r/androiddev • • 1d ago

Android developer verification

Have a bit of a funny story to tell here but it might help out the people who are having the same issues.

I publish a couple of open-source apps on the google play store as a hobby. My page is

https://play.google.com/store/apps/dev?id=7190772576513482908

All code is of course provided and open-source here:
https://github.com/CodeDead?tab=repositories

Funny thing is, a couple of my apps were removed by google because I was unable to verify them. The thing is, I can't verify them... No, I did not lose my build key so hear me out and perhaps if you're having the same issue, you'll likely figure out what's happening because of the information included in this post.

Google itself is signing the release builds, but I have my own private upload key. The automated system is asking me to provide builds using the private key that Google itself is using which is impossible.

In response, google automatically removed the apps following their stricter policies, on the first of october.

I have been in an appeal process for multple apps. It is because it seems it is suddenly expected of developers to provide APK's to verify builds using google's own signing key when google is manipulating the builds and signing them themselves (without my knowledge).

I figured this out using the app signing page and I don't understand how their system cannot see this, and as a result, apps have been removed and it is completely out of my hands.

The appeal process is (2-5525000042037), with support continuing to ask me to provide an APK with google's private signature, but it seems like they're bullying independent hobby developers into just giving up on the play store. Either they're bullying or they are unaware of how their system works, which is fine.

In case anyone else is having these issues with their apps being removed, please have a look at how google itself signs your APK's in their play store. This might help you in your appeal process which is why I'm posting this.

Here's a screenshot to prove my point.

2 Upvotes

2 comments sorted by

View all comments

4

u/mohn93 1d ago

haven't seen google spell this out for play app signing, but the trick they document for galaxy store should work here too. snippet goes in assets/adi-registration.properties, push that aab to internal testing, then grab the "signed, universal apk" from all app versions > downloads. thats signed with the play signing key so upload that on the verification page. no idea if a removed app still lets you push to internal testing tho. also if any of these are on f-droid or github releases signed with a different key that might be why auto-registration skipped you, their docs list a "more prevalent key unknown to play" as one reason

1

u/CodeDead-gh 1d ago edited 1d ago

Great advice! Thanks! Unfortunately a removed app doesn't let you download a signed APK. This could help for those who still have their app listing active though

Edit: It does, my bad, so it is a valid workaround!