A blank navy booklet like a passport beside a phone face down in a navy case and a rubber stamp with a coral handle, on pale blue paper

Android developer verification: what changes outside Google Play

By Zdeněk Dolák, Founder6 min read

From 2027, Google plans to require verified developers for Android apps installed outside Google Play too. Who is affected, what it takes, what to do now.

Google plans to require, from 2027, that every app installed on a certified Android phone or tablet comes from a developer who has verified their identity with Google, including apps installed outside Google Play.

The first phase started on 30 September 2026 in Brazil, Indonesia, Singapore and Thailand, and only for apps installed from seven app stores. Google has not published a date for the EU or Czechia. Its documentation says the requirement will roll out globally "in 2027 and beyond".

If your Android app is only on Google Play, under an account your company owns, there is probably little to do. This article is for companies that put an app on devices some other way: as an APK from their website, through another store, by a link sent to field staff, testers or partners, or through a supplier's developer account.

What developer verification is

Google calls it an identity check, not a review of the app. A developer proves who they are, then registers each app's package name and the signing key it is signed with. Android devices then check, before installing or updating an app, whether it is registered to a verified developer.

The check runs on certified Android devices running Android 7 or later: phones and tablets that ship with Google Play. Google delivers it through Google Play services rather than through an Android update, so older phones are covered too.

Google says verification does not collect information about what the app does, so an app built under a non-disclosure agreement can be registered without describing it.

What has happened and what is planned

WhenWhat happensWhere
August 2026Limited distribution accounts, the console API and the advanced install flow for unregistered apps launchedWorldwide
30 September 2026Installs and updates from seven stores need an app registered by a verified developer: Google Play, Galaxy Store, Xiaomi GetApps, OPPO App Market, vivo V-Appstore, HONOR App Market and Palm StoreBrazil, Indonesia, Singapore and Thailand
2027 and beyondThe requirement extends to all apps on certified Android devices. Google gives no month and no list of countriesGlobal, according to Google's plan

In the four first countries, apps installed directly or from stores outside the list are not affected yet. Google's FAQ says so explicitly. The global phase is where apps distributed outside any store come in.

Who has to register, and who doesn't

Apps on Google Play. Google says 99% of Play apps were registered automatically, using the identity the developer already verified for Play. New apps are registered when they are created in Play Console. Check the Play Console home page for apps that still need action.

Apps distributed outside Google Play. Register them, either in Play Console if you already have an account there, or in the separate Android Developer Console if you distribute only outside Play. Google enforces the requirement only for phones and tablets outside Play, but recommends registering apps for other form factors too.

Apps on managed company devices. Google exempts apps installed from an organisation's own managed store on managed devices, because the company's IT administrator has already vetted them. It still recommends registering them: once the requirement applies, an unregistered app installed from a link or on a personal phone runs into the check.

Installs over a USB cable. Apps installed with Android Debug Bridge (ADB), the developer tool, don't need verification. That covers development and testing on a developer's own devices. It isn't a way to roll an app out to a team.

Limited distribution accounts. Students, teachers and hobbyists can share an app with up to 20 devices without an ID or a fee. Google designed this for learning and personal use, not for a company's apps.

What happens to an unregistered app

Once the requirement applies, an unregistered app installs only through ADB or through what Google calls the advanced flow. The advanced flow is a one-time setup on each phone:

  1. Turn on developer options in the system settings.
  2. Confirm that nobody is coaching you through the change.
  3. Restart the phone and sign in again.
  4. Wait 24 hours, then confirm with a fingerprint, face or PIN.
  5. Allow unregistered apps for 7 days or indefinitely. Each install still shows a warning.

If the advanced flow is turned off again, updates to unregistered apps fail.

The steps are deliberate. Google built them to stop scammers who talk people into disabling protection during a phone call. For a company, it means asking every warehouse worker, courier or partner to wait a day and accept warnings before your app works. That isn't a realistic way to distribute a business app.

What registration needs

For a company, a full distribution account in the Android Developer Console asks for:

  • A D-U-N-S number, the company identifier from Dun & Bradstreet. It's free, but Google warns it can take up to 28 days to issue, so apply early.
  • A website verified in Google Search Console.
  • Official company documents, and a contact email and phone number confirmed with a one-time code.
  • A USD 25 fee, which Google compares to Play's own registration fee.

An individual developer submits a government photo ID and a proof of address instead.

For each app, you register its package name (the identifier such as com.example.app) and the SHA-256 fingerprint of its signing certificate. For a package name already in use, you prove ownership by signing a test APK containing a code snippet the console gives you.

That last step needs the signing key. Apps that use Play App Signing are registered from what Google already holds. For an app signed outside Play, Google's FAQ is blunt: "If you lose your signing key you won't be able to register your packages." If someone else already uses your package name, registration goes through an extra review, and Google may suggest a different name.

Who should own the developer identity

The company whose app it is. Registration ties an app to a verified developer's identity and signing key. If a supplier registers your app under its own account, the app is tied to the supplier's identity.

Google's documentation we checked doesn't describe moving a registered package name from one account to another. Registering in your company's name from the start avoids depending on such a process later. It is the same principle as for store accounts and signing keys, covered in who owns your app.

A supplier can still do the work under your account. Play Console lets you invite them as a team member, and the Android Developer Console API lets a third-party platform you authorise register package names and keys on your behalf.

What to do now

  1. List every Android app you distribute and how each reaches devices: Google Play, a managed store, an APK on a website, another store or a link to testers and partners.
  2. Check Play Console for apps that weren't registered automatically, and register apps you distribute outside Play in the same account.
  3. Decide whose account registers the rest. It should be your company's. If you have no D-U-N-S number, apply now; it is needed for Play and Apple organisation accounts too.
  4. Find the signing key of every app signed outside Play. If a supplier or a former employee holds it, sort out access before the requirement reaches Europe.
  5. Ask IT how apps reach company phones. Installs from a managed store on managed devices are exempt, but links sent around and personal phones are not.
  6. Watch for Google's date for Europe. Until Google publishes one, 2027 is a plan, not a deadline.

If you want a second opinion on how your Android apps are distributed and who holds what, the mobile app development page describes how we work. A short description through the contact page is enough to start; please don't send keys or passwords.

Sources

Checked on 7 October 2026.