HTMLtoApphtmltoapp.net Build free
publish

Android signing keys, explained for people who just wanted an app

8 min readUpdated 2026-10-05By the HTML to App team

Every Android app is signed with a private key that proves later versions come from the same developer: Android refuses to install an update signed with a different key. With Google Play App Signing there are two keys — the upload key, which you use to sign the AAB you upload, and the app signing key, which Google holds and uses to sign what users download. Keep a backup of your upload key; if it is lost, Google can reset it, but only through support.

What signing does

A signature is a cryptographic seal over the APK's contents. It does two jobs: it shows the file was not altered after signing, and it ties the app to a key. Android remembers the key an app was installed with and will only install an update signed by the same key. That is what stops someone else from publishing an "update" to your app.

Keystore, alias, password

Keys live in a keystore file (.jks or .keystore). Inside, each key has an alias and a password. The public half of the key is a certificate, identified by fingerprints such as SHA-1 and SHA-256 — those are what services like Firebase or Google Sign-In ask for.

Upload key vs app signing key

Upload keyApp signing key
Held byYouGoogle (Play App Signing)
SignsThe AAB you uploadThe APKs users install from Play
If lostRequest a reset from Play support—
Fingerprint used forNothing user-facingFirebase, Maps API keys, Sign-In

Shared key (free) vs your own key (Pro)

Free HTML to App builds are signed with a shared release key. That is perfectly valid for installing, testing and sharing an APK — Android only needs a valid signature. It is not suitable for Google Play, where your upload key must be yours alone. Pro signs with a key generated for your account, which you can download and back up. Use that key for every AAB you upload for that app, forever.

The rules

  1. Back up your keystore and passwords in two places (a password manager plus offline storage).
  2. Never commit a keystore to a public repository.
  3. Sign every update of an app with the same key.
  4. Increase the version code with every release; the version name is just a label.

Questions people ask

Can I change the signing key of a published app?

Not by yourself. With Play App Signing you can request an upload-key reset from Google, and Play also supports key rotation of the app signing key for eligible apps.

Is the free shared key safe?

It is safe for installing and sharing APKs. It is not appropriate for publishing on Play, because the key is not unique to you.

Where do I find my app's SHA-256 fingerprint?

In the Play Console under Setup → App integrity for the app signing key, or from your keystore with keytool -list -v.

Your HTML is one upload away from an app

Install the free builder, drop in your HTML file or ZIP, and download a signed APK in a few minutes. No watermark, no card, no Android Studio.

Build my APK free