Android Apps

Android Developer Verification 2026-2027: What Developers and Users Need to Know

Google now checks who made an Android app before certified phones install it. What started on September 30, 2026, what comes in 2027, what developers must register, how sideloading still works, why the Android Developer Verifier appeared on your phone, and how to get your signing certificate.

An Android phone checking that an app comes from a verified developer

Android has always let you install apps from anywhere. That is changing: Google now checks who made an app before a certified Android phone installs it. The first countries started on September 30, 2026, and the rest of the world follows in 2027.

This guide explains what Android developer verification is, the dates, what developers must do, what changes for people who sideload apps, why an app called Android Developer Verifier appeared on your phone, and how to get the signing certificate you need to register an app. It reflects Google's rules as of October 2026.

What is Android developer verification?

It is Google's program that ties every Android app to a verified developer: a person or company whose identity Google has checked. Each app's package name (such as com.yourcompany.app) and signing key are registered to that developer. When a certified Android device installs an app, it checks that the app is registered. Google's reason is malware: scammers who are banned can no longer publish the same harmful app again under a new name in minutes.

The timeline: September 2026 and 2027

WhenWhat happens
August 2026Free limited distribution accounts, the advanced flow for power users, and the developer APIs open
September 30, 2026Protections start in Brazil, Indonesia, Singapore and Thailand, for apps installed from seven stores (Google Play, Galaxy Store, Xiaomi GetApps, OPPO App Market, vivo V-Appstore, HONOR App Market and Palm Store) on certified devices with Android 7 or newer. The same day, every app on Google Play had to be registered, or be removed from Play worldwide.
2027Verification expands to all apps on certified Android devices worldwide

Registration is open now in Play Console and in the Android Developer Console, so there is no reason to wait for 2027.

The new requirements for developers

If your apps are on Google Play

Google says it registered about 99% of Play apps automatically, using the identity you already verified for Play Console. Open Play Console, look at the Home page for a notice about unregistered apps, and register any that are listed. Apps that were not registered by September 30, 2026 are removed from Google Play.

If you share apps outside Google Play

APK files on your website, in other stores, or sent to customers need the Android Developer Console:

  • Verify your identity: legal name, address, email and phone, with a government ID. A full account has a one-time registration fee of $25.
  • Register each package name with the certificate of its signing key. For a package name Android has never seen, the public certificate is enough. For one already in use, you prove ownership by uploading an APK signed with the matching private key.

Students and hobbyists: limited distribution accounts

A limited distribution account lets you share an app with up to 20 devices with no government ID and no fee. It is meant for students, teachers, learners and testing with friends.

Try it: get your signing certificate

To register a package name, you need the certificate of the key you sign your app with. With Google Play, use your upload key. These commands use keytool, which comes with Android Studio's Java (in Android Studio's jbr\bin folder) or any JDK:

# 1. If you do not have an upload key yet, make one (keep this file and its password safe!)
keytool -genkeypair -v -keystore upload-keystore.jks -alias upload -keyalg RSA -keysize 2048 -validity 10000

# 2. Show its fingerprints: the SHA-256 line identifies your key
keytool -list -v -keystore upload-keystore.jks -alias upload

# 3. Export the public certificate (a .pem file) to upload when registering a package name
keytool -exportcert -rfc -keystore upload-keystore.jks -alias upload -file upload_certificate.pem

Android Studio can also print the SHA-256 of every key your project signs with:

# Or, inside your Android Studio project (Windows: gradlew signingReport)
./gradlew signingReport
CommandWhat it does
-genkeypairMakes a new key pair in a keystore file. Lose this file or its password and you cannot update the app outside Play again.
-list -vShows the certificate, including its SHA-256 fingerprint, which identifies your key
-exportcert -rfcWrites the public certificate as a .pem file. It contains no secret, so it is safe to upload.
signingReportLists the debug and release signing keys of each build in your project

Sideloading after verification

Installing unverified apps does not disappear:

  • The advanced flow: a person who really wants unverified apps turns on developer mode, waits 24 hours and confirms with their fingerprint or face. Google describes it as a one-time setup. The waiting time is there to stop scammers who pressure people over the phone into installing an app right now.
  • adb: installing from a computer over USB is not affected, so developers and testers can work as before:
# Developers and testers: installing over USB with adb is not affected
adb install app-release.apk
  • Phones that are not Google-certified, such as many custom ROMs, are not covered by the program.

Why did my phone download Android Developer Verifier?

