],"wp:attachment":[{"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/media?parent=1565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/categories?post=1565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.netexl.com\/blog\/wp-json\/wp\/v2\/tags?post=1565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}