Publishing guide
Updated Oct 10, 2026 · 19 min read
Forgot Your Unity Keystore Password? How to Reset Your Google Play Upload Key
Can’t sign your Unity build for Google Play anymore? Check whether the key is recoverable, create and store a new upload key, request an upload key reset in Play Console, and ship the next update.
You open Unity to ship an update, Player Settings asks for the keystore password, and nothing you type works. Or the .jks file left with an old laptop. Either way you can’t sign a build Google Play will accept, and for a moment it looks like your game can never be updated again.
For almost every game on Google Play, that isn’t true. If your app uses Play App Signing — every app created since August 2021 does — the key you’ve lost is only your upload key, and Google can register a new one. This guide walks through the whole job: working out which situation you’re in, trying to recover the password, creating and storing a new upload key, requesting the reset in Play Console, and signing your next Unity build with it.
How Play signing works
Under Play App Signing, two different keys sign your game, and only one of them is yours. Your upload key lives in the keystore Unity signs with, and Google uses it only to confirm that a bundle really came from you. Google then signs the APKs it delivers to players with the app signing key, which Google keeps and you can’t download.
- 1You sign the bundle with your upload keyUnity builds the .aab and signs it with the keystore on your machine.
- 2Play Console checks the upload certificateThis only proves the bundle came from you. It’s the key Google can reset.
- 3Google Play re-signs with the app signing keyGoogle holds this key and you can’t download it. A reset doesn’t touch it.
- 4Players install and updateDevices only see the app signing key, so updates keep working after a reset.
That split is what makes a lost upload key recoverable. Google can register a new upload key for your app, and because the app signing key stays the same, players receive your next release as a normal update — same app, same reviews, same save data.
| Upload key | Held by you in a Java keystore (.jks or .keystore). Signs the bundle you upload. Google can reset it if it’s lost or compromised. |
|---|---|
| App signing key | Held by Google. Signs the APKs delivered to devices. You can’t download a copy, and an upload key reset doesn’t change it. |
| Your first upload | When Google generates the app signing key (the default), the key you sign your first release with becomes your upload key. |
| Apps created since August 2021 | Must publish with Android App Bundles (.aab), and app bundles require Play App Signing. |
| Older apps that upload self-signed APKs | Can still manage their own signing key. If that key is lost, Google can’t reset it. |
Find your situation
Work out exactly what’s missing before you change anything. Some of these situations take five minutes to fix, most end in an upload key reset, and one can’t be fixed at all.
- You have the file but forgot the keystore password. Try to recover it first (next section). If it’s really gone, request an upload key reset.
- You know the keystore password but not the key password. Try the keystore password as the key password. Keystores made with recent keytool versions can’t have a separate one. If that fails, reset.
- You forgot the alias. That’s not a lost key.
keytool -listshows the alias names even without the password. - The keystore file is gone. Nothing to recover. Request an upload key reset.
- The key leaked. Committed to a public repository, shared in a chat, on a stolen laptop: treat it as compromised and request a reset the same way.
- No build was ever uploaded for this app. There’s nothing to reset. Create a new keystore; the first bundle you upload (on any track) sets the upload key.
- The app isn’t on Play App Signing and you lost its signing key. This is the one case with no fix. See the rule below.
The spec sheet
These are the hard requirements you’ll meet during a reset. Everything else in this guide is how to get there.
| Key type | RSA, 2,048 bits or more |
|---|---|
| Keystore format | Java keystore, .jks or .keystore |
| Key validity | Google recommends at least 25 years; Google Play requires a validity period ending after 22 October 2033 |
| Certificate for the request | The new upload key’s public certificate, exported in PEM format (.pem) |
| Who can configure Play App Signing | A Play Console user with admin permission |
| Where to request it | Protected with Play → Play Store protection → Manage Play app signing → Upload key certificate → Request upload key reset |
| Turnaround | Not published by Google |
| Effect on the app signing key | None. Players keep receiving normal updates. |
| Unity Keystore Manager passwords | ASCII characters only |
| Unity Keystore Manager default validity | 50 years |
| Unity password storage | Unity doesn’t save keystore or key passwords |
| Version code | Every upload needs a version code you haven’t used before |
Try recovering first
A recovered password beats a reset: no request, no waiting, nothing to re-register. It’s worth fifteen focused minutes before you create anything new.
Where the password might still be
- Your password manager and notes. Search for the game’s name, the package name (for example
com.example.lanterndrift), “keystore”, “jks”, and “alias”. Check notes apps and old messages to teammates too. - The other password. Many people use one password for both the keystore and the key. Try each one in both fields.
