APK viewer: check an Android app before you install it
Got an .apk from a website, a forum, a friend or an APK mirror? See what it is before your phone does: the package name and version, which Android versions it runs on, every permission it asks for with the dangerous ones first, which of its parts other apps can call, and the SHA-256 fingerprint of the certificate it was signed with.
The file is read by this tab only. It is not uploaded, not installed and not run.
What it shows
- Which app it is. The package name (the ID Android and Google Play know the app by, such as
org.mozilla.firefox), the app's name and launcher icon taken from its resources, the version name and the version code. Android compares the version code to decide whether an install is an update. - Which Android it needs. Minimum, target and compile SDK, each with its Android version: API 26 is Android 8.0, API 34 is Android 14. An app with a minimum of 29 will not install on an Android 9 phone.
- Every permission it asks for, each with a one-line meaning in Android's own words. Dangerous permissions come first (location, camera, microphone, contacts, SMS, call log), then special-access ones such as drawing over other apps or installing other apps. Permissions only system apps can get are marked as such.
- Its components: activities (screens), services, broadcast receivers and content providers. Exported ones are flagged, because other apps can start or query them. You also get the web addresses and app links it claims to open.
- Who signed it. Each signer certificate's subject, validity dates and SHA-256 fingerprint, from the old v1 JAR signature (
META-INF/*.RSA,.DSA,.EC) and from the v2, v3 and v3.1 blocks of the APK Signing Block. The same key in every scheme is shown once. - Native libraries by processor (arm64-v8a, armeabi-v7a, x86_64…), the number of DEX code files, the SHA-256 of the whole file, and the decoded
AndroidManifest.xml. See every file opens the same APK in the archive viewer, so you can open any picture or text file inside it.
What it cannot do
- No malware verdict. The page shows what the app declares and who signed it. It does not judge whether the app is safe. Many harmful apps ask for few permissions, and many honest ones ask for a lot.
- No signature verification. Certificates are read and fingerprinted, never checked against the file's contents, so a tampered APK carrying a copied certificate looks the same here as the original. Android verifies the signature when it installs the app, and
apksigner verify --print-certs app.apkfrom the Android SDK does it on a computer. - No .aab manifest. An Android App Bundle is what developers upload to Google Play. Its manifest is stored as a protocol buffer, not binary XML, so it is named and its files are listed, but its permissions are not read.
- No decompiling. The app's code (
classes.dex) is counted, not decompiled. Whether the code actually uses a permission, and what for, is not visible here. - Encrypted bundles. Newer
.apkmfiles from APKMirror keep their APKs encrypted, so only APKMirror's own installer can open them. The page says so.
Useful to know about APKs
- Comparing the fingerprint
- Every APK is signed with its developer's key, and Android installs an update only when the new APK is signed with the same key as the app already on the phone. If the SHA-256 fingerprint here matches the one the developer publishes (many open-source projects list it in their README or on their download page, and F-Droid shows it for reproducible builds), the file came from whoever holds that key. A different fingerprint for the same package name means a different signer.
- Dangerous, normal and special
- Since Android 6.0 (API 23), Android asks you at run time before an app gets a dangerous permission, and you can take it back in Settings. Normal permissions, such as internet access, are granted at install without a prompt. Special access (drawing over other apps, installing unknown apps, all-files access) stays off until you switch it on in Settings. The levels shown here come from a snapshot of AOSP's core
AndroidManifest.xml, the file that defines every platform permission. - Signature schemes
- v1 is the JAR signature from Android 1.0. v2 (Android 7.0, API 24) signs the whole file, so a changed byte anywhere breaks it. v3 (Android 9, API 28) adds key rotation, and v3.1 (Android 13) lets a rotated key apply only from a given Android version. v4 (Android 11) lives in a separate
.idsigfile used for streaming installs. A modern APK usually carries v2 or v3, plus v1 if it still supports Android 6 or older. - Exported components
- An exported activity, service, receiver or provider can be started or queried by any other app on the phone. That is how sharing and app links work, and it is also the most common source of security bugs in Android apps. An app that targets Android 12 (API 31) or later must set
android:exportedon every component with an intent filter. In older targets such a component was exported by default. The page tells you which rule applied. - Splits and bundles
- Google Play delivers most apps as a base APK plus config splits: one for your processor's native libraries, one for your screen density, one per language. Sites like APKPure (
.xapk), APKMirror (.apkm) and the SAI installer (.apks) zip those APKs together. A phone cannot install the bundle file itself; their installer app installs the splits together.