Sitelet https://capgo.app/tools/android-keystore-generator/
Skip to main content

Android signing

Android Keystore Generator

Generate an Android keystore online in seconds, without Android Studio or keytool. Get a PKCS#12 release keystore, the PEM certificate, and the SHA-1 and SHA-256 fingerprints, ready for Gradle, Capacitor, fastlane, CI, and Google Play.

Container

PKCS#12

Key

RSA 2048, SHA-256

Fingerprints

SHA-1 and SHA-256

Release checklist

  1. 1. Choose the alias and password that will stay with this app over time.
  2. 2. Download the keystore and save the metadata in your secret manager.
  3. 3. Configure the same alias and password in Gradle or your CI environment.
  4. 4. Keep the upload key stable so future Play releases do not break.

Input

Keystore details

Fill in the subject information that should be embedded in the signing certificate and pick a stable alias.

Output

Generated Android signing bundle

After generation you will get a downloadable keystore plus the certificate export and fingerprints needed for store setup or OAuth integrations.

Generate the signing bundle to display the alias, fingerprints, and file downloads here.

Basics

What is an Android keystore?

An Android keystore is a password-protected file that contains the private key and certificate used to sign your app. Every APK and Android App Bundle must be signed before it can be installed or published, and Android only accepts an update when it is signed with the same key as the version already installed.

That makes the keystore one of the most important files in your project. With Play App Signing it acts as your upload key, which Google checks before re-signing your app. Without Play App Signing it is the app signing key itself, and losing it means you can no longer update the app.

This generator creates a PKCS#12 (.p12) keystore with an RSA 2048-bit key and a SHA-256 certificate, the same output as keytool and the Android Studio signing wizard, with a 25-year default validity that meets Google Play requirements.

Security and privacy

How your keystore is generated

  • The keystore is created on demand by a stateless Capgo endpoint over HTTPS and returned directly to your browser as a download.
  • Responses are sent with Cache-Control: no-store. The private key, password, and files are never saved to a database or kept after the response.
  • The keystore is protected with your password using AES-256 encryption inside the PKCS#12 container.
  • No account or sign-up is required, and requests are rate limited to prevent abuse.

Need a key that never leaves your machine? Run the equivalent keytool command locally. It produces the same kind of keystore.

Equivalent keytool command
keytool -genkeypair -v \
  -storetype PKCS12 \
  -keystore release.p12 \
  -alias release \
  -keyalg RSA -keysize 2048 \
  -validity 9125 \
  -dname "CN=Jane Doe, O=Acme Mobile, C=DE"

Step by step

How to generate an Android keystore online

From an empty form to a signed release on Google Play in six steps. The first three take less than a minute.

  1. Step 1

    Enter the certificate details

    Add your full name, email, and two-letter country code. Organization, unit, city, and state are optional and only appear in the certificate subject.

  2. Step 2

    Choose an alias, validity, and password

    Pick a simple alias such as release or upload, keep the 25-year validity, and set a strong password of at least 8 characters. Write all three down before you continue.

  3. Step 3

    Generate and download the keystore

    Select Generate keystore, then download the .p12 keystore and the PEM certificate. Copy the SHA-1 and SHA-256 fingerprints from the result panel.

  4. Step 4

    Back up the keystore and credentials

    Store the keystore file, alias, and password together in a password manager or secret manager. Never commit the keystore to Git.

  5. Step 5

    Configure signing in your build

    Point Gradle, the Capacitor CLI, fastlane, or Capgo Cloud Build at the keystore with the alias and password, then build a signed release AAB or APK.

  6. Step 6

    Upload the signed app to Google Play

    Upload the signed Android App Bundle in Play Console. With Play App Signing, this keystore becomes your upload key and Google manages the final app signing key.

Use the output

Sign your Android app with the generated keystore

Replace the alias and password with the values you entered above. Because the keystore is PKCS#12, the key password is the same as the store password.

Gradle signing config

Works for Capacitor, Ionic, React Native, Flutter, and native projects. Keep passwords in gradle.properties or environment variables.

android/app/build.gradle
// android/app/build.gradle
android {
    signingConfigs {
        release {
            storeFile file(RELEASE_STORE_FILE)
            storePassword RELEASE_STORE_PASSWORD
            keyAlias RELEASE_KEY_ALIAS
            keyPassword RELEASE_STORE_PASSWORD
            storeType "pkcs12"
        }
    }
    buildTypes {
        release {
            signingConfig signingConfigs.release
        }
    }
}

# ~/.gradle/gradle.properties (keep out of Git)
RELEASE_STORE_FILE=/path/to/release.p12
RELEASE_STORE_PASSWORD=your-password
RELEASE_KEY_ALIAS=release

Capacitor CLI

Build a signed Android App Bundle for a Capacitor app in one command.

Capacitor signed build
bunx cap build android \
  --keystorepath ./release.p12 \
  --keystorepass "your-password" \
  --keystorealias release \
  --keystorealiaspass "your-password" \
  --androidreleasetype AAB

Capgo Cloud Build

Save the keystore once and let Capgo Cloud Build sign and upload every release.

Capgo CLI
bunx @capgo/cli@latest build credentials save \
  --platform android \
  --keystore ./release.p12 \
  --keystore-alias release \
  --keystore-key-password "your-password" \
  --keystore-store-password "your-password"

fastlane

Inject signing properties into the Gradle action from CI secrets.

