Sona.
World news, made local
Tech

Android's developer check verifies the maker, not the app

From 30 September, participating stores in four countries will begin checking who is behind an Android app. That is an accountability link, not an app safety certificate or a blanket ban on sideloading.

Conceptual Android app verification checkpoint linking a package to an identity medallion and signing-key token above a phone
The new check links an app package and signing key to a developer identity; it does not certify the app's behaviour. AI generated image

Android is about to add a new question to some app installations: not simply where did this file come from, but who registered it?

From 30 September 2026, Google says Android developer verification will start affecting users in Brazil, Indonesia, Singapore and Thailand. The first phase covers installations from seven participating stores, including Google Play and stores operated by Honor, Oppo, Samsung, Transsion, vivo and Xiaomi, on certified devices running Android 7 or later.

The phrase "developer verification" can easily be mistaken for an app approval badge. It is not that. Google's documentation describes a link between a real person or organisation, an app's package name and the signing key used to prove control of that package. The check is about accountability for the publisher, not a review of everything the software does.

That distinction is the most useful thing to understand before the September rollout.

Every Android app has a package name, the technical identifier that distinguishes it from other apps, and is signed with a developer-controlled key. For developers distributing only outside Google Play, the new Android Developer Console asks for an account, identity verification, the package name and a SHA-256 certificate fingerprint from the signing key. An existing app may also need a signed APK to prove ownership.

Developers using Google Play manage the process through Play Console. Google says most already verified Play identities need no new identity step and that 99 per cent of apps on Play have been registered automatically. Developers still need to check for any packages that were not matched.

The resulting link can make it harder for a removed malicious operation to return immediately behind another anonymous package. It does not prove that a verified app is harmless, well designed, private or suitable for a particular user. Google's FAQ says the verification process is narrowly focused on developer identity and does not collect information about an app's content or functionality.

A verified developer label should therefore be read as "there is an accountable identity linked to this signed package", not "Android has inspected and endorsed this app".

The first enforcement date is narrower than some accounts of an Android-wide sideloading ban.

Google's current guide says the 30 September phase applies in four countries and to installations from the named participating stores. Its FAQ says apps delivered through another store, or sideloaded directly, are not covered by this initial phase. For distribution outside Google Play, the September enforcement is limited to mobile and tablet form factors in those countries.

Google plans to expand the system globally in 2027 to all apps on certified Android devices. That later phase is why developers using websites or independent stores still have a reason to prepare, even if their present distribution route is outside the September list.

There is a separate consequence inside Google Play. Its developer guide says remaining package names should be registered by 30 September to avoid removal from Play and to keep installation working smoothly. That is a Play distribution rule, not evidence that every direct download stops working everywhere on the same day.

The word "certified" also matters. The check is delivered to Play Protect certified devices, which Google defines as devices tested against its compatibility and security requirements and licensed to include Google apps. It is not a claim about every device built from the Android open-source code.

Google says registered apps can still be distributed through app stores, direct downloads and other channels. For most users installing registered packages, the company says the experience should remain much as it is now.

For unverified developers, Google documents an "advanced flow" intended for experienced users who deliberately choose to accept the risk. The process includes developer mode, a restart and reauthentication, a waiting period and a later choice to allow unverified installs. Android Debug Bridge installation remains available for development and testing.

Those safeguards are designed around social-engineering scams in which a caller or message pressures someone to disable protections immediately. Their existence should not be read as a recommendation to bypass a warning. If someone is coaching the installation in real time, the prudent interpretation is that the delay is doing its job.

Android is also offering a limited-distribution account for students, teachers and hobbyists. Google says it is free, does not require government ID and can authorise up to 20 devices. It still requires a Google account with two-step verification and a payments profile holding the developer's legal name and address. It is a small-sharing route, not unlimited anonymous distribution.

For users in the first four countries, the immediate question is the source of the app. An installation from a participating store may begin enforcing the identity-to-package link after 30 September. A direct download or another store sits outside that first phase, but it does not acquire a safety guarantee simply because the new check has not reached it.

The usual source questions still matter: did you reach the developer through a known website or store, does the package name match the expected app, and are you being hurried into changing a security setting? Developer verification adds an accountability layer. It does not replace judgement about permissions, updates, reputation or the purpose of the software.

For developers, the route depends on distribution. Play developers should inspect the verification page in Play Console for unmatched packages. Developers distributing only elsewhere use the Android Developer Console and need to connect their identity, package names and signing keys. Small personal projects can consider the limited route, while broad distribution requires full verification.

The new system is neither a simple app-store lock nor a universal safety seal. It is a platform checkpoint that asks a more specific question: can Android connect this signed app package to someone who can be held accountable for it?

That is a meaningful security change. It is also a limited claim, and readers will be better served if the label stays limited to what it can actually prove.

Editorial note. This article is general technology and platform-policy reporting, not individual cybersecurity, legal or app-installation advice. Do not change device security settings because a caller, message or website is pressuring you to install an app. Check the current Android documentation and your device or store guidance before relying on a rollout date or distribution route.

Sources

  1. Android Developers, "Android developer verification" overview and guides, updated 18 August 2026 and extracted 29 August 2026. Verified the 30 September milestone, participating stores, four-country scope, certified Android 7+ device boundary, 2027 expansion and the identity-package-signing-key model. and /guides
  2. Android Developers, developer verification FAQ, updated 27 August 2026 and extracted 29 August 2026. Verified the limits of September enforcement, the treatment of direct sideloading and non-participating stores, the advanced flow, ADB exception, form-factor boundary and statement that verification does not collect app content or functionality
  3. Android Developers, "Register on Google Play Console", updated 18 August 2026 and extracted 29 August 2026. Verified that most Play identities need no new identity step, 99 per cent of Play apps were automatically registered and remaining packages must be checked before 30 September
  4. Android Developers, "Register on Android Developer Console", updated 20 August 2026 and extracted 29 August 2026. Verified the outside-Play route, package-name registration, SHA-256 signing certificate fingerprint and signed-APK ownership challenge
  5. Android Developers, "Register for limited distribution on Android devices", updated 20 August 2026 and extracted 29 August 2026. Verified the free account, 20-device limit, no-government-ID condition, two-step verification and payments-profile requirements
  6. Android, "Play Protect Certified Android devices", extracted 29 August 2026. Verified what Google means by a certified Android device and why the verification scope does not describe every Android-derived device

Help us improve

Was this article useful?

One anonymous tap helps Sona improve future reporting, headlines and source context.

Up next

Unbranded smartwatch battery lifted from a sealed case in a professional repair cradle
Tech
EU battery exception would shift some wearable repairs to professionals

A Commission measure awaiting scrutiny would keep qualifying batteries replaceable, but let independent professionals handle some compact wearables and specialised devices.

Continue reading

More in Tech

Unbranded smartwatch battery lifted from a sealed case in a professional repair cradle Tech
EU battery exception would shift some wearable repairs to professionals
A conceptual smart-home security tag opens onto an update wheel, finite support timeline and configuration record. Tech
The US Cyber Trust Mark is a doorway, not a security score
A sealed passkey cassette moves between compatible Android password-manager docks while a loose file route stays blocked. Tech
Android now has a route for moving passkeys between password managers
Hannah Wright, Senior Editor at Sona News
Written by
Hannah Wright
Senior Editor, Sona News

British journalist and Senior Editor at Sona News, covering politics, macro-economics and institutions from London.

Read next EU battery exception would shift some wearable repairs to professionals