How to Keep Sideloaded Android Apps Updated
Why an APK update installs or fails, and four ways to keep sideloaded apps updated: a store app, Obtainium, the app’s own update check, or by hand.
Short answer: an update installs over an app only if it is signed with the same certificate as the installed copy (or with a newer key the developer has formally linked to it) and its version code isn’t lower. So the simplest way to keep a sideloaded app updated is to stick with one source for it and take every update from that source, by hand or with an app that does it for you.
The two rules Android checks
- Same signing certificate. Android’s documentation: “When the system is installing an update to an app, it compares the certificate(s) in the new version with those in the existing version. The system allows the update if the certificates match.” A copy signed by someone else won’t install over yours; see “App not installed as package conflicts” for what that error looks like and the other things that cause it. The exception is key rotation. Since Android 9, a developer who moves to a new signing key can include a “proof-of-rotation” record (part of APK Signature Scheme v3) that Android verifies, and an update signed with the new key then installs over copies signed with the old one. Android’s documentation doesn’t recommend relying on rotation for Android 12 and earlier.
- A version code that isn’t lower. Every APK carries a version code, a whole number, and each new release normally has a higher one. Android uses it “to protect against downgrades by preventing users from installing an APK with a lower versionCode than the version currently installed”. You can’t go back to an older version without uninstalling first.
Why the same app can have several signatures
The same version of an app can be signed with different keys depending on where it comes from:
- F-Droid usually builds apps from source and signs them with its own key. For some apps it can instead publish the developer’s own signed APK, but only after checking that it matches the build made from F-Droid’s recipe.
- IzzyOnDroid says its apps “are official binaries built and signed by the original application developers”.
- GitHub releases are signed with whatever key the developer uses.
- Google Play may use yet another key, and from outside you usually can’t check which one.
So an app you installed from F-Droid’s own build won’t take an update from the developer’s GitHub page, and the other way round, even if the version is newer. Every app page on this site says which key signed the file and whether it is F-Droid’s build or the developer’s.
Four ways to get updates
- A store app for the repository. If you installed from F-Droid or IzzyOnDroid, a client for those repositories checks for updates for you: F-Droid’s own app, Droid-ify or Neo Store. They can only install updates signed with the same key as the copy you have.
- Obtainium, which promises to “get Android app updates straight from the source”: you add each app’s release page, such as GitHub, GitLab or Codeberg, and it tells you about and installs new releases. Good for apps that publish only on GitHub.
- The app’s own update check. Some apps look for new releases themselves and open the download page when there is one. Many leave this off, or switch it off when a store installed them.
- By hand. Download the newer APK from the same page you got the first one from, and install it over the old one.
Obtainium alternatives compared covers more tools of this kind.
Updates without a prompt
Normally Android asks you to confirm each install. Since Android 12, an installer app can update an app without asking only when all of these are true, per Android’s documentation:
- It asks for no confirmation and declares a special permission for this (
UPDATE_PACKAGES_WITHOUT_USER_ACTION). - It is the app’s installer of record, or its update owner where update ownership is enforced (Android 14 added this), which in practice means the app that installed it; or the installer app is updating itself.
- The app being updated targets a recent enough Android version; the bar rises with each Android release.
Even then, the documentation tells installer apps to be ready for Android to ask for confirmation anyway.
That is why an app you installed from a browser usually still asks for confirmation when a store app updates it: the store app didn’t install it. Some store apps, Droid-ify and Neo Store among them, can also install through root or Shizuku to skip the prompts.
Switching to another source
When the source you want uses a different key that isn’t a rotation of yours, the only way is to uninstall and install again, and uninstalling deletes the app’s data. Before you do it:
- Use the app’s own backup or export option if it has one (many have one under Settings).
- With root, Neo Backup can back up an app’s data and restore it later.
- After switching, take every update from the new source.
On this site
Each file here comes from one source per app, and new releases replace it after the same checks, so updating from the same page normally keeps the same signature. If a developer switches to a new signing key without Android’s key rotation, updates signed with it won’t install over your copy, from this site or anywhere else, until you uninstall the old one. We host only regular releases, never beta builds (with the rare exceptions the app pages explain).
Apps in this guide
-
Obtainium Installs and updates Android apps straight from where developers publish them, such as GitHub releases, and tells you when a new version is out.Download -
Droid-ify A tidier way to use F-Droid: browse and install from F-Droid, IzzyOnDroid and your own repositories, keep apps updated in the background, and install without prompts through Shizuku or root.Download -
Neo Store An alternative app for browsing and installing open-source apps from F-Droid, IzzyOnDroid and other repositories, with filters, download statistics and silent updates through root or Shizuku.Download -
Neo Backup Back up your apps together with their data on a rooted phone, and put them back later or on a fresh install: one app at a time, in batches or on schedules, encrypted if you want.Download
Sources
- Sign your app: signing considerations (Android Developers) checked Oct 5, 2026
- Version your app (Android Developers) checked Oct 5, 2026
- PackageInstaller.SessionParams: setRequireUserAction (Android Developers) checked Oct 5, 2026
- Reproducible Builds: publishing APKs with the upstream developer’s signature (F-Droid) checked Oct 5, 2026
- IzzyOnDroid repository README checked Oct 5, 2026
- Obtainium README checked Oct 5, 2026
- APK Signature Scheme v3: key rotation (Android Open Source Project) checked Oct 5, 2026
- SigningInfo.hasPastSigningCertificates (Android Developers) checked Oct 5, 2026