Find SHA-1 and SHA-256 Fingerprints for the Right Build
An Android certificate fingerprint identifies a signing certificate using a hash algorithm. SHA-1 and SHA-256 fingerprints of the same certificate look.
Read embedded signing-certificate metadata: scheme presence, SHA-1/SHA-256 fingerprints, subject, issuer and certificate dates. This does not verify cryptographic integrity or the signer’s real-world identity.
Android Signing Certificate Checker is part of APKLint, an online toolkit for inspecting Android APK files. Read embedded signing-certificate metadata: scheme presence, SHA-1/SHA-256 fingerprints, subject, issuer and certificate dates. This does not verify cryptographic integrity or the signer’s real-world identity. Upload an APK in your browser to view the relevant details; results reflect what the file itself exposes.
Drop your file here
or click to choose from your device
Read embedded signing-certificate metadata: scheme presence, SHA-1/SHA-256 fingerprints, subject, issuer and certificate dates. This does not verify cryptographic integrity or the signer’s real-world identity.
Android Signing Certificate Checker is part of APKLint’s apk & aab analysis toolkit — Unpack, inspect, and break down Android packages. It’s free to use and needs no account.
Your privacy is the default: files you upload are processed on our servers over an encrypted connection and permanently deleted by a scheduled hourly cleanup after analysis finishes, and never shared.
Good to know: Reads embedded certificate metadata. Signature cryptography, APK integrity, real-world identity and Play App Signing upstream are not verified.
Every tool is free with no login and no paywall. Reasonable file and input limits keep the free service stable.
A clean, focused interface with no third-party ad banners cluttering your results.
Files you upload are deleted by a scheduled hourly cleanup after analysis finishes, and never shared.
Built on androguard for APK parsing and manifest/certificate analysis.
Start immediately — no account, login, or email required.
Runs in any modern browser, on desktop or mobile.
Read embedded signing-certificate metadata: scheme presence, SHA-1/SHA-256 fingerprints, subject, issuer and certificate dates. This does not verify cryptographic integrity or the signer’s real-world identity.
It's in the certificate read-out. Many Google APIs ask for the signing SHA-1 or SHA-256 — both are shown here.
Yes. Every tool on APKLint is completely free, with no sign-up and no account.
Your uploaded file and its result are processed on our servers over an encrypted connection, then removed by the next hourly cleanup after analysis finishes. We never share them.
An Android APK — a .apk file — up to 1 GB.
All product names, logos, and trademarks are property of their respective owners. APKLint is an independent toolset and is not affiliated with, endorsed by, or sponsored by Google, Android, or any other party.