APK checker: what this one does and does not check
An APK checker can mean several things. This one compares a file with the fingerprint its publisher printed, on your own phone.
Searching for an APK checker turns up tools that do different jobs under one name. The one on this page compares a file with a fingerprint and nothing more, and nothing leaves your phone while it does. Use it for the question “is this the file that was published?”, not for “is this app harmless?”.
In the example, the publisher’s value was printed with capital letters, colons and a SHA256 label. The checker ignores all of that, so the result for app-file-example.apk is Matches. A pasted value only needs to hold the 64 characters.
This site hosts no app files and cannot say which file is the right one.
Common questions
Does this checker scan an APK for viruses?
No. It works out the file’s SHA-256 fingerprint and compares it with the value you paste. It does not open the app, read its permissions or look for malware, and it says so rather than implying a scan.
Does the way the fingerprint is written matter?
No. Capital or small letters, spaces, colons, dashes and a leading SHA256 label are all ignored. What matters is that the 64 characters 0 to 9 and a to f are all there and in order.
What does a matching fingerprint prove?
Only that your file is identical to the one the fingerprint was printed for. It says nothing about who made it, what the app does once it runs, or whether it is the newest version.
Where should the publisher’s fingerprint come from?
From a second place, not the page or chat that gave you the file. If one source hands you both, whoever swapped the file could have swapped the number too, and a match shows only that the download arrived whole.
Does the file I choose leave my phone?
No. Your browser reads the file on your own device and works out the fingerprint there. Nothing is sent to this site or anywhere else, and nothing is stored.