FAQ
Android keystore generator FAQ
Answers about keystore formats, passwords, validity, Google Play upload keys, and what to do if a key is lost.
What is an Android keystore?
An Android keystore is a password-protected file that holds the private key and certificate used to sign your APK or Android App Bundle. Android and Google Play use that signature to verify that every update comes from the same developer, so the same key must sign all future releases of the app.
How do I generate an Android keystore online without Android Studio?
Fill in your name, email, country code, a key alias, a validity period, and a password in the form above, then select Generate keystore. You get a ready-to-use .p12 keystore, a PEM copy of the certificate, and the SHA-1 and SHA-256 fingerprints. No Android Studio, JDK, or keytool install is needed.
What file format does this Android keystore generator produce?
It produces a PKCS#12 (.p12) keystore with a single RSA 2048-bit signing key and a SHA-256 signed certificate, plus a PEM certificate export. PKCS#12 is the default keystore type since Java 9 and is accepted by Gradle, apksigner, jarsigner, and Google Play. If an older tool needs a JKS file, convert it with keytool -importkeystore.
Is it safe to generate a keystore online? Is my key stored?
The keystore is generated on demand by a stateless Capgo endpoint over HTTPS and returned straight to your browser. Responses are sent with Cache-Control: no-store, and the private key, password, and files are never written to a database or kept after the response. If your security policy requires keys that never leave your machine, use the equivalent keytool command shown on this page.
Can I use this keystore for Google Play releases?
Yes. Use it as the upload key for a new app enrolled in Play App Signing, or as the app signing key for direct APK distribution. Google Play requires the certificate to be valid until at least 22 October 2033, which the default 25-year validity covers.
Should the store password and key password be different?
No. PKCS#12 keystores use one password for the container and the key. In Gradle, the Capacitor CLI, fastlane, or Capgo Cloud Build, enter the same value for both the store password and the key password.
What validity period should I choose?
Keep the default of 25 years. Google recommends at least 25 years, and Google Play rejects uploads signed with a certificate that expires before 22 October 2033. You cannot extend the validity of an existing key later.
What happens if I lose my keystore or password?
If your app uses Play App Signing, you can ask Google to reset the upload key from Play Console by generating a new keystore here and uploading its PEM certificate. Without Play App Signing, a lost key means you cannot publish updates to the same app listing, so back up the file, alias, and password in a secret manager.
Do I need this tool for a debug keystore?
Usually not. The Android SDK creates a debug keystore automatically at ~/.android/debug.keystore with the password android and the alias androiddebugkey. Use this generator for release and upload keys that must stay stable across store releases.
Where do I find the SHA-1 and SHA-256 fingerprints?
They are shown in the result panel right after generation. Register them with Firebase, Google Sign-In, Google Maps, or Android App Links (assetlinks.json). Note that once Play App Signing re-signs your app, Google services also need the app signing key fingerprint from Play Console.
Does it work for Capacitor, Ionic, React Native, and Flutter apps?
Yes. A keystore is framework independent. Any Android build that uses Gradle can sign with it, including Capacitor, Ionic, React Native, Flutter, and native Kotlin or Java projects.