How to Verify an APK's SHA-256 Checksum on Android and on a Computer
Check an APK's SHA-256 hash with certutil, PowerShell, shasum or sha256sum, or on the phone itself, and learn what a match does and doesn't prove.
A SHA-256 checksum is a 64-character fingerprint of a file. Change a single byte and the fingerprint changes completely. If you compute the hash of the APK you downloaded and it matches the value the source published, you know you hold the same file they hashed.
That is useful for catching truncated downloads, corrupted transfers and swapped files. It also has clear limits, which this guide covers after the step-by-step part.
What you need before you start
- The file exactly as downloaded. Renaming a file doesn't change its hash. Editing, re-zipping or re-signing it does.
- The expected SHA-256 value, published by the source of the file, ideally on a page you opened directly over HTTPS.
- Certainty about which file the value refers to. An
.xapk,.apksor.apkmcontainer has a different hash from the.apkfiles inside it. See APK vs XAPK vs APKS vs APKM explained if you're not sure which one you have.
Whether you got the build from the TechBigs apps or games catalog or anywhere else, the method below is the same.
On Windows: certutil or PowerShell
Using certutil (Command Prompt):
- Open the folder that contains the file in File Explorer.
- Click the address bar, type
cmdand press Enter. A Command Prompt opens in that folder. - Run:
certutil -hashfile "game.apk" SHA256
- The output shows a line such as
SHA256 hash of game.apk:, then the hash, then a completion message. Older Windows versions print the hash with spaces between byte pairs; remove the spaces before you compare.
Always include SHA256. Without it, certutil defaults to SHA-1.
Using PowerShell:
Get-FileHash .\game.apk -Algorithm SHA256
To let PowerShell do the comparison for you, run:
(Get-FileHash .\game.apk -Algorithm SHA256).Hash -eq "PASTE_EXPECTED_HASH"
It prints True or False. The -eq comparison ignores upper and lower case, so it doesn't matter how the source formatted the letters.
On macOS: shasum
- Open Terminal and move to the folder:
cd ~/Downloads - Run:
shasum -a 256 game.apk
The output is the hash, two spaces, then the file name. Don't forget -a 256, because without it shasum calculates SHA-1.
For an automatic comparison:
echo "PASTE_EXPECTED_HASH game.apk" | shasum -a 256 -c
You'll see game.apk: OK or game.apk: FAILED. Note the two spaces between the hash and the file name.
On Linux: sha256sum
sha256sum game.apk
The automatic check works the same way:
echo "PASTE_EXPECTED_HASH game.apk" | sha256sum -c
If the source provides a .sha256 file that lists the hash and file name, place it next to the APK and run sha256sum -c followed by that file's name.
On the Android phone itself
The standard Files app on Android has no checksum button, so you have three practical routes:
- A file manager that shows hashes. Some file managers list MD5, SHA-1 and SHA-256 values in a file's properties or details screen. Make sure you pick SHA-256. A hashing tool only needs access to the file you select, not "All files access". The special permissions guide explains why that distinction matters.
- ADB from a computer. If you already use USB debugging, run
adb shell sha256sum /sdcard/Download/game.apk. Current Android versions include asha256sumcommand in their built-in toolbox. Turn USB debugging off again when you're done. - Copy the file to a computer and use one of the commands above. This is often the simplest option.
Comparing correctly
- Compare all 64 characters, not just the first and last few. The automatic comparisons above remove the guesswork.
- Case doesn't matter.
A–Fanda–fare the same hex digits. - Check the length. MD5 is 32 hex characters, SHA-1 is 40 and SHA-256 is 64. If the lengths differ, you are comparing different algorithms.
- Watch for stray spaces or line breaks picked up when copying the value from a web page.
What a match proves
A matching SHA-256 tells you one thing: the file on your device is bit-for-bit identical to the file the publisher hashed. The download wasn't cut short, the transfer didn't corrupt it, and no mirror, cache or proxy along the way swapped it for something else.
What a match does not prove
- It doesn't prove the app is harmless. A malicious file has a perfectly valid hash. A checksum identifies a file; it doesn't judge it.
- It doesn't prove who built the file. If the same page serves both the file and its hash, anyone who controls that page can change both. A checksum protects you most when it comes from a trusted channel separate from the download.
- It doesn't prove the signing key. Android verifies APK signatures itself. Every APK must be signed, and an update must be signed with the same certificate as the version already installed. Modified builds are re-signed with a different key, which is why they can't install over the official version and why you must uninstall first, losing local data. A matching checksum says nothing about which key signed the file.
- It doesn't prove the app will run on your phone. CPU architecture and minimum Android version still matter; see how to check your Android version and CPU architecture.
If the hash doesn't match
- Make sure you hashed the right file. Look for duplicates such as
game (1).apk, or partial downloads ending in.crdownloador.part. - Compare the file size with the size listed by the source.
- Confirm the expected value is for the same version and format. An XAPK hash won't match the APK inside it.
- Delete the file and download it again over a stable connection.
- If it still doesn't match, don't install it. There's no safe way to "repair" a file that differs from the published one.
If the hash matches but installation still fails, the App not installed troubleshooting guide covers signature conflicts, parse errors and storage problems.
Keep the other safety layers on
- Keep Google Play Protect on and read its warnings. A matching checksum doesn't overrule a Play Protect warning about the app's behavior.
- Grant "Install unknown apps" only to the browser or file manager you used, and switch it off afterwards.
- After installing, check what the app asks for. A game requesting accessibility or notification access is a red flag regardless of its checksum.
FAQ
Is an MD5 or SHA-1 checksum good enough? Both still catch accidental corruption, but deliberate collisions are practical for MD5 and have been demonstrated for SHA-1. Prefer SHA-256 when the source offers it.
Does renaming the APK change its checksum? No. The hash covers the file's contents, not its name.
What if the download page shows no checksum at all? Then there's nothing to compare against. Rely on the other layers: keep Play Protect on, review permissions, and be cautious with any app that asks for more than its function needs.