- Build scripts and CI. Unity never saves these passwords, so any automated build has to set them somewhere. Search your project for
keystorePassandkeyaliasPass(thePlayerSettings.Androidproperties) and check your CI’s secret settings. Most CI systems won’t show a saved secret again, but whoever set it up may still have it. - A Unity Editor that’s still open. Unity doesn’t write the passwords to disk, but it keeps what you typed in Player Settings while the Editor runs. If the Editor you last built with hasn’t been closed since, the script below copies the passwords to your clipboard.
using UnityEditor;
// Delete this file as soon as you have the passwords.
static class CopyKeystorePasswords
{
[MenuItem("Tools/Signing/Copy keystore password")]
static void CopyKeystorePassword() => EditorGUIUtility.systemCopyBuffer = PlayerSettings.Android.keystorePass;
[MenuItem("Tools/Signing/Copy key password")]
static void CopyKeyPassword() => EditorGUIUtility.systemCopyBuffer = PlayerSettings.Android.keyaliasPass;
}Choose Tools → Signing → Copy keystore password, paste the result straight into your password manager, then do the same for the key password and delete the script. If the clipboard comes back empty, this Editor session no longer has it.
Get keytool from Unity
The rest of this guide uses keytool, which ships with every Java Development Kit — including the one Unity installs with Android Build Support. In Unity, open Edit → Preferences (macOS: Unity → Settings) → External Tools → Android. With JDK installed with Unity enabled, the JDK folder is shown there; keytool is in its bin subfolder. With a default Unity Hub install on Windows, that’s:
C:\Program Files\Unity\Hub\Editor\<version>\Editor\Data\PlaybackEngines\AndroidPlayer\OpenJDK\binPut that folder on your PATH for the current terminal session, then every command below works as written:
$env:Path = "<JDK folder>\bin;" + $env:Path
keytool -helpexport PATH="<JDK folder>/bin:$PATH"
keytool -helpIf you only forgot the alias
keytool -list -keystore lanterndrift.keystoreWhen it asks for the password, press Enter without typing anything. keytool warns that it couldn’t verify the keystore’s integrity, but it still lists every alias name. If you know the password and have several keystores, add -v and type the password: keytool prints each key’s SHA-1 and SHA-256 fingerprints. The one that matches the Upload key certificate fingerprint on Play Console’s app signing page is your upload key.
A word on guessing
Password-recovery tools that try huge numbers of guesses exist, but they’re only realistic when you remember most of the password — a base word, a pattern, a likely ending. If you don’t, stop here. The reset is the reliable route, and it doesn’t put your app at risk.
Create a new key
Create a brand-new keystore holding one key. Unity’s Keystore Manager and the keytool command line both produce a keystore Unity can load; pick whichever you’re more comfortable with.
Option A: Unity’s Keystore Manager
- Open Edit → Project Settings → Player, select the Android tab, and expand Publishing Settings.
- Select Keystore Manager, then Keystore → Create New. Choose In Dedicated Location, or Anywhere and browse to a folder outside your project — Anywhere starts in your project folder. Name the file after the game, for example
lanterndrift-upload.jks. - Enter and confirm a keystore Password.
- Under New Key Values, set Alias (for example
upload), the key Password, and Validity (years) — the default 50 is fine. Fill in at least your name, organization, and country code: Unity doesn’t validate these fields and uses empty values for blanks. - Select Add key. When Unity asks whether to use the new keystore and key for the project, choose Yes.
Option B: keytool
keytool -genkeypair -v -keystore lanterndrift-upload.jks -alias upload -keyalg RSA -keysize 2048 -validity 10000keytool asks for a keystore password twice, then your name, organizational unit, organization, city, state, and two-letter country code, and finally asks you to confirm — type yes. 10,000 days is about 27 years, above Google’s 25-year recommendation.
Recent keytool versions (including the JDKs Unity installs) create a PKCS12 keystore even when the file ends in .jks. PKCS12 keystores don’t support a separate key password, so the key password is the keystore password. Enter the same one in both of Unity’s password fields.
Whichever option you used, confirm the key meets Google’s requirements:
keytool -list -v -keystore lanterndrift-upload.jks -alias uploadLook for Subject Public Key Algorithm: 2048-bit RSA key (or larger) and a Valid from … until date decades away.
Do
- A new file name, kept next to — not over — the old keystore
- One key per keystore, with an alias you’ll remember, such as “upload”
- A validity of 25 years or more
- A long, random password generated by your password manager
- Name, organization, and country filled in
Don’t
- Saving the keystore in Assets/ or anywhere your repository tracks
- Reusing your Google account or Play Console password
- Non-ASCII characters in passwords (Unity’s Keystore Manager supports ASCII only)
- Keys under 2,048 bits
- Shipping with Unity’s debug keystore (Custom Keystore turned off)
Export the certificate
Play Console needs the public certificate of your new upload key as a .pem file. A certificate contains no private key, so it’s safe to upload and share.
