APK Hash vs Signature: What Each One Actually Proves

Published: October 7, 2026 Updated: October 8, 2026

Short answer: the file hash proves integrity (this file downloaded without corruption), while the signature and its certificate fingerprint prove identity (Signal's private key signed this app). A fake file can have a perfectly valid hash, but it cannot have Signal's signature. For safety, the signature check is the one that matters, and running both takes only a few minutes.

Ask five people how to verify an APK and you will hear "check the hash" and "check the signature" used as if they were the same thing. They are not. They answer two different questions, they fail in different ways, and only one of them catches a malicious fake. This guide explains the difference honestly so you know exactly what each check buys you.

Get the official Signal APK

from Signal's official site — file hosted by Signal, not by us

Diagram comparing file hash (integrity) with signature (identity)

What the file hash proves (and what it cannot)

A file hash, such as the SHA-256 value from sha256sum, shasum -a 256, or Windows certutil -hashfile … SHA256, is a short fingerprint of the file's exact bytes. Change one byte and the hash changes completely. Keep the bytes identical and the hash is identical, on any computer in the world.

What that gives you:

What it does not give you:

What the signature proves (and what it cannot)

Every Android APK is signed with the developer's private key. Android uses that signature to verify updates, and anyone can read the signing certificate's fingerprint with a tool like apksigner:

apksigner verify -v --print-certs --min-sdk-version 24 your-signal.apk

The output includes the SHA-256 fingerprint of the signing certificate. Signal publishes its fingerprint on signal.org/android/apk (re-verified by us on October 7, 2026): 4B:E4:F6:CD:5B:E8:44:08:3E:90:02:79:DC:82:2A:F6:5A:54:7F:EC:C2:6A:BA:7F:F1:F5:20:3A:45:51:8C:D8. If the fingerprint from your file matches that value character for character, only the holder of Signal's private signing key could have produced that APK.

What that gives you:

What it does not give you:

Side by side

Hash vs signature at a glance
File hash (SHA-256 of the .apk)Signature (certificate fingerprint)
Answers"Is this file intact?""Who signed this app?"
Computed withsha256sum, shasum, certutilapksigner verify --print-certs
Compared againstA reference hash from a trusted sourceThe fingerprint published on signal.org/android/apk
CatchesCorrupted or incomplete downloadsRepackaged fakes, tampered files, impostor apps
Cannot catchA perfectly intact fake fileAn old-but-genuine release; bugs in genuine code
Changes per releaseYes, every release has a new file hashNo, the fingerprint is stable across releases

Which check catches which threat

Here is the decision framework. Find your threat in the left column, read across to see which check catches it:

Threat vs check matrix
ThreatFile hashSignature check
Download corrupted by a bad networkCatches itCatches it too (damaged signature)
Repackaged fake with spyware, signed by the attackerMisses it (fake file, valid hash)Catches it (fingerprint will not match)
"Signal Pro / Plus" impostor appMisses itCatches it
File downloaded from a sketchy mirrorOnly if you have a trusted reference hashCatches it (compare to Signal's page)
Proxy or middlebox modifying downloadsCatches it (compare two networks)Catches it (signature breaks)
Signal's own signing key stolenMisses itMisses it (the ultimate worst case)

The pattern is clear: the signature check catches everything the hash check catches, plus the threats that actually matter for safety. The hash check is still worth running because it is fast and it diagnoses the most common real-world problem, a bad download, in seconds.

Comparison chart: Which check catches which threat
File hash vs Signature check.

When each check is enough

One honest limitation: if Signal's private signing key itself were ever compromised, the fingerprint check would not save you, because the attacker could sign fakes with the real key. That would be an industry-shaking event, not something you can defend against with a local check. For every realistic threat, the signature check holds.

What about hashes posted on download sites?

You will sometimes see a third-party download site or forum post listing a SHA-256 hash next to its Signal APK mirror, inviting you to "verify" your download against it. Treat that offer with skepticism:

Mirrors are sometimes unavoidable on slow networks, and a hash from the mirror at least catches corruption in transit. Just know what it does and does not prove: integrity against that mirror's copy, nothing about authenticity. Authenticity always comes back to the signature.

Checklist graphic: What about hashes posted on download sites?
Checklist: The site controls both the file and the hash., A hash from Signal itself would be different., The safe pattern.

How to run both in under five minutes

  1. Hash the file. Follow our per-OS guide: check SHA-256 on Windows, Mac and Linux. Save the hash.
  2. Verify the signature. Run apksigner verify -v --print-certs --min-sdk-version 24 file and compare the SHA-256 certificate fingerprint with 4B:E4:F6:CD:5B:E8:44:08:3E:90:02:79:DC:82:2A:F6:5A:54:7F:EC:C2:6A:BA:7F:F1:F5:20:3A:45:51:8C:D8 from Signal's download page. Our step-by-step: verify the Signal APK SHA-256 fingerprint.
  3. Interpret the results. Hash mismatch plus signature failure usually means a corrupted download: re-download from the official page. Signature mismatch on a fresh official download means do not install, full stop.

Five minutes, two commands, and you have answered both questions: the file is intact, and the file is genuinely Signal's.

Step-by-step diagram of: What the signature proves (and what it cannot)
Steps: Hash the file., Verify the signature., Interpret the results.

Frequently asked questions

Which one matters more, the hash or the signature?

For safety, the signature. A file hash only proves a file is intact; a signature check against Signal's published certificate fingerprint proves who actually signed the app. Integrity without identity is not enough.

Can a fake APK have a valid SHA-256 hash?

Yes. The hash of a fake file is a perfectly valid hash of that fake file. The hash only becomes meaningful when compared to a reference hash from a trusted source, and even then it says nothing about who created the file.

What does apksigner verify actually prove?

It proves the APK's signature is internally consistent and shows you the signing certificate fingerprints. Combined with a comparison against the fingerprint published on signal.org/android/apk, it proves the app was signed by Signal's key.

Does Play Protect replace these checks?

No. Play Protect scans for known malware patterns, which is useful but different: a brand-new repackaged fake may not be in any malware database yet. Use it as a supplement, not a replacement for the signature check.

Related guides