---
title: "Forgot Your Unity Keystore Password? How to Reset Your Google Play Upload Key"
description: "Can’t sign your Unity build for Google Play anymore? Check whether the key is recoverable, create and store a new upload key, request an upload key reset in Play Console, and ship the next update."
source: https://dmgforge.com/resources/guides/reset-lost-google-play-upload-key
updated: 2026-10-10
tags: ["Google Play", "Unity", "Android", "Signing"]
publisher: DMG Forge
---

# Forgot Your Unity Keystore Password? How to Reset Your Google Play Upload Key

> Can’t sign your Unity build for Google Play anymore? Check whether the key is recoverable, create and store a new upload key, request an upload key reset in Play Console, and ship the next update.

You open Unity to ship an update, Player Settings asks for the keystore password, and nothing you type works. Or the `.jks` file left with an old laptop. Either way you can’t sign a build Google Play will accept, and for a moment it looks like your game can never be updated again.

For almost every game on Google Play, that isn’t true. If your app uses Play App Signing — every app created since August 2021 does — the key you’ve lost is only your **upload key**, and Google can register a new one. This guide walks through the whole job: working out which situation you’re in, trying to recover the password, creating and storing a new upload key, requesting the reset in Play Console, and signing your next Unity build with it.

> **How to use this guide:** Signing rules, key requirements, and Play Console steps come from Google’s Play Console Help and Android Developers docs; Unity behavior comes from the Unity Manual (all linked in [Sources](https://dmgforge.com/resources/guides/reset-lost-google-play-upload-key#sources)). The keytool commands were tested with the OpenJDK builds that Unity 2022.3 LTS and Unity 6 install. Advice on storing keys is practice, not policy. Google moves Play Console menus around regularly — the paths here match Google’s help pages in October 2026, and if the console disagrees with this guide, the console wins.

## How Play signing works

Under Play App Signing, two different keys sign your game, and only one of them is yours. Your upload key lives in the keystore Unity signs with, and Google uses it only to confirm that a bundle really came from you. Google then signs the APKs it delivers to players with the app signing key, which Google keeps and you can’t download.

*Figure: The two-key model. Losing the upload key breaks steps 1–2 only; the app signing key that players’ devices check never changes.*

1. **You sign the bundle with your upload key** — Unity builds the .aab and signs it with the keystore on your machine.
2. **Play Console checks the upload certificate** — This only proves the bundle came from you. It’s the key Google can reset.
3. **Google Play re-signs with the app signing key** — Google holds this key and you can’t download it. A reset doesn’t touch it.
4. **Players install and update** — Devices only see the app signing key, so updates keep working after a reset.

That split is what makes a lost upload key recoverable. Google can register a new upload key for your app, and because the app signing key stays the same, players receive your next release as a normal update — same app, same reviews, same save data.

| Item | Details |
| --- | --- |
| Upload key | Held by you in a Java keystore (.jks or .keystore). Signs the bundle you upload. Google can reset it if it’s lost or compromised. |
| App signing key | Held by Google. Signs the APKs delivered to devices. You can’t download a copy, and an upload key reset doesn’t change it. |
| Your first upload | When Google generates the app signing key (the default), the key you sign your first release with becomes your upload key. |
| Apps created since August 2021 | Must publish with Android App Bundles (.aab), and app bundles require Play App Signing. |
| Older apps that upload self-signed APKs | Can still manage their own signing key. If that key is lost, Google can’t reset it. |

> **Pro tip:** Quick check: if you’ve ever uploaded an `.aab` for this game, it’s enrolled in Play App Signing, because app bundles require it. You can confirm on the Play app signing page, which shows separate App signing key and Upload key certificate sections for enrolled apps.

## Find your situation

Work out exactly what’s missing before you change anything. Some of these situations take five minutes to fix, most end in an upload key reset, and one can’t be fixed at all.

- **You have the file but forgot the keystore password.** Try to recover it first (next section). If it’s really gone, request an upload key reset.
- **You know the keystore password but not the key password.** Try the keystore password as the key password. Keystores made with recent keytool versions can’t have a separate one. If that fails, reset.
- **You forgot the alias.** That’s not a lost key. `keytool -list` shows the alias names even without the password.
- **The keystore file is gone.** Nothing to recover. Request an upload key reset.
- **The key leaked.** Committed to a public repository, shared in a chat, on a stolen laptop: treat it as compromised and request a reset the same way.
- **No build was ever uploaded for this app.** There’s nothing to reset. Create a new keystore; the first bundle you upload (on any track) sets the upload key.
- **The app isn’t on Play App Signing and you lost its signing key.** This is the one case with no fix. See the rule below.

> **Google Play rule:** A self-managed app signing key can’t be reset. If your app isn’t enrolled in Play App Signing and you lose the key that signs it, you also can’t enroll, because enrolling an existing app means uploading that key. Your only option is to publish the game again under a new package name, and existing players won’t get it as an update.

## The spec sheet

These are the hard requirements you’ll meet during a reset. Everything else in this guide is how to get there.

**Upload key and reset requirements**

| Item | Details |
| --- | --- |
| Key type | RSA, 2,048 bits or more |
| Keystore format | Java keystore, .jks or .keystore |
| Key validity | Google recommends at least 25 years; Google Play requires a validity period ending after 22 October 2033 |
| Certificate for the request | The new upload key’s public certificate, exported in PEM format (.pem) |
| Who can configure Play App Signing | A Play Console user with admin permission |
| Where to request it | Protected with Play → Play Store protection → Manage Play app signing → Upload key certificