Android signing & keystores
A Production build must be signed with your upload keystore. You upload it once and BuildStack seals it, encrypted at rest, opened only for the moment a build needs it, never returned to the dashboard or logs.
When you need a keystore
- Development and Preview builds don't need one. Preview is an installable
release APK that's debug-signed by the template, so it runs standalone on any device, ideal for scan-to-install testing.
- Production (signed release AAB/APK, and anything you publish to Google Play)
requires your keystore.
Upload your keystore
- Open the project → Credentials → Signing keystore.
- Upload the
.jks/.keystorefile and enter the key alias, store password, and
key password.
- Save. The panel then shows "A keystore is set (alias …)", and that status line
is how you confirm it's stored (the form fields clear on reload by design; they never re-display your file or passwords). Upload again to replace it.
Release builds are then signed with it automatically, including Expo projects, where expo prebuild regenerates the native project on every build (BuildStack re-applies your release signing after prebuild, so the AAB is signed with your upload key, not the debug key).
Match what Play expects. If your app is already on Google Play, sign with the same upload key you used before, or enrol in Play App Signing; otherwise Google rejects the upload with "signed with the wrong key." You can verify a keystore's certificate with keytool -list -v -keystore your.jks.
>
Keep a backup of your keystore. If you lose your upload key you must request an upload-key reset from Google.
How sealing works
Credentials are encrypted with an envelope key held in a hardware-backed key vault. The plaintext keystore exists only in memory, only during a build.
Debug signing
Development builds (and Preview) are signed with the standard debug key automatically, no setup needed. Only Production uses your keystore.