Android Developer Verifier (package com.google.android.verifier) is a Google system component that arrives with system updates. It is the part of Android that checks whether an app being installed belongs to a registered developer. It is not malware and does not read your messages or files.

Can I disable Android Developer Verifier?

It is a system app, so it cannot be uninstalled the normal way, and Google offers no switch to turn it off. People do remove system apps with adb, but that can break installs or updates and is not worth it: outside the countries where verification is active it does not block anything yet, and when it does, the advanced flow and adb still let you install the apps you choose.

Is Android developer verification safe?

For users, yes: it is a check by Google on the phone that looks at the app being installed, not at you. For developers, the trade-off is privacy: you give Google your identity documents, and an app you publish is tied to your name. That is the same as Play Console has asked for years, but it now applies to apps you share outside Play too.

The backlash, and what changed because of it

Open-source developers, alternative app stores such as F-Droid, and many people on Reddit criticised the plan, saying it gives Google control over apps that never touch Google Play. A “Keep Android Open” campaign asked Google to drop it. Google kept the program but added the free limited distribution accounts and the advanced flow for power users after that feedback. The debate continues, so expect more details before the 2027 rollout.

Bought an app's source code? Register your own version

Verification ties a package name and signing key to one developer. If you buy app source code and publish it:

  • Change the package name to your own, such as com.yourcompany.yourapp, before your first build. Our reskin guide shows how.
  • Sign it with your own key, never one that came with the code.
  • Register it in Play Console or the Android Developer Console under your own verified account.

All our Android apps come with neutral package names for exactly this reason. Our website to Android app source code (Kotlin) turns any website into your own app with bottom tabs, a side menu, push notifications, AdMob, offline pages, a QR scanner, PIN lock and dark mode, all set in one config file; the Dock design version has a modern bottom dock instead. You change the package name, sign with your key, register it, and publish.

Checklist

  • Play developers: check Play Console's Home page for unregistered apps
  • Apps outside Play: create an Android Developer Console account and register every package name
  • Keep your keystore and its password backed up in two places
  • Learners: use a free limited distribution account (up to 20 devices)
  • Testing: keep using adb install

Where to go next

Questions people ask

What is Android developer verification?
A Google program that ties every Android app to a developer whose identity Google has checked. Each app's package name and signing key are registered to that developer, and certified Android devices check the registration when an app is installed.
When does Android developer verification start?
It started on September 30, 2026 in Brazil, Indonesia, Singapore and Thailand for apps from seven participating stores on certified devices with Android 7 or newer. Google plans to expand it to all apps on certified devices worldwide in 2027.
Is Android developer verification safe?
For users, yes: it is a check by Google on the phone that helps block repeat malware. Developers share identity documents with Google, which is a privacy trade-off, as Play Console has required for years.
Why did my phone download Android Developer Verifier?
Android Developer Verifier (com.google.android.verifier) is a Google system component installed with system updates. It checks whether an app being installed comes from a registered developer. It is not malware.
Can I disable Android Developer Verifier?
It is a system app, so it cannot be uninstalled normally, and Google offers no switch to turn it off. Removing it with adb can break installs and updates. You can still install unverified apps through the advanced flow or with adb.
Does Android developer verification stop sideloading?
No. People can still install unverified apps through the advanced flow (developer mode, a 24-hour wait and fingerprint or face confirmation, as a one-time setup), and installs over adb are not affected.
How much does Android developer verification cost?
A full Android Developer Console account has a one-time $25 registration fee and needs a government ID. A limited distribution account for students and hobbyists, for up to 20 devices, is free and needs no ID.
Do Google Play developers need to do anything?
Google registered about 99% of Play apps automatically. Check the Home page of Play Console for unregistered apps; apps not registered by September 30, 2026 were removed from Google Play.
What is a limited distribution account?
A free Android developer account for students, teachers, hobbyists and testers. It lets you share an app with up to 20 devices without a government ID or a registration fee.
Does Android developer verification apply to custom ROMs?
The program covers Google-certified Android devices. Phones that are not certified, such as many custom ROMs, are not part of it.
How do I find my app's signing certificate for registration?
Run keytool -list -v on your keystore to see the SHA-256 fingerprint, and keytool -exportcert -rfc to save the public certificate as a .pem file. In Android Studio, gradlew signingReport prints the keys of every build.

Written by Habib Baloch

I build Android apps, websites and Ubuntu servers, and write down exactly how I did it.

Ask me about this guide →