Live desk
T20India vs Australia · Hyderabad · 19:00 IST ODISouth Africa vs England · Cape Town · 13:30 IST T10Abu Dhabi league · Match 14 · 22:00 IST TestEngland vs New Zealand · Day 3 · Lord's · 15:00 IST T20West Indies vs Pakistan · Guyana · 03:30 IST FootballPremier League GW3 · Sunday slate · 19:30 IST KabaddiPKL Match 18 · Bengaluru · 20:00 IST
Source: ICC/BCCI/IPL feed · Last update 14 Aug 2026, 18:42 IST
Direct APK install

Direct APK install — when the Play Store path is not available.

A direct APK install is the path for readers whose device cannot reach the Play Store, runs a custom ROM or is on a corporate-managed profile. The desk publishes the publisher name, the SHA-256 fingerprint and the install steps; the reader verifies all three before tapping install.

Editorial desk Last review 14 Aug 2026 Verified sources
APK install An overhead view of an Android phone showing the Install unknown apps prompt with the publisher name and the SHA-256 fingerprint
Hub · APK install
Direct APK install — when the Play Store path is not available.
01What an APK is

An APK is the Android package format used to install an app outside the Play Store.

APK stands for Android Package Kit. It is the file format Google uses to distribute Android apps through the Play Store, and the format Android accepts for sideloaded installs from outside the Play Store. A sideloaded APK is signed by the same publisher key as the Play Store version; verifying the signature against the publisher's published SHA-256 fingerprint is how the reader confirms the file has not been tampered with between the publisher and the device.

An overhead view of an Android phone showing the 'Install unknown app' prompt with the publisher name and the SHA-256 fingerprint

APK stands for Android Package Kit. It is the file format Google uses to distribute Android apps through the Play Store, and the format Android accepts for sideloaded installs from outside the Play Store. A sideloaded APK is signed by the same publisher key as the Play Store version; verifying the signature against the publisher's published SHA-256 fingerprint is how the reader confirms the file has not been tampered with between the publisher and the device.

02Why a direct APK path

Some readers need the APK when the Play Store is unavailable or restricted on the device.

A direct APK path is useful when the reader's device is on a corporate-managed profile that blocks Play Store access, when the device runs a custom ROM without Play Services, when the reader wants to install the app on a tablet that does not ship with the Play Store, or when the reader is testing the install on a secondary device before committing the primary device to the install. The desk publishes the APK path for these use cases, not as a workaround for a Play Store ban.

A smartphone on a wooden countertop next to a printed APK download checklist with the publisher's SHA-256 fingerprint circled

A direct APK path is useful when the reader's device is on a corporate-managed profile that blocks Play Store access, when the device runs a custom ROM without Play Services, when the reader wants to install the app on a tablet that does not ship with the Play Store, or when the reader is testing the install on a secondary device before committing the primary device to the install. The desk publishes the APK path for these use cases, not as a workaround for a Play Store ban.

03Before you install

Three checks before the reader taps install on a sideloaded APK.

First, confirm the publisher name on the file matches the publisher name published on the about page — a different name on the install prompt means the file is from a different publisher. Second, compare the SHA-256 fingerprint of the downloaded file against the fingerprint on the about page; a mismatch means the file was modified in transit. Third, read the permissions list on the install prompt; a legitimate install lists the permissions the app needs (storage, network) and nothing else.

First, confirm the publisher name on the file matches the publisher name published on the about page — a different name on the install prompt means the file is from a different publisher. Second, compare the SHA-256 fingerprint of the downloaded file against the fingerprint on the about page; a mismatch means the file was modified in transit. Third, read the permissions list on the install prompt; a legitimate install lists the permissions the app needs (storage, network) and nothing else.

04Install steps

Allow the source, open the file, tap install, verify the publisher.

On Android 8 and above, open Settings → Apps → Special app access → Install unknown apps. Pick the browser or file manager the reader will use to open the APK and toggle 'Allow from this source' on. Open the downloaded APK, review the install prompt and tap Install. After install, the publisher name on the app info screen must match the publisher name on the about page. If the publisher name does not match, uninstall the file and report the mismatch to the customer-care desk.

An Android phone showing the Install unknown apps toggle list with the browser entry highlighted and the publisher fingerprint overlaid

On Android 8 and above, open Settings → Apps → Special app access → Install unknown apps. Pick the browser or file manager the reader will use to open the APK and toggle 'Allow from this source' on. Open the downloaded APK, review the install prompt and tap Install. After install, the publisher name on the app info screen must match the publisher name on the about page. If the publisher name does not match, uninstall the file and report the mismatch to the customer-care desk.

05When NOT to sideload

If the reader is not sure, install from the Play Store.

The Play Store path is the safer install path for most readers. The Play Store enforces publisher identity, scans for known malware and ties the install to the reader's Google account. The desk recommends the Play Store path unless the reader has a specific need the Play Store path does not cover. Sideloading from a third-party mirror the desk does not list on this page is out of scope; the desk does not vouch for files the desk did not publish.

A wide welcome-page card listing the APK path versus the Play Store path with the publisher name and the install fingerprint on each row

The Play Store path is the safer install path for most readers. The Play Store enforces publisher identity, scans for known malware and ties the install to the reader's Google account. The desk recommends the Play Store path unless the reader has a specific need the Play Store path does not cover. Sideloading from a third-party mirror the desk does not list on this page is out of scope; the desk does not vouch for files the desk did not publish.

FAQAPK questions

Common questions about the direct APK install.

Where does the APK file live on the device?

By default, Android places downloaded files in the Downloads folder. The reader can move the file to any folder; the install path is the same.

How do I verify the publisher?

Open Settings → Apps → pick the app → App details. The publisher name on the device must match the publisher name on the about page. A mismatch means the file is from a different publisher and should be uninstalled.

Can the APK update itself?

No. A sideloaded APK does not auto-update from the Play Store. The reader must re-download and reinstall the file when the publisher publishes a new version. The desk lists the current version stamp on this page.

Does sideloading void warranty?

No. Sideloading does not void the device warranty. However, sideloaded apps run at the reader's risk; the publisher's support covers the Play Store path, not the sideload path.

Desk pickTonight's captain ledger
Read picks