keytool -export -rfc -keystore lanterndrift-upload.jks -alias upload -file lanterndrift_upload_cert.pem-rfc writes the printable PEM format, so the file starts with -----BEGIN CERTIFICATE-----; without it you’d get binary DER. -export is the older name for -exportcert, and both work. While you’re here, print the certificate’s fingerprints — you’ll compare builds against them later:
keytool -printcert -file lanterndrift_upload_cert.pemStore the key safely
Before you send anything to Google, put the new key somewhere you’ll still find it in three years. This is the step that would have prevented the whole problem. Keep these together:
| Keystore file | lanterndrift-upload.jks |
|---|---|
| Keystore password | The one you set when you created the keystore |
| Key alias and key password | upload, plus its password (the same as the keystore password for keytool-made keystores) |
| Certificate | lanterndrift_upload_cert.pem, with its SHA-1 and SHA-256 fingerprints |
| Scope | Package names of every game signed with this key |
What works
- One password-manager item per key. Put the passwords, alias, and fingerprints in a single item and attach the keystore file to it. Most password managers handle attachments; in 1Password, for example, it’s Edit → Add More → Attach a File.
- An offline backup. Keep a second copy on encrypted storage away from your computer. Accounts get locked and laptops get stolen.
- A shared vault for teams. If someone else builds releases, share the item through the password manager rather than sending the file over chat or email.
- Nothing in version control. Keep the keystore outside the project entirely. The
.gitignorelines below are a safety net, not a plan.
# Android signing keys: never commit these
*.jks
*.keystoreRequest the reset
With the new key stored and its .pem exported, ask Google to register it. The request is per app: if the lost key signed several of your games, repeat it on each game’s page. You can register the same new certificate for all of them.
- Sign in to Play Console and open the game.
- Go to Protected with Play → Play Store protection → Manage Play app signing. Google’s help also reaches this page through Protected with Play → Play Store distribution → Go to Play app signing; older versions of the console had it under Test and release → Setup → App signing.
- Scroll to the Upload key certificate section and select Request upload key reset.
- Enter the reason for the reset.
- Upload
lanterndrift_upload_cert.pemand select Request.
Keep the reason short and factual — what happened and what you’re attaching:
We lost the password for our upload keystore and can no longer sign releases. We created a new upload key and attached its certificate. Please register it as the upload key for this app.
Our upload keystore was accidentally pushed to a public repository on 3 October 2026, so we consider it compromised. The attached certificate belongs to a newly generated upload key. Please register it as the upload key for this app.
What happens next
- 1You submit the requestA reason, plus the new upload certificate as a .pem file.
- 2Google reviews itNot instant. Google doesn’t publish a turnaround time.
- 3You get the approval noticeIt says from what date and time the new key is valid.
- 4You upload with the new keyFrom that moment on. Players and the app signing key are unaffected.
Google reviews each request, and Google doesn’t publish a turnaround time. When it’s approved you’re notified — Google has described this as a Play Console Inbox message and an email to the account owner and admins — and the notice tells you from when the new key is valid. Developers often report around 48 hours, but go by the date and time Google gives you, not a rule of thumb.
Until then, Play keeps expecting the old key, so a bundle signed with the new one is rejected. After that, the new certificate is your app’s registered upload key — sign every future release with it.
Configure Unity
Point Unity at the new keystore while you wait. Unity remembers which keystore you chose but never the passwords, so you’ll re-enter them every time you restart the Editor.
- Open Edit → Project Settings → Player → Android → Publishing Settings.
- Enable Custom Keystore, open the Select dropdown, choose Browse, and pick
lanterndrift-upload.jks. If you created it in the Keystore Manager and chose Yes, it’s already selected. - Enter the keystore password. Unity loads the keystore when the password is correct.
- Pick
uploadas the key alias and enter the key password. - Raise Bundle Version Code (Other Settings → Identification) above your last upload.
- In File → Build Profiles (Unity 6) or File → Build Settings (Unity 2022.3), enable Build App Bundle (Google Play) and build.
| Unity 2022.3 LTS field names | Project Keystore: Custom Keystore, Select, Path, Password. Project Key: Alias, Password. |
|---|---|
| Unity 6 field names | Project Keystore: Custom Keystore, Select, Keystore path, Keystore password, Key alias, Key password. |
Verify the signature
Before uploading, prove the bundle is signed with the new key. It takes ten seconds and turns a confusing Play Console rejection into a local check.
keytool -printcert -jarfile LanternDrift.aabCompare the SHA-1 and SHA-256 under Signer #1 with your certificate’s fingerprints and, once the reset is approved, with the Upload key certificate fingerprints on the Play app signing page. They must match exactly.
For an APK you built for local testing, keytool -printcert -jarfile works too, or use apksigner from the Android SDK build-tools folder that Unity installs:
apksigner verify --print-certs LanternDrift.apkUpdate anything that used the old fingerprint
Google APIs and many other services identify your app by package name plus a certificate fingerprint. Which fingerprint they see depends on how the build was installed:
- Installed from Google Play, on any track. Signed with the app signing key, which Google says is the fingerprint to register with API providers. A reset doesn’t change it, so these registrations keep working.
