Direct APK install — when the Play Store path is not available.
A direct APK install is the path for readers whose device cannot reach the Play Store, runs a custom ROM or is on a corporate-managed profile. The desk publishes the publisher name, the SHA-256 fingerprint and the install steps; the reader verifies all three before tapping install.
An APK is the Android package format used to install an app outside the Play Store.
APK stands for Android Package Kit. It is the file format Google uses to distribute Android apps through the Play Store, and the format Android accepts for sideloaded installs from outside the Play Store. A sideloaded APK is signed by the same publisher key as the Play Store version; verifying the signature against the publisher's published SHA-256 fingerprint is how the reader confirms the file has not been tampered with between the publisher and the device.
APK stands for Android Package Kit. It is the file format Google uses to distribute Android apps through the Play Store, and the format Android accepts for sideloaded installs from outside the Play Store. A sideloaded APK is signed by the same publisher key as the Play Store version; verifying the signature against the publisher's published SHA-256 fingerprint is how the reader confirms the file has not been tampered with between the publisher and the device.
Some readers need the APK when the Play Store is unavailable or restricted on the device.
A direct APK path is useful when the reader's device is on a corporate-managed profile that blocks Play Store access, when the device runs a custom ROM without Play Services, when the reader wants to install the app on a tablet that does not ship with the Play Store, or when the reader is testing the install on a secondary device before committing the primary device to the install. The desk publishes the APK path for these use cases, not as a workaround for a Play Store ban.
A direct APK path is useful when the reader's device is on a corporate-managed profile that blocks Play Store access, when the device runs a custom ROM without Play Services, when the reader wants to install the app on a tablet that does not ship with the Play Store, or when the reader is testing the install on a secondary device before committing the primary device to the install. The desk publishes the APK path for these use cases, not as a workaround for a Play Store ban.
Three checks before the reader taps install on a sideloaded APK.
First, confirm the publisher name on the file matches the publisher name published on the about page — a different name on the install prompt means the file is from a different publisher. Second, compare the SHA-256 fingerprint of the downloaded file against the fingerprint on the about page; a mismatch means the file was modified in transit. Third, read the permissions list on the install prompt; a legitimate install lists the permissions the app needs (storage, network) and nothing else.
First, confirm the publisher name on the file matches the publisher name published on the about page — a different name on the install prompt means the file is from a different publisher. Second, compare the SHA-256 fingerprint of the downloaded file against the fingerprint on the about page; a mismatch means the file was modified in transit. Third, read the permissions list on the install prompt; a legitimate install lists the permissions the app needs (storage, network) and nothing else.
Allow the source, open the file, tap install, verify the publisher.
On Android 8 and above, open Settings → Apps → Special app access → Install unknown apps. Pick the browser or file manager the reader will use to open the APK and toggle 'Allow from this source' on. Open the downloaded APK, review the install prompt and tap Install. After install, the publisher name on the app info screen must match the publisher name on the about page. If the publisher name does not match, uninstall the file and report the mismatch to the customer-care desk.
On Android 8 and above, open Settings → Apps → Special app access → Install unknown apps. Pick the browser or file manager the reader will use to open the APK and toggle 'Allow from this source' on. Open the downloaded APK, review the install prompt and tap Install. After install, the publisher name on the app info screen must match the publisher name on the about page. If the publisher name does not match, uninstall the file and report the mismatch to the customer-care desk.
If the reader is not sure, install from the Play Store.
The Play Store path is the safer install path for most readers. The Play Store enforces publisher identity, scans for known malware and ties the install to the reader's Google account. The desk recommends the Play Store path unless the reader has a specific need the Play Store path does not cover. Sideloading from a third-party mirror the desk does not list on this page is out of scope; the desk does not vouch for files the desk did not publish.
The Play Store path is the safer install path for most readers. The Play Store enforces publisher identity, scans for known malware and ties the install to the reader's Google account. The desk recommends the Play Store path unless the reader has a specific need the Play Store path does not cover. Sideloading from a third-party mirror the desk does not list on this page is out of scope; the desk does not vouch for files the desk did not publish.
Common questions about the direct APK install.
Where does the APK file live on the device?
By default, Android places downloaded files in the Downloads folder. The reader can move the file to any folder; the install path is the same.
How do I verify the publisher?
Open Settings → Apps → pick the app → App details. The publisher name on the device must match the publisher name on the about page. A mismatch means the file is from a different publisher and should be uninstalled.
Can the APK update itself?
No. A sideloaded APK does not auto-update from the Play Store. The reader must re-download and reinstall the file when the publisher publishes a new version. The desk lists the current version stamp on this page.
Does sideloading void warranty?
No. Sideloading does not void the device warranty. However, sideloaded apps run at the reader's risk; the publisher's support covers the Play Store path, not the sideload path.
Companion install and reader pages.
The companion pages for the install path.
Download
The full read on bookmark, home-screen shortcut and pinned-tab install paths across Android, iOS and desktop.
App access
The mobile reading surface, the chapters that travel well on a phone and the chapters that read better on desktop.
About the desk
The publisher name, the SHA-256 fingerprint reference and the verification stamp.
Customer care
How to file a publisher-name mismatch, a hash mismatch or a permissions anomaly with the desk.