viewhack

APK viewer: check an Android app before you install it

Got an .apk from a website, a forum, a friend or an APK mirror? See what it is before your phone does: the package name and version, which Android versions it runs on, every permission it asks for with the dangerous ones first, which of its parts other apps can call, and the SHA-256 fingerprint of the certificate it was signed with.

The file is read by this tab only. It is not uploaded, not installed and not run.

What it shows

What it cannot do

Useful to know about APKs

Comparing the fingerprint
Every APK is signed with its developer's key, and Android installs an update only when the new APK is signed with the same key as the app already on the phone. If the SHA-256 fingerprint here matches the one the developer publishes (many open-source projects list it in their README or on their download page, and F-Droid shows it for reproducible builds), the file came from whoever holds that key. A different fingerprint for the same package name means a different signer.
Dangerous, normal and special
Since Android 6.0 (API 23), Android asks you at run time before an app gets a dangerous permission, and you can take it back in Settings. Normal permissions, such as internet access, are granted at install without a prompt. Special access (drawing over other apps, installing unknown apps, all-files access) stays off until you switch it on in Settings. The levels shown here come from a snapshot of AOSP's core AndroidManifest.xml, the file that defines every platform permission.
Signature schemes
v1 is the JAR signature from Android 1.0. v2 (Android 7.0, API 24) signs the whole file, so a changed byte anywhere breaks it. v3 (Android 9, API 28) adds key rotation, and v3.1 (Android 13) lets a rotated key apply only from a given Android version. v4 (Android 11) lives in a separate .idsig file used for streaming installs. A modern APK usually carries v2 or v3, plus v1 if it still supports Android 6 or older.
Exported components
An exported activity, service, receiver or provider can be started or queried by any other app on the phone. That is how sharing and app links work, and it is also the most common source of security bugs in Android apps. An app that targets Android 12 (API 31) or later must set android:exported on every component with an intent filter. In older targets such a component was exported by default. The page tells you which rule applied.
Splits and bundles
Google Play delivers most apps as a base APK plus config splits: one for your processor's native libraries, one for your screen density, one per language. Sites like APKPure (.xapk), APKMirror (.apkm) and the SAI installer (.apks) zip those APKs together. A phone cannot install the bundle file itself; their installer app installs the splits together.