Noticia
Android Developer Verification Sets a September Deadline for Four Countries
Google’s Android developer verification rollout will begin affecting app installations in four countries on September 30, while preserving sideloading options for power users.

Google is moving closer to the first user-facing stage of Android developer verification, a security program designed to make app distribution more accountable without removing Android’s sideloading flexibility. The company says new protections will begin on September 30, 2026, for certified Android devices in Brazil, Indonesia, Singapore and Thailand.
The deadline is approaching as Google continues to roll out registration tools for developers. In a July 15 update attached to its Android Developers Blog announcement, Google said that more than 99% of apps on Google Play had already been registered automatically. Developers are still being asked to check Play Console and register any remaining apps before the September deadline.
What changes on September 30
Android developer verification links an app package to a verified developer. For the first phase, Google says app installations will be checked across seven participating stores: Google Play, HONOR App Market, OPPO App Market, Palm Store, Galaxy Store, vivo’s V-Appstore and Xiaomi’s GetApps.
The initial rollout is limited to four countries, but Google describes it as the start of a wider expansion. The company says the protections will extend globally to apps installed on certified Android devices in 2027, after feedback from users, developers and distribution partners.
For most people, Google expects the normal download experience to remain unchanged. The main difference appears when a user tries to install an app that has not been registered by a verified developer. Google says those installations can still proceed through Android Debug Bridge, known as ADB, or through a new advanced flow intended for experienced users.
Why Google is introducing the system
Google presents developer verification as an additional layer of accountability against malicious actors who repeatedly distribute harmful apps under anonymous or changing identities. In its March rollout announcement, the company said its analysis found more than 90 times more malware from sideloaded sources than on Google Play. That figure is Google’s own analysis, not an independent performance test, but it explains the security problem the company is targeting.
The change focuses on who published an app and whether its package has been registered. It does not mean that every app distributed outside Google Play will suddenly become a Play-reviewed app. Users will still need to consider the app’s permissions, source, update path and reputation before installing it.
Sideloading remains available, with more friction
Google says power users will retain the ability to install software from unverified developers. The advanced flow is intended to make that choice harder to trigger accidentally or under pressure from a scammer. The company says the process will include security checkpoints while still allowing users to proceed when they understand the risks.
This balance is central to Google’s messaging. Android is not closing the door on alternative app stores, testing builds or software shared directly by developers. Instead, the platform is adding a stronger distinction between registered apps and installations that require an informed override.
That distinction may matter most for developers distributing beta software, open-source projects or specialized tools outside mainstream stores. A sideloaded application will not necessarily be blocked forever, but the person installing it may have to complete additional steps. For ordinary users, those interruptions could also act as a warning that an app comes from a source Android cannot verify.
New accounts and developer APIs
Google is also trying to reduce the administrative burden of registration. Its published timeline says the Android Developer ID Status API will allow developers to check whether a package name has already been registered. The Android Developer Console API is intended to support registration and package management from development environments and continuous integration pipelines.
Both APIs are designed to support OAuth delegation, which means an app store or another authorized platform can perform registration tasks on a developer’s behalf. Google says the new Android Developer Console API will launch globally in August.
Students, hobbyists and learners are being offered a separate path. Limited distribution accounts are designed to let them share apps with up to 20 devices without a government-issued ID or a registration fee. Google’s timeline lists the global launch of those accounts in August, alongside the advanced flow for power users.
What developers should check now
Developers distributing through Google Play should open Play Console and confirm that every app they intend to keep distributing is registered. Google says most Play apps were handled automatically, but the remaining packages still need attention. Developers distributing only through other stores or direct downloads should use the Android Developer Console and review the official registration guidance.
The practical message is straightforward: Android remains open to multiple distribution channels, but verified identity and package registration are becoming part of the platform’s baseline for certified devices. The first enforcement date is September 30 in four countries, with a broader global rollout planned for 2027. Developers have time to prepare, but the deadline is close enough that registration status should no longer be treated as a future-only concern.