No, you won't find Signal in F-Droid's catalog: here's why

Published: October 7, 2026 · Updated: October 8, 2026

No. Signal is not in F-Droid's official catalog, and refreshing the repository won't change that. If you search "Signal" inside the F-Droid app, the official app simply isn't there. The short version of why: F-Droid builds apps from source code and signs the finished APKs with its own keys, so the app you'd install wouldn't be the build Signal published and signed. Signal's team has declined that arrangement for years. They want one official build, signed by them, reaching users untouched. The good news is that F-Droid users are not stuck: you can install Signal's own APK directly and verify its signature yourself, or you can use the independent fork Molly, which publishes its own F-Droid-compatible repository. This guide walks through the real reasons, what each option costs you, and how to stay safe either way.

A phone showing the F-Droid store with a search for Signal returning no results, beside a shield

What "not on F-Droid" actually means

Let's be precise, because people mean three different things by this question. One: "Is Signal listed in the official F-Droid repository?" Answer: no. The package org.thoughtcrime.securesms is not in F-Droid's main catalog, so the F-Droid client app will never offer it. Two: "Can I install Signal through the F-Droid app at all?" Answer: not directly, but the F-Droid client can use third-party repositories, and the independent Signal fork Molly publishes exactly such a repo. Three: "Does the open-source community support Signal without Google?" Answer: yes, through sideloaded APKs and forks, just not through F-Droid's official catalog. Most of the confusion comes from mixing these up. Someone reads "Signal is open source, F-Droid hosts open-source apps, so Signal should be on F-Droid" and concludes something must be wrong. Nothing is wrong; the two projects have incompatible distribution philosophies, and they have known it for years.

The real reasons, without the conspiracy theories

The story starts with how F-Droid works. Unlike the Play Store, which hosts files the developer uploaded and signed, F-Droid builds most apps from source code on its own build servers and signs the finished APKs with F-Droid's own per-app signing keys. That is documented in F-Droid's own writings on signing keys: for the bulk of its catalog, the signature on the APK belongs to F-Droid, not to the app's developer.

Signal's team has said, in public issue threads going back years, that they are not comfortable with this. Their position, in plain language, has three parts:

None of this requires believing anyone is acting in bad faith. It is a policy difference: F-Droid's model is "we build it so you don't have to trust the developer's binary," and Signal's model is "trust only the binary we built and signed." Both are coherent. They just don't fit together.

A note on reproducible builds, because it comes up: F-Droid now supports a mode where it verifies that its own build matches the developer's published APK and then ships the developer's signed binary. In principle, this resolves the signing-key objection. In practice, it requires the app to be built reproducibly and the developer to cooperate, and Signal has still not moved to publish there. The door is technically open; nobody is walking through it.

This isn't FUD about F-Droid

It is worth saying plainly: F-Droid is a legitimate, well-run project, and this guide is not an attack on it. For hundreds of apps, F-Droid's source-built, independently signed model is a fine tradeoff, and in some ways it is more transparent than trusting a developer's binary blindly. The issue here is specific to Signal's requirements, not a verdict on F-Droid. When you see forum posts claiming Signal avoids F-Droid "because they have something to hide," that is nonsense. Signal's client code is public, and their refusal is about distribution control, which is a defensible engineering choice whether or not you agree with it. Judge the arrangement on its technical merits, not on tribal loyalty to one store or the other.

What F-Droid users actually do

Four-step diagram showing the manual official-APK route for F-Droid users
Same official APK, just fetched by hand.

If you run a de-Googled phone and F-Droid is your home base, you have two clean paths to Signal-class messaging. Both are legitimate; they just hand you different trust tradeoffs.

Option 1: sideload Signal's own APK and verify the signature yourself. Download the APK from Signal's official APK page, then verify the signing certificate with the method in our SHA-256 verification walkthrough or the step-by-step apksigner command guide. This is the closest thing to what F-Droid would give you, except the signer is Signal itself, which is exactly what Signal wants. The website build also updates itself automatically, so you are not stuck checking for updates by hand. This is the option Signal officially supports for people outside the Play Store.

