DEV Community

Cover image for Lost your keystore? You can still publish updates on Google Play. Here is how
Emre P.
Emre P.

Posted on

Lost your keystore? You can still publish updates on Google Play. Here is how

You open Android Studio to ship a small fix and the build asks for a keystore you no longer have. Maybe it was on an old laptop. Maybe a freelancer built the app and never handed the key over. Maybe you still have the file but the password is gone.

Whether you can publish updates again depends on one setting you may never have looked at. Here is how to check it, and what to do in each case.

First, the two keys

Google Play apps can have two different keys, and people mix them up all the time.

  • App signing key: the key that signs the APKs your users install. If your app uses Play App Signing, Google keeps this key. You never see it and you can't lose it.
  • Upload key: the key you sign your AAB with before uploading it to Play Console. This is the one that lives in your .jks or .keystore file.

If you are on Play App Signing, what you lost is the upload key. That one can be reset.

Check if you are on Play App Signing

In Play Console, open your app and go to the app signing page. Google moves the menu around, but at the time of writing it is under Protected with Play → Play Store distribution → Manage Play app signing (older layouts: Test and release → App integrity).

If you see "Releases signed by Google Play" or an App signing key certificate managed by Google, you are fine. Every app published for the first time since August 2021 uses Play App Signing, because new apps have to publish as app bundles.

Case 1: Play App Signing is on (most apps)

You are not locked out. You create a new upload key and ask Google to accept it.

1. Create a new upload key on your own computer:

keytool -genkey -v -keystore upload-keystore.jks -keyalg RSA -keysize 2048 -validity 10000 -alias upload
Enter fullscreen mode Exit fullscreen mode

Pick a password you will actually keep, and store the file somewhere that is not your laptop only: a password manager, an encrypted drive, anywhere you'll still have in three years.

2. Export its certificate:

keytool -export -rfc -keystore upload-keystore.jks -alias upload -file upload_certificate.pem
Enter fullscreen mode Exit fullscreen mode

3. Request the reset. On the same app signing page, in the upload key certificate section, choose Request upload key reset, pick a reason, upload upload_certificate.pem and submit.

4. Wait for Google. The account owner gets an email when the request is approved, with the date and time from which the new key works. It usually takes a day or two. Until then, uploads signed with the new key will be rejected, so don't panic if an early try fails.

5. Point your build at the new key. In a Flutter project that usually means updating android/key.properties (storeFile, storePassword, keyAlias, keyPassword). In a native project it's the signingConfigs block in build.gradle. Then build a release AAB and upload it as usual.

That's it. Your users notice nothing: the installs are still signed with Google's app signing key, which never changed.

Forgot the password but still have the file? Same fix. Without the password the file is useless, so treat it as lost and reset.

Case 2: Play App Signing is off and the key is gone

This is the bad one. If you manage the app signing key yourself and lose it, Google can't reset it, and no one else can either. Nobody can "recover" a keystore from your app, whatever a gig title says.

What is left:

  • Search properly before giving up: old laptops, backup drives, CI secrets, the freelancer or agency that built the app, email attachments with .jks or .keystore files.
  • If it's really gone, the app can't be updated. The way forward is to publish it again under a new package name and move your users over with an in-app message or a final update of the old listing if you still can.

A real case

A client of mine hired me for something else, the developer verification check, and mentioned on the side that she didn't have her signing key anymore.

The first thing I checked was the app signing page: "Releases signed by Google Play". So the app was on Play App Signing and a reset was possible. What sounded like "I can never update my app again" turned into a short checklist. With the target API 36 deadline for updates coming on November 1, the reset is the first step, because no update can go out without a working upload key.

Don't lose it again

  • Keep the upload keystore and its password in two places, one of them off your computer.
  • Write down the alias. People keep the file and forget the alias.
  • If someone else builds your app, ask for the upload key and passwords as part of the handover.
  • Never send your keystore or passwords to anyone who offers to "fix it for you". A reset never needs them.

I help small teams and solo developers with Google Play problems like this one. If you'd rather not do the reset on your own, I walk you through it as a fixed-price job, and your key stays on your computer the whole time: my Upwork profile.

Official sources:

Top comments (0)