Android developer verification for private apps

Starting September 30 2026, private Android apps on unmanaged Google Play Protect certified Android devices must be registered to a verified developer identity to remain installable and receive updates. Apps deployed on fully managed devices or within Work Profiles are exempt from these requirements. This guide helps IT admins choose the right registration path and complete the steps.

Overview

Android developer verification is designed to protect the Android ecosystem by ensuring that every app originates from an authenticated, real-world identity. Verifying a developer’s identity establishes accountability, making it significantly harder for bad actors from repeatedly distributing scams, financial fraud, and harmful apps. Ultimately, these requirements build a safer digital environment, giving users peace of mind that the apps they install come from legitimate, verified sources. Learn more about these requirements.

Does this apply to your organization?

The requirements for Android developer verification depend on the distribution method and the device management status of your organization's devices. Understanding whether your devices are managed or unmanaged is the first step to determining if your apps need to be registered.

  • Managed devices: No - Enrolling in EMM or MDM management exempts your devices. Private apps distributed only to EMM managed devices or Work Profiles don’t require developer verification registration.
  • Unmanaged devices: Yes - You must register private apps distributed to unmanaged devices with a verified developer account. Apps that are not registered through the Android developer verification process cannot be installed or updated on unmanaged devices.
Note: The system considers a device managed if it is enrolled in Android Enterprise management. This includes fully managed or Work Profile modes through an EMM or MDM solution. Unmanaged devices are personal or unenrolled devices. Private apps on fully managed devices or with Work Profiles are not affected. Private apps distributed to managed Android Enterprise devices are currently exempt from Android developer verification requirements.

Registration options

Google provides two consoles that can be used for developer verification and package name registration:

  • Google Play Console: This is the main developer platform for publishing and managing Android apps distributed via the Google Play Store. Developers can complete an identity check in this console to verify their identity. App package name registration is not required when using the Google Play Console
  • Android Developer Console: This standalone console is made for developers who distribute apps outside of Google Play. Developers can use this console to verify their identity and register their app package names. However, it is not an app publishing platform.
Note: To register a package name in the Android Developer Console, you must complete a cryptographic challenge using your private key. If Google Play manages your signing key, we will share more details soon.
(Recommended) Option 1: Register through the Android Developer Console

Developers that have not completed identity checks through the Google Play Console can use the Android Developer Console to verify their identity. This includes developers of private apps that are distributed to unmanaged devices.

Note: This option requires the SHA-256 certificate fingerprint from your app's signing key pair.

Step 1: Set up an Android Developer Console account

  1. Create an Android Developer Console account using a Google Account.
  2. Select Full Distribution  Organization Account.
  3. Enter your corporate domain email address. The system blocks generic @gmail.com addresses.
  4. Link a Google Payments profile that has your organization's legal name, address, and D-U-N-S number.
  5. Provide contact information and complete the email verification.
  6. Accept the Android Developer Console terms, and pay a $25 USD fee to finish creating your account.

Step 2: Register your app package names

  1. In the Android Developer Console, go to Packages Register Package.
  2. Enter your app's Package Name and a friendly display name.
  3. Add your SHA-256 certificate fingerprint:
    • New package names: Enter the SHA-256 fingerprint. Verification is usually completed within minutes.
    • Existing package names: Complete the cryptographic challenge. To do this, place the generated nonce token in a dummy APK's asset directory. Sign it with your production private key. Finally, upload to prove key ownership.
  4. Sign and upload an APK.
Option 2: Enroll devices in management

When you enroll unmanaged devices into Android Enterprise management, the system automatically exempts private apps from Android developer verification enforcement. This includes devices with a Work Profile or in fully managed mode.

Option 3: Enable advanced flow on end-user devices

End-users can manually allow unregistered private apps on unmanaged devices. To do this, enable the advanced flow setting in the Android developer options.

Was this helpful?

How can we improve it?
Search
Clear search
Close search
Main menu
16740426038623362557
true
Search Help Center
false
true
true
true
true
true
108584
false
false
false
false
false