Option 2: install Molly through its own F-Droid repository. Molly (molly.im/fdroid) is an independent, hardened fork of Signal, not the official app, and it should never be confused with one. It keeps its own F-Droid-compatible repository that you add to your F-Droid client alongside the official catalog. Because the repository is Molly's own, the builds come straight from Molly's developers rather than being rebuilt and re-signed by F-Droid. Molly is a separate project with its own signing keys and its own release notes; read our Molly fork guide before deciding.

Download the official Signal APK

from Signal's official site — file hosted by Signal, not by us

The honest tradeoffs, in one table

Comparison table of the official Signal APK versus the F-Droid route
F-Droid users aren't out of luck. They just take the manual road.
QuestionSignal's own APK (sideloaded)Molly via its F-Droid repo
Who signed the app?Signal FoundationMolly's developers
Who are you trusting?Signal onlyMolly's project (plus Signal's servers, which both use)
UpdatesAutomatic, straight from SignalThrough the repo; follows Signal releases with a small delay
F-Droid client integrationNone: installed outside F-DroidFull: shows up in the F-Droid app once the repo is added
Verification possibleYes: compare the SHA-256 fingerprint to Signal's published valueYes: Molly publishes its own signing fingerprints
Official support from SignalYes: this is their supported pathNo: it is an independent fork; Signal's team does not support it

The row that matters most is the first one. If your priority is "I want the fewest parties between me and the code," the sideloaded official APK wins: one signer, one updater, one party to trust. If your priority is "everything I install should come through my F-Droid client with a consistent workflow," Molly's repo is the practical answer, with the understanding that you are trusting a different development team. Neither choice is free, and neither is wrong. What is wrong is grabbing a random "Signal" APK from a mirror site because it was the first search result. See our guide on whether the official APK can contain malware for why that is the one move to avoid.

Will Signal ever land on F-Droid?

Honest answer: don't hold your breath. The reproducible-build path that could resolve the signing objection has existed for a while now, and Signal's position hasn't moved. Positions like this change when a project decides the distribution benefit outweighs the control cost, and nothing in Signal's history suggests that tradeoff is coming soon. The practical advice is to pick one of the two working options above and move on. Check back once a year if you like. The F-Droid inclusion policy and Signal's stance are both public, but don't let a missing store listing keep you from messaging securely today. The verified APK is a five-minute job, and the guides linked above walk you through every step.

Frequently asked questions

Why is Signal not on F-Droid?

Signal is not in F-Droid's official catalog because F-Droid builds apps from source and signs them with its own keys, while Signal insists that only its own signature appears on the official app. Signal has declined this arrangement for years, citing the signing chain, update speed, and a policy against third-party builds of the official app.

Is there any way to install Signal through the F-Droid app?

The official Signal app, no. But the F-Droid client supports third-party repositories, and the independent fork Molly publishes its own F-Droid-compatible repo at molly.im/fdroid. Molly is a separate project with its own signing keys, not the official Signal app.

Is F-Droid unsafe because Signal won't use it?

No. F-Droid is a legitimate open-source app store, and its source-built model is fine for many apps. Signal's refusal is about its own distribution requirements (one official build, signed by Signal, updated instantly), not a verdict on F-Droid's safety.

Which is safer: sideloading Signal's APK or using Molly?

The sideloaded official APK has the fewest trusted parties: one signer (Signal) and automatic updates from Signal. Molly adds a second development team to trust but integrates with the F-Droid client. Both are defensible; what matters is downloading each from its real source and verifying signatures.

Will Signal ever be added to F-Droid?

Unlikely in the near term. The technical path (reproducible builds shipped with the developer's signature) already exists and Signal still hasn't moved. Pick a working option (the verified website APK or Molly) rather than waiting.

Keep reading