Last updated: 2026-10-03
On September 30, 2026, Google's Android developer verification began for users in Brazil, Indonesia, Singapore and Thailand. An app installed from one of seven participating stores on a certified device must now be registered to a developer whose identity Google has verified, and Google plans to expand the check "globally for all apps on certified Android devices in 2027." Registration links a package name and its signing key to a named person or organization. Per the program's FAQ, verification is "narrowly focused on the developer's identity" and "does not collect information about the app content or functionality". The SDKs in an app and the hosts it sends data to are app content and functionality.
What changed on September 30, 2026?
Google's guide lists the seven stores: Google Play, HONOR App Market, OPPO App Market, Samsung Galaxy Store, Transsion's Palm Store, vivo V-Appstore and Xiaomi GetApps. Per Google's Android Help page, apps from these stores "must be registered by a verified developer to be installed and receive updates".
Google's two pages give different minimum Android versions. The developer page says "certified devices running Android 7+"; the Help page says "certified Android devices running Android 8 and up". The check runs in a Google system service, Android Developer Verifier (package com.google.android.verifier), which Google began rolling out in June 2026 for automatic installation "on most Android devices", per the June 18 Android Developers Blog post.
The same post gave Play developers a deadline: register any remaining apps "by September 30, 2026 to avoid global removal from Google Play". In a July 15 update to the post, Google reports that "99% of apps on Play have been registered automatically", and that "Millions of apps have been registered since the verification launched in March."
Google's March 30, 2026 post says "our recent analysis found over 90 times more malware from sideloaded sources than on Google Play" and gives no method for the figure. As of October 3, 2026, Google has published no count of installs blocked since September 30.
Which installs are outside the first phase?
Sideloads and installs from stores off the seven are outside the September 30 requirement until the global rollout in 2027. From the FAQ, entry updated July 15, 2026: "If you distribute your app through other stores, or if users sideload your app directly, these new verification requirements won't apply to your app yet."
For ADB installs, the same FAQ says "Apps installed using ADB won't require verification" (entry of Sept 11, 2025), and the guide says the "ADB workflow and experience stays the same." Google's ADB statements give no end date. Other exceptions Google lists:
- Apps from an organization's store on managed devices are exempt.
- Enforcement covers phones and tablets only for apps distributed outside Google Play.
- AOSP and non-certified devices are exempt, and the checks do not run on devices in comprehensively sanctioned countries.
For unregistered apps, Google built an advanced flow: developer mode on, a check that no one is coaching the user, a restart, a one-day wait, then biometric or PIN confirmation. The user then allows unverified installs for 7 days or indefinitely; each install shows an unverified-developer warning with an "Install Anyway" button.
What does a developer have to register?
A developer registers an identity, then claims each package name with its signing key. Organizations give a D-U-N-S number and a website verified in Google Search Console; package names are claimed by "providing the APK signed with your private key", per the guide.
| Path | Identity check | Distribution | User experience |
|---|---|---|---|
| Full distribution | Yes; $25 fee in Android Developer Console | Any store or channel | Unchanged |
| Limited distribution | No government ID; free | Up to 20 devices the user authorizes | Accepts an invitation |
| Unregistered | None | Channels outside stores that require verification | Advanced flow or ADB |
Source: Android developer verification guide, FAQ and limited distribution page, opened 2026-10-03.
Can anyone check whether an app is registered?
Anyone with a Google Cloud API key, per Google's documentation. The Android Developer ID Status API takes a package name and an optional SHA-256 fingerprint of the signing certificate and returns REGISTERED, NOT_REGISTERED or REGISTERED_WITH_ANOTHER_CERTIFICATE_FINGERPRINT. The guide describes checks made "on behalf of another developer", and the documented response contains the resource path (packages/<package>/packageRegistrationStatus) and the state. I have not queried the API.
What does an APK scan show next to verification?
A built APK contains the two values the Status API takes: the package name in the manifest and the signing certificate in the APK Signing Block. When I scan an Android app, the report records the SHA-256 fingerprint of each signing certificate and the signature schemes present. Across a list of apps, the scan flags apps that share a signing certificate, leaving out the public AOSP test and platform keys. A shared certificate establishes common signing. It also results when one vendor, agency or signing service signs apps for several developers, or when a signing key has leaked, so it leaves open who owns the apps. Google stores the registration status and the verified identity behind the key; neither appears in a scan or a capture.
The rest of the report covers what verification omits: the SDKs found in the binary, the declared permissions, the consent flow, and the traffic recorded on test devices (what was sent, to which host, before or after consent). Earlier posts cover SDKs in Google Play apps: ad SDKs that put precise location in auction requests and the EngageLab push SDK's exported activity. Static findings cite the file and line; what a scan checks and the limits of a scan are on the methodology page.
I run these investigations for lawyers and for researchers working with lawyers, on one app or a list in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.