Scope: This article provides platform and product guidance, not a guarantee of approval or an official Google decision.

Two key roles

With Play App Signing, the key used to sign distributed APKs can be different from the key you use to upload new bundles.

Identify the certificate

Compare SHA-1/SHA-256 fingerprints from your local keystore, Play Console and connected services such as Firebase.

Lost upload key

Supported accounts can use the official upload-key reset process. This is different from changing the app-signing key.

Connected service failures

OAuth, Firebase authentication or API restrictions can fail after release if production certificate fingerprints were not registered.

Protect private keys

Do not email private keys or passwords. Share fingerprints and configuration screenshots first; most diagnosis does not require custody of the key.

Official sources

Policies and platform requirements can change. Check the linked official documentation for the latest wording before acting on a time-sensitive case.

Need case-specific help?

If your situation includes a specific warning, rejection or account state, send the exact notice rather than applying generic steps blindly.

Request assessment