TechBigs
Back to blog
ChecksumAPKSecurity

How to Verify an APK's SHA-256 Checksum on Android and on a Computer

Check an APK's SHA-256 hash with certutil, PowerShell, shasum or sha256sum, or on the phone itself, and learn what a match does and doesn't prove.

TechBigs Editorial Team2026-10-096 min min read

Language versions

A SHA-256 checksum is a 64-character fingerprint of a file. Change a single byte and the fingerprint changes completely. If you compute the hash of the APK you downloaded and it matches the value the source published, you know you hold the same file they hashed.

That is useful for catching truncated downloads, corrupted transfers and swapped files. It also has clear limits, which this guide covers after the step-by-step part.

What you need before you start

  • The file exactly as downloaded. Renaming a file doesn't change its hash. Editing, re-zipping or re-signing it does.
  • The expected SHA-256 value, published by the source of the file, ideally on a page you opened directly over HTTPS.
  • Certainty about which file the value refers to. An .xapk, .apks or .apkm container has a different hash from the .apk files inside it. See APK vs XAPK vs APKS vs APKM explained if you're not sure which one you have.

Whether you got the build from the TechBigs apps or games catalog or anywhere else, the method below is the same.

On Windows: certutil or PowerShell

Using certutil (Command Prompt):

  1. Open the folder that contains the file in File Explorer.
  2. Click the address bar, type cmd and press Enter. A Command Prompt opens in that folder.
  3. Run:
certutil -hashfile "game.apk" SHA256
  1. The output shows a line such as SHA256 hash of game.apk:, then the hash, then a completion message. Older Windows versions print the hash with spaces between byte pairs; remove the spaces before you compare.

Always include SHA256. Without it, certutil defaults to SHA-1.

Using PowerShell:

Get-FileHash .\game.apk -Algorithm SHA256

To let PowerShell do the comparison for you, run:

(Get-FileHash .\game.apk -Algorithm SHA256).Hash -eq "PASTE_EXPECTED_HASH"

It prints True or False. The -eq comparison ignores upper and lower case, so it doesn't matter how the source formatted the letters.

On macOS: shasum

  1. Open Terminal and move to the folder: cd ~/Downloads
  2. Run:
shasum -a 256 game.apk

The output is the hash, two spaces, then the file name. Don't forget -a 256, because without it shasum calculates SHA-1.

For an automatic comparison:

echo "PASTE_EXPECTED_HASH  game.apk" | shasum -a 256 -c

You'll see game.apk: OK or game.apk: FAILED. Note the two spaces between the hash and the file name.

On Linux: sha256sum

sha256sum game.apk

The automatic check works the same way:

echo "PASTE_EXPECTED_HASH  game.apk" | sha256sum -c

If the source provides a .sha256 file that lists the hash and file name, place it next to the APK and run sha256sum -c followed by that file's name.

On the Android phone itself

The standard Files app on Android has no checksum button, so you have three practical routes:

  1. A file manager that shows hashes. Some file managers list MD5, SHA-1 and SHA-256 values in a file's properties or details screen. Make sure you pick SHA-256. A hashing tool only needs access to the file you select, not "All files access". The special permissions guide explains why that distinction matters.
  2. ADB from a computer. If you already use USB debugging, run adb shell sha256sum /sdcard/Download/game.apk. Current Android versions include a sha256sum command in their built-in toolbox. Turn USB debugging off again when you're done.
  3. Copy the file to a computer and use one of the commands above. This is often the simplest option.

Comparing correctly

  • Compare all 64 characters, not just the first and last few. The automatic comparisons above remove the guesswork.
  • Case doesn't matter. A–F and a–f are the same hex digits.
  • Check the length. MD5 is 32 hex characters, SHA-1 is 40 and SHA-256 is 64. If the lengths differ, you are comparing different algorithms.
  • Watch for stray spaces or line breaks picked up when copying the value from a web page.

What a match proves

A matching SHA-256 tells you one thing: the file on your device is bit-for-bit identical to the file the publisher hashed. The download wasn't cut short, the transfer didn't corrupt it, and no mirror, cache or proxy along the way swapped it for something else.

What a match does not prove

  • It doesn't prove the app is harmless. A malicious file has a perfectly valid hash. A checksum identifies a file; it doesn't judge it.
  • It doesn't prove who built the file. If the same page serves both the file and its hash, anyone who controls that page can change both. A checksum protects you most when it comes from a trusted channel separate from the download.
  • It doesn't prove the signing key. Android verifies APK signatures itself. Every APK must be signed, and an update must be signed with the same certificate as the version already installed. Modified builds are re-signed with a different key, which is why they can't install over the official version and why you must uninstall first, losing local data. A matching checksum says nothing about which key signed the file.
  • It doesn't prove the app will run on your phone. CPU architecture and minimum Android version still matter; see how to check your Android version and CPU architecture.

If the hash doesn't match

  1. Make sure you hashed the right file. Look for duplicates such as game (1).apk, or partial downloads ending in .crdownload or .part.
  2. Compare the file size with the size listed by the source.
  3. Confirm the expected value is for the same version and format. An XAPK hash won't match the APK inside it.
  4. Delete the file and download it again over a stable connection.
  5. If it still doesn't match, don't install it. There's no safe way to "repair" a file that differs from the published one.

If the hash matches but installation still fails, the App not installed troubleshooting guide covers signature conflicts, parse errors and storage problems.

Keep the other safety layers on

  • Keep Google Play Protect on and read its warnings. A matching checksum doesn't overrule a Play Protect warning about the app's behavior.
  • Grant "Install unknown apps" only to the browser or file manager you used, and switch it off afterwards.
  • After installing, check what the app asks for. A game requesting accessibility or notification access is a red flag regardless of its checksum.

FAQ

Is an MD5 or SHA-1 checksum good enough? Both still catch accidental corruption, but deliberate collisions are practical for MD5 and have been demonstrated for SHA-1. Prefer SHA-256 when the source offers it.

Does renaming the APK change its checksum? No. The hash covers the file's contents, not its name.

What if the download page shows no checksum at all? Then there's nothing to compare against. Rely on the other layers: keep Play Protect on, review permissions, and be cautious with any app that asks for more than its function needs.

More articles