Android Developer Verification 2026-2027: What Developers and Users Need to Know
Google now checks who made an Android app before certified phones install it. What started on September 30, 2026, what comes in 2027, what developers must register, how sideloading still works, why the Android Developer Verifier appeared on your phone, and how to get your signing certificate.
Android has always let you install apps from anywhere. That is changing: Google now checks who made an app before a certified Android phone installs it. The first countries started on September 30, 2026, and the rest of the world follows in 2027.
This guide explains what Android developer verification is, the dates, what developers must do, what changes for people who sideload apps, why an app called Android Developer Verifier appeared on your phone, and how to get the signing certificate you need to register an app. It reflects Google's rules as of October 2026.
What is Android developer verification?
It is Google's program that ties every Android app to a verified developer: a person or company whose identity Google has checked. Each app's package name (such as com.yourcompany.app) and signing key are registered to that developer. When a certified Android device installs an app, it checks that the app is registered. Google's reason is malware: scammers who are banned can no longer publish the same harmful app again under a new name in minutes.
The timeline: September 2026 and 2027
| When | What happens |
|---|---|
| August 2026 | Free limited distribution accounts, the advanced flow for power users, and the developer APIs open |
| September 30, 2026 | Protections start in Brazil, Indonesia, Singapore and Thailand, for apps installed from seven stores (Google Play, Galaxy Store, Xiaomi GetApps, OPPO App Market, vivo V-Appstore, HONOR App Market and Palm Store) on certified devices with Android 7 or newer. The same day, every app on Google Play had to be registered, or be removed from Play worldwide. |
| 2027 | Verification expands to all apps on certified Android devices worldwide |
Registration is open now in Play Console and in the Android Developer Console, so there is no reason to wait for 2027.
The new requirements for developers
If your apps are on Google Play
Google says it registered about 99% of Play apps automatically, using the identity you already verified for Play Console. Open Play Console, look at the Home page for a notice about unregistered apps, and register any that are listed. Apps that were not registered by September 30, 2026 are removed from Google Play.
If you share apps outside Google Play
APK files on your website, in other stores, or sent to customers need the Android Developer Console:
- Verify your identity: legal name, address, email and phone, with a government ID. A full account has a one-time registration fee of $25.
- Register each package name with the certificate of its signing key. For a package name Android has never seen, the public certificate is enough. For one already in use, you prove ownership by uploading an APK signed with the matching private key.
Students and hobbyists: limited distribution accounts
A limited distribution account lets you share an app with up to 20 devices with no government ID and no fee. It is meant for students, teachers, learners and testing with friends.
Try it: get your signing certificate
To register a package name, you need the certificate of the key you sign your app with. With Google Play, use your upload key. These commands use keytool, which comes with Android Studio's Java (in Android Studio's jbr\bin folder) or any JDK:
# 1. If you do not have an upload key yet, make one (keep this file and its password safe!)
keytool -genkeypair -v -keystore upload-keystore.jks -alias upload -keyalg RSA -keysize 2048 -validity 10000
# 2. Show its fingerprints: the SHA-256 line identifies your key
keytool -list -v -keystore upload-keystore.jks -alias upload
# 3. Export the public certificate (a .pem file) to upload when registering a package name
keytool -exportcert -rfc -keystore upload-keystore.jks -alias upload -file upload_certificate.pem
Android Studio can also print the SHA-256 of every key your project signs with:
# Or, inside your Android Studio project (Windows: gradlew signingReport)
./gradlew signingReport
| Command | What it does |
|---|---|
-genkeypair | Makes a new key pair in a keystore file. Lose this file or its password and you cannot update the app outside Play again. |
-list -v | Shows the certificate, including its SHA-256 fingerprint, which identifies your key |
-exportcert -rfc | Writes the public certificate as a .pem file. It contains no secret, so it is safe to upload. |
signingReport | Lists the debug and release signing keys of each build in your project |
Sideloading after verification
Installing unverified apps does not disappear:
- The advanced flow: a person who really wants unverified apps turns on developer mode, waits 24 hours and confirms with their fingerprint or face. Google describes it as a one-time setup. The waiting time is there to stop scammers who pressure people over the phone into installing an app right now.
- adb: installing from a computer over USB is not affected, so developers and testers can work as before:
# Developers and testers: installing over USB with adb is not affected
adb install app-release.apk
- Phones that are not Google-certified, such as many custom ROMs, are not covered by the program.
Why did my phone download Android Developer Verifier?
Android Developer Verifier (package com.google.android.verifier) is a Google system component that arrives with system updates. It is the part of Android that checks whether an app being installed belongs to a registered developer. It is not malware and does not read your messages or files.
Can I disable Android Developer Verifier?
It is a system app, so it cannot be uninstalled the normal way, and Google offers no switch to turn it off. People do remove system apps with adb, but that can break installs or updates and is not worth it: outside the countries where verification is active it does not block anything yet, and when it does, the advanced flow and adb still let you install the apps you choose.
Is Android developer verification safe?
For users, yes: it is a check by Google on the phone that looks at the app being installed, not at you. For developers, the trade-off is privacy: you give Google your identity documents, and an app you publish is tied to your name. That is the same as Play Console has asked for years, but it now applies to apps you share outside Play too.
The backlash, and what changed because of it
Open-source developers, alternative app stores such as F-Droid, and many people on Reddit criticised the plan, saying it gives Google control over apps that never touch Google Play. A “Keep Android Open” campaign asked Google to drop it. Google kept the program but added the free limited distribution accounts and the advanced flow for power users after that feedback. The debate continues, so expect more details before the 2027 rollout.
Bought an app's source code? Register your own version
Verification ties a package name and signing key to one developer. If you buy app source code and publish it:
- Change the package name to your own, such as
com.yourcompany.yourapp, before your first build. Our reskin guide shows how. - Sign it with your own key, never one that came with the code.
- Register it in Play Console or the Android Developer Console under your own verified account.
All our Android apps come with neutral package names for exactly this reason. Our website to Android app source code (Kotlin) turns any website into your own app with bottom tabs, a side menu, push notifications, AdMob, offline pages, a QR scanner, PIN lock and dark mode, all set in one config file; the Dock design version has a modern bottom dock instead. You change the package name, sign with your key, register it, and publish.
Checklist
- Play developers: check Play Console's Home page for unregistered apps
- Apps outside Play: create an Android Developer Console account and register every package name
- Keep your keystore and its password backed up in two places
- Learners: use a free limited distribution account (up to 20 devices)
- Testing: keep using
adb install