- Built and signed on your machine, installed directly. Signed with the upload key. If you registered the old upload key’s SHA-1 so local release builds could use Google Sign-In, Firebase, or a restricted API key, add the new key’s fingerprint and remove the old one.
Common errors
The first four messages below are keytool’s exact wording. The three password messages come from Java itself, so Unity’s Gradle build can show the same text inside a longer signing error.
Keystore was tampered with, or password was incorrectWrong keystore password for a JKS keystore — or the wrong file. Check which keystore Unity has loaded, then re-enter the password.keystore password was incorrectThe same problem for a PKCS12 keystore.Cannot recover keyThe keystore password was right, but the key password wasn’t. For a keytool-made keystore, use the keystore password.Alias <upload> does not existThe alias is misspelled or belongs to another keystore. List the aliases withkeytool -list.- Play Console says the bundle is signed with the wrong key. The error lists the SHA-1 it expected and the one it got. Either the reset isn’t active yet (Play still wants the old key), or Unity is still pointing at the old keystore. Compare fingerprints before changing anything.
- Play Console refuses a debug-signed bundle. Custom Keystore was off when you built.
- Play Console says the version code is already used. Raise Bundle Version Code and rebuild; Play won’t accept a version code you’ve used before.
- The password fields are empty after restarting Unity. Expected. Unity never saves them; paste them from your password manager.
Testing and iterating
Ship the first bundle signed with the new key to internal testing, not production. An internal test reaches up to 100 testers you add by email, and a new bundle usually reaches them within minutes.
- Wait for the date and time in Google’s approval notice.
- Build the AAB with the new key and run
keytool -printcert -jarfileon it. - Upload it under Test and release → Testing → Internal testing and roll it out.
- On a test device that already has the live game and is signed in as an internal tester, update from the Play Store. It should install as an update and keep save data — proof that the app signing key didn’t change.
- Test everything tied to a fingerprint: sign-in, cloud saves, purchases, and restricted API keys.
- Release the same bundle to production.
If an upload is rejected for the wrong key, don’t generate yet another keystore — compare fingerprints first. The usual causes are Unity still pointing at the old keystore, or uploading before the activation time.
Then test your backup while everything is fresh: restore the keystore from your password manager into a temporary folder and run keytool -list -v on it with the stored password. A backup you’ve never restored is only a hope.
Recovery checklist
Before the request
- App: enrolled in Play App Signing (you’ve uploaded an .aab, or the app signing page shows an App signing key section)
- Recovery tried: password manager, notes, build scripts, CI secrets, a still-open Unity Editor
- Old keystore: kept, not overwritten
- New keystore: new file name, RSA ≥ 2,048 bits, validity ≥ 25 years
- Certificate: exported from the new keystore with keytool -export -rfc
- Storage: keystore file, passwords, alias, and fingerprints in one password-manager item, plus an offline backup
- Repository: no keystore inside the Unity project or any repository
The request
- Requested from Protected with Play → Play Store protection → Manage Play app signing
- Repeated for every app the lost key signed
- Activation date and time from Google’s notice noted
After approval
- Unity: Custom Keystore on, new keystore and alias selected, both passwords entered
- Bundle Version Code higher than any previous upload
- Fingerprints: keytool -printcert -jarfile output matches the new upload certificate
- Internal testing: release installed as an update over the live game
- Fingerprint registrations: old upload key replaced wherever local builds used it
- Backup: restored once and opened with the stored password
Sources
Rules, requirements, and UI paths in this guide were checked against these sources in October 2026. The keytool commands and messages were run against the OpenJDK 11 and 17 builds bundled with Unity 2022.3 and Unity 6.
- Use Play App Signing — Play Console Help
- About Android App Bundles — Play Console Help
- Set up an open, closed, or internal test — Play Console Help
- Sign your app — Android Developers
- Build your app from the command line — Android Developers
- apksigner — Android Developers
- Version your app — Android Developers
- Authenticating your client — Google Play services
- The keytool command — Java SE 17 documentation
- Android Player settings (Unity 6) — Unity Manual
- Android Player settings (Unity 2022.3) — Unity Manual
- Keystore Manager window reference — Unity Manual
- Create a new keystore — Unity Manual
- Add keys to a keystore — Unity Manual
- Load a keystore — Unity Manual
- Android External Tools reference — Unity Manual
- Android build settings — Unity Manual
- PlayerSettings.Android.keystorePass — Unity Scripting API
- Store files in 1Password — 1Password Support
Take this guide with you
The full guide as one Markdown file — ready to hand to an AI agent, drop into your notes, or read offline.