Fastfile
gradle(
  task: "bundle",
  build_type: "Release",
  properties: {
    "android.injected.signing.store.file" => ENV["RELEASE_STORE_FILE"],
    "android.injected.signing.store.password" => ENV["RELEASE_STORE_PASSWORD"],
    "android.injected.signing.key.alias" => ENV["RELEASE_KEY_ALIAS"],
    "android.injected.signing.key.password" => ENV["RELEASE_STORE_PASSWORD"],
  }
)

Verify, convert, and store in CI

Check the alias and fingerprints, convert to JKS for legacy tools, or encode the file for a CI secret.

keytool and base64
# Inspect the keystore, alias, and fingerprints
keytool -list -v -keystore release.p12 -storetype PKCS12

# Convert to JKS if an older tool requires it
keytool -importkeystore \
  -srckeystore release.p12 -srcstoretype PKCS12 \
  -destkeystore release.jks -deststoretype JKS

# Base64-encode the keystore for a CI secret
base64 -i release.p12 | tr -d '\n' > release.p12.base64

Troubleshooting

Common Android keystore errors and fixes

Keystore was tampered with, or password was incorrect
The store password is wrong. Copy it again from your password manager and check for trailing spaces in CI secrets.
No key with alias 'release' found in keystore
The alias does not match. Run keytool -list on the keystore to see the exact alias, which is case sensitive.
Given final block not properly padded
The key password is wrong. With PKCS#12 keystores, the key password must equal the store password.
Invalid keystore format
An older Java 8 toolchain is reading a PKCS#12 file as JKS. Set storeType "pkcs12" in Gradle or convert the file to JKS with keytool -importkeystore.
Your Android App Bundle is signed with the wrong key
Google Play expects the original upload key. Sign with that key, or request an upload key reset in Play Console using the PEM certificate from a new keystore.
Google Sign-In or Firebase Auth fails only in release builds
Add the release SHA-1 and SHA-256 fingerprints to Firebase, and also the Play App Signing key fingerprints from Play Console.

FAQ

Android keystore generator FAQ

Answers about keystore formats, passwords, validity, Google Play upload keys, and what to do if a key is lost.

What is an Android keystore?

An Android keystore is a password-protected file that holds the private key and certificate used to sign your APK or Android App Bundle. Android and Google Play use that signature to verify that every update comes from the same developer, so the same key must sign all future releases of the app.

How do I generate an Android keystore online without Android Studio?

Fill in your name, email, country code, a key alias, a validity period, and a password in the form above, then select Generate keystore. You get a ready-to-use .p12 keystore, a PEM copy of the certificate, and the SHA-1 and SHA-256 fingerprints. No Android Studio, JDK, or keytool install is needed.

What file format does this Android keystore generator produce?

It produces a PKCS#12 (.p12) keystore with a single RSA 2048-bit signing key and a SHA-256 signed certificate, plus a PEM certificate export. PKCS#12 is the default keystore type since Java 9 and is accepted by Gradle, apksigner, jarsigner, and Google Play. If an older tool needs a JKS file, convert it with keytool -importkeystore.

Is it safe to generate a keystore online? Is my key stored?

The keystore is generated on demand by a stateless Capgo endpoint over HTTPS and returned straight to your browser. Responses are sent with Cache-Control: no-store, and the private key, password, and files are never written to a database or kept after the response. If your security policy requires keys that never leave your machine, use the equivalent keytool command shown on this page.

Can I use this keystore for Google Play releases?

Yes. Use it as the upload key for a new app enrolled in Play App Signing, or as the app signing key for direct APK distribution. Google Play requires the certificate to be valid until at least 22 October 2033, which the default 25-year validity covers.

Should the store password and key password be different?

No. PKCS#12 keystores use one password for the container and the key. In Gradle, the Capacitor CLI, fastlane, or Capgo Cloud Build, enter the same value for both the store password and the key password.

What validity period should I choose?

Keep the default of 25 years. Google recommends at least 25 years, and Google Play rejects uploads signed with a certificate that expires before 22 October 2033. You cannot extend the validity of an existing key later.

What happens if I lose my keystore or password?

If your app uses Play App Signing, you can ask Google to reset the upload key from Play Console by generating a new keystore here and uploading its PEM certificate. Without Play App Signing, a lost key means you cannot publish updates to the same app listing, so back up the file, alias, and password in a secret manager.

Do I need this tool for a debug keystore?

Usually not. The Android SDK creates a debug keystore automatically at ~/.android/debug.keystore with the password android and the alias androiddebugkey. Use this generator for release and upload keys that must stay stable across store releases.

Where do I find the SHA-1 and SHA-256 fingerprints?

They are shown in the result panel right after generation. Register them with Firebase, Google Sign-In, Google Maps, or Android App Links (assetlinks.json). Note that once Play App Signing re-signs your app, Google services also need the app signing key fingerprint from Play Console.

Does it work for Capacitor, Ionic, React Native, and Flutter apps?

Yes. A keystore is framework independent. Any Android build that uses Gradle can sign with it, including Capacitor, Ionic, React Native, Flutter, and native Kotlin or Java projects.