Google's Android developer verification stopped being a future plan on 30 September 2026. From that date its protections apply on certified Android devices in Brazil, Indonesia, Singapore and Thailand, and Google lists a global rollout for 2027 and beyond. If you ship an Android app, the useful question is not whether this touches you. It is which of three paths you are on.
What verification checks, and what it skips
Verification is an identity check. Google's help page for the Android Developer Console says it confirms "who the developer is, not reviewing the content of their app or where it came from." Your app is not reviewed any differently than before.
The reason, per Google's announcement on the Android Developers Blog, is malware: Google says it found over 90 times more malware from sideloaded sources than on Google Play. The rule applies to every developer, whether the app is on Play or not.
In the four launch countries, Google's developer page says protections cover users installing from participating stores on certified devices running Android 7 or higher. An app from a developer who has not registered cannot be installed in the normal way. The route for everything else is ADB or the advanced flow, covered below.
Pick your path
Path 1: you only publish on Google Play
This is the easy one. Google says "Google Play automatically registers 99% of apps," and you are registered automatically if you distribute through Play. The leftover 1% need manual registration in the Play Console. Open the console and look for any warning on your apps before you assume you are in the 99%.
Path 2: you also ship outside Play
If you hand out APKs from your own site, push them through a company device programme or list on another store, those packages need registering too. According to Google's developer page, the Play Console covers apps distributed on Play, outside Play, or both, with manual registration for anything not auto-registered. The separate Android Developer Console is for developers who distribute only outside Google Play.
A full-distribution Android Developer Console account needs a government ID and carries a $25 fee, according to the Console Help page.
Path 3: you build for a few people
Students, teachers and hobbyists can use a limited distribution account. It needs no government ID and no fee, but the app can reach only up to 20 devices. That covers a class project, a family tool or a closed pilot.
What if you do nothing?
Your app is not deleted. But in the launch countries, anyone installing it on a certified device has to use ADB or the new advanced flow. Android Authority, writing in June 2026, described that flow as including "a mandatory 24-hour lock and multiple steps during installation." That is fine for a developer testing their own build. It is a wall for a normal user.
Registering package names
Registration ties each package name to your developer account. Google's guide describes the step as proving ownership "by providing the APK signed with your private key." So you need to know which keys sign which builds.
Two commands help when you are collecting that information. The first lists the signing configuration for each build variant in a Gradle project. The second prints the certificate details from a built APK.
./gradlew signingReport
apksigner verify --print-certs app-release.apk
Both are standard Android tooling. Neither registers anything for you; that happens in the console.
The package names people forget are usually the odd ones: a staging flavour with an applicationIdSuffix that real testers use, a white-label build for one client, an old app you stopped updating but never unpublished. If it can be installed from somewhere, it counts.
What it means if you are based in India
The four launch countries do not include India, so nothing changes today for people installing your app at home. But the rule is tied to where the user is, not where you live. If your app is available on Play in Brazil, Indonesia, Singapore or Thailand, it is in scope now. And since Google describes the rollout as global from 2027, the registration you do this month is work you would otherwise do under time pressure later.
Agencies and freelancers have an extra job: client apps. If you publish under a client's developer account, ask who completed identity verification and who holds the signing key. If you publish under your own account, make sure the client knows the apps are tied to your identity.
A one-week checklist
List every package name you have ever distributed, including regional and client builds.
For each one, note where it is distributed: Play only, or also outside Play.
Check the Play Console for apps that were not auto-registered and register them manually.
If you ship APKs outside Play, register those packages in the Play Console, or set up an Android Developer Console account if you do not publish on Play at all.
Tell beta testers and clients in Brazil, Indonesia, Singapore and Thailand what to expect if a build is not registered.
Put the 2027 global rollout in your roadmap, so you are not registering 40 apps in one week.
What the documents leave open
Google gives the global expansion only as "2027 and beyond." No exact date appears in the pages I read. The set of participating stores is also something to check: Android Authority named Google Play, Samsung Galaxy Store, Xiaomi GetApps, HONOR App Market, OPPO App Market, vivo V-Appstore and Palm Store for the launch regions.
The sources also differ on small dates, such as when limited distribution accounts opened (June or August 2026, depending on the page). Treat the console itself as the final word on what is available to you today.
The practical takeaway: if you are on Play only, spend ten minutes confirming registration. If you distribute anywhere else, start the identity step now, because identity checks are the part that takes calendar time, not engineering time.



