How to Verify the Signal APK's Signing Certificate Fingerprint

Published: October 7, 2026 · Updated: October 8, 2026

Short answer: Signal publishes the SHA-256 fingerprint of its signing certificate on signal.org/android/apk. Before you install the APK, check the file's signature with apksigner (or an on-device signature viewer) and compare the fingerprints. If they match, the file really came from Signal and nobody tampered with it. If they don't, delete it.

This check takes about five minutes and it is the single strongest thing you can do before sideloading any app. Play Protect scanning, antivirus apps, and "it looked legit" are all weaker signals. The signature is math: only the holder of Signal's private signing key can produce an APK that matches Signal's published fingerprint. A repackaged fake with spyware inside cannot fake that match.

Get the official Signal APK

from Signal's official site — file hosted by Signal, not by us

A document showing the Signal APK's SHA-256 certificate fingerprint being compared, with a Match result

What the fingerprint actually proves

Every Android app is signed with the developer's private key when it is built. The signature does two jobs: it proves who made the app, and it proves the app was not modified after signing. The SHA-256 fingerprint is a short, readable digest of the signing certificate. Think of it as the key's public ID card.

Here is what matters for you in practice:

One caution: the fingerprint belongs to the website build's signing key. The Play Store build uses a different key, so a Play-installed Signal will show a different fingerprint. That is expected and fine. Do not mix the two up when comparing.

Checklist graphic for: What the fingerprint actually proves
Checklist: what the fingerprint actually proves.

The fingerprint on Signal's page

Signal's download page shows the SHA-256 fingerprint for its 4096-bit signing certificate. Quoted directly from signal.org/android/apk — we re-verified this value live on October 7, 2026:

4B:E4:F6:CD:5B:E8:44:08:3E:90:02:79:DC:82:2A:F6:5A:54:7F:EC:C2:6A:BA:7F:F1:F5:20:3A:45:51:8C:D8

Always re-check the live page before you verify. Signal can rotate its keys, and the page is the source of truth, not this guide.

The page also mentions a second, older fingerprint for a 1024-bit certificate:

29:F3:4E:5F:27:F2:11:B4:24:BC:5B:F9:D6:71:62:C0:EA:FB:A2:DA:35:AF:35:C1:64:16:FC:44:62:76:BA:26

You may see this one if your verification tool is out of date and does not support the latest Android APK Signature Scheme. If you see it with a current tool, treat it as a mismatch. Update your tools and check again. The fix Signal suggests is to update to the latest Android SDK Build Tools.

Keypoints graphic for: The fingerprint on Signal's page
Key points: the fingerprint on signal's page.

Method 1: check with apksigner (computer)

This is the method Signal's own page recommends. Run apksigner verify -v --print-certs --min-sdk-version 24 your-file.apk (part of the Android SDK Build Tools), and compare the SHA-256 certificate digest in the output with the fingerprint on Signal's page, character by character. If even one pair differs, stop. Do not install. Our apksigner command guide walks through installing the tool, reading the output, the keytool alternative, and troubleshooting.

A successful check ends with apksigner reporting the APK as verified and a digest that matches the published fingerprint. Both conditions matter: "verified" alone only means the file is self-consistent, not that Signal signed it.

Method 2: check on your phone

No computer handy? You can check the signature on the phone itself with an APK signature viewer app. The general procedure:

  1. Install a reputable APK signature viewer

    Look for an open-source APK analyzer or signature viewer from a source you trust (F-Droid is a good place to find them). You want an app whose only job is reading APK metadata, not a "cleaner" or "booster" app.

  2. Open the downloaded Signal APK in the viewer

    Point the viewer at the APK file in your Downloads folder. Do not install the APK yet. Just inspect it.

  3. Find the signing certificate's SHA-256

    The viewer will show certificate details for the signer. Look for the SHA-256 fingerprint or "certificate digest."

  4. Compare with Signal's published fingerprint

    Open signal.org/android/apk in your phone's browser and compare the two values character by character.

This method is slightly less rigorous than apksigner (you are trusting the viewer app to read the signature correctly), but it is far better than no check at all, and it catches the common cases: repackaged fakes and corrupt">File hash vs certificate fingerprint

People mix these up constantly, so here is the distinction that actually matters for safety:

CheckWhat it proves
File hash (SHA-256 of the .apk file)That the file downloaded without corruption. It says nothing about who made the file. A perfectly intact fake has a perfectly valid hash.
Certificate fingerprint (SHA-256 of the signing cert)Who signed the app. Only Signal's private key produces this fingerprint. This is the check that catches repackaged fakes.

Rule of thumb: hash checks integrity, fingerprint checks identity. When safety is the question, identity is the check you want. The full side-by-side is on our APK hash vs signature explainer.

What to do if it doesn't match

First, rule out the boring explanations before you panic:

If a fresh download from the official page still doesn't match, do not install it. Something is wrong. A proxy or network middlebox may be modifying downloads, or the page itself may have changed (check whether Signal announced a key rotation). In that situation, the safe move is to install from the Play Store instead if you can, and report what you found. Never "just try it" with a mismatched signature: the entire point of the check is that a mismatch is a hard stop.

Frequently asked questions

Where is the official SHA-256 fingerprint published?

On Signal's own download page, signal.org/android/apk. Always copy it from there at verification time rather than trusting any third-party copy, including this one.

What is the exact apksigner command Signal recommends?

apksigner verify -v --print-certs --min-sdk-version 24 followed by your APK filename. The --print-certs flag is what shows you the certificate fingerprints to compare.

Why am I seeing a different, shorter fingerprint?

You are probably seeing the legacy 1024-bit certificate fingerprint. That happens when your Build Tools are out of date. Update to the latest Android SDK Build Tools and check again.

Does the fingerprint change with each Signal update?

No. The fingerprint identifies the signing key, not the app version, so it stays the same across updates, unless Signal rotates its signing key, in which case the download page will show the new value.

Can a fake APK pass the fingerprint check?

Only if the attacker has Signal's private signing key, which would be a catastrophic breach, not a repackaging scam. For every realistic threat (repackaged spyware, corrupted downloads, impostor apps), the check catches it.

Do I need to verify every update?

The website build updates itself through Signal's own updater, which checks signatures automatically. You mainly need the manual check when you first download the APK or when you grab a fresh copy yourself.

Related guides