apksigner is the strongest check you can run: here's the command

Published: October 7, 2026 · Updated: October 8, 2026

Yes. One command settles the question of whether your Signal APK is genuine. apksigner is Google's official APK verification tool, shipped with the Android SDK Build Tools, and Signal's own download page prints the exact command to use: apksigner verify -v --print-certs --min-sdk-version 24. Run it against your downloaded APK, find the SHA-256 digest line in the output, and compare it character-by-character with the fingerprint Signal publishes on the same page. If it matches, the file was signed by Signal's private key. That is math, not trust. No repackaged fake with malware inside can produce that match. This guide covers installing the tool, running the command on every major OS, reading the output, the keytool alternative, and what to do when something looks off.

A terminal window showing the apksigner verify command and a matching SHA-256 fingerprint with a check mark

Why this beats every other check

Most "is this APK safe" advice is really advice about trust: trust the site, trust the uploader, trust the scanner's opinion. Signature verification is different: it is a mathematical check.

Every APK is signed with the developer's private key, and Android records the signature when the app is installed. apksigner verify --print-certs shows you the signing certificate inside the file. If that certificate's fingerprint matches the one Signal publishes, the file could only have been signed by whoever holds Signal's private key.

A fake can't fake it: anyone who modifies the APK (to add spyware, ads, or anything else) breaks the original signature, and re-signing produces a different certificate with a different fingerprint. So the whole security question collapses to one comparison: does this string match that string? Play Protect scanning, antivirus apps, and "the site looked legit" are all weaker signals than this one check. Do this, and you have done the strongest thing a user can do.

What you need

You need a computer running Windows, macOS, or Linux (the commands below work on all three) and the Android SDK Build Tools, which is where apksigner lives. You do not need Android Studio and you do not need an Android device: this check runs on the APK file itself, before anything is installed.

The command

Signal's download page gives this exact command for retrieving and verifying the certificate before installation:

Terminal showing the apksigner verify command and its output for the Signal APK
One command, one digest: compare it with the official one.
apksigner verify -v --print-certs --min-sdk-version 24

Run it with your APK file as the argument:

apksigner verify -v --print-certs --min-sdk-version 24 Signal-Android-website-prod-universal-release-8.29.3.apk

What each flag does, in plain language:

Reading the output

A successful run prints a "Verifies" confirmation followed by per-signer details. The lines you care about look like this:

Verifies
Verified using v1 scheme (JAR signing): true
Verified using v2 scheme (APK Signature Scheme v2): true
...
Signer #1 certificate SHA-256 digest: 4be4f6cd5be844083e900279dc822af65a547fecc26aba7ff1f5203a45518cd8
...

Two things to know about reading it. First, the fingerprint in the terminal is usually printed without colons and in lowercase, while Signal's page prints it with colons and uppercase (4B:E4:F6:CD:...). That is the same value in two formats. Strip the colons and compare case-insensitively, or reformat one side to match the other. Second, "Verified using v1/v2 scheme: true" tells you the signature is structurally valid. That's necessary but not sufficient: a perfectly valid signature from someone else's key also verifies. The fingerprint comparison is what ties the file to Signal.

Comparing the fingerprint

This is the moment of truth. Signal publishes the SHA-256 fingerprint of its 4096-bit signing certificate on its download page. At the time this guide was written (re-verified live from that page on 2026-10-07), it reads:

4B:E4:F6:CD:5B:E8:44:08:3E:90:02:79:DC:82:2A:F6
5A:54:7F:EC:C2:6A:BA:7F:F1:F5:20:3A:45:51:8C:D8

Compare every character of your terminal output against this value (ignoring colons and case). Match: the APK was signed by Signal's key. Install with confidence. Mismatch: the file is not Signal's build. Delete it and re-download from the official page.

Always cross-check against the live page

One standing rule: always cross-check against the live page, not against this guide or any other copy. We verified this value on October 7, 2026 and will re-check it, but Signal can rotate keys, and a value copied from anywhere, including this page, is a value you didn't verify. The live page is the authority; everything else is a convenience. Signal's page also notes that very old versions of apksigner may show a different fingerprint for a legacy 1024-bit certificate. If you see that, update your Build Tools and run again rather than trusting the old output.

Why this guide quotes the fingerprint

Why does this page quote the fingerprint while our other guides just say "published on Signal's page"? Because this guide is specifically about performing the comparison, and showing the real format (colon-separated, uppercase) helps you recognize it. The build brief's rule stands: the value is quoted only because it was re-verified live at build time, and you should still confirm it on the live page before trusting a download.

Download the official Signal APK

from Signal's official site — file hosted by Signal, not by us

The keytool alternative

No Android SDK handy? keytool ships with every Java JDK and can extract the same fingerprints:

keytool -printcert -jarfile Signal-Android-website-prod-universal-release-8.29.3.apk

The output lists the certificate's owner and a "Certificate fingerprints" section with SHA1 and SHA256 values. Take the SHA256 line and compare it to Signal's published fingerprint the same way: strip colons, ignore case, match every character. The security guarantee is identical. You're reading the same signing certificate through a different tool. One caveat: keytool shows you the certificate but doesn't verify the APK's signature schemes the way apksigner verify does. For a pre-install authenticity check it's fine; apksigner remains the more complete tool.

The full verification checklist

StepActionExpected result
1Download the APK from signal.org/android/apkFile named like Signal-Android-website-prod-universal-release-8.29.3.apk
2Confirm the package name is org.thoughtcrime.securesmsExact match: impostor apps use look-alike names
3Run apksigner verify -v --print-certs --min-sdk-version 24 <file>Output starts with "Verifies"
4Read the "Signer #1 certificate SHA-256 digest" lineA 64-hex-character fingerprint
5Open the live download page and compareEvery character matches (colons and case aside)
6Only then installA genuine, Signal-signed APK on your phone
The full APK verification checklist: official URL, apksigner, digest comparison, keytool
Do all four and a fake APK cannot slip through.

Do these six steps in order every time you download a fresh APK (updates included). It takes about two minutes once you've done it once, and it is the single highest-value security habit in sideloading. Our SHA-256 verification walkthrough covers the same check from the non-technical side if you want the conceptual version first.

Troubleshooting

Frequently asked questions

What is the exact apksigner command to verify the Signal APK?

apksigner verify -v --print-certs --min-sdk-version 24 : the command printed on Signal's own download page. The -v and --print-certs flags show the signing certificate fingerprints you need to compare.

Where do I get apksigner?

It ships with the Android SDK Build Tools. No Android Studio required. Look in $ANDROID_HOME/build-tools// (apksigner.bat on Windows). Signal's page recommends updating to the latest Build Tools so it understands current signature schemes.

What should the output look like?

It starts with 'Verifies', confirms the v1/v2 signature schemes, and lists a 'Signer #1 certificate SHA-256 digest' line. Compare that fingerprint character-by-character with the value published on signal.org/android/apk. A match proves the file was signed by Signal's key.

Can I verify without the Android SDK?

Yes: keytool -printcert -jarfile (ships with any Java JDK) prints the certificate's SHA256 fingerprint for the same comparison. apksigner remains the more complete check since it also verifies the signature schemes.

My fingerprint doesn't match. What do I do?

Don't install the file. Delete it and re-download from signal.org/android/apk, then verify the fresh copy. A persistent mismatch means the file is not Signal's build.

Why does Play Protect still warn after a successful verification?

Play Protect doesn't recognize the website build's signing certificate because it differs from the Play Store build's key. A verified signature is stronger evidence than the scanner's caution. See our Play Protect guide for the details.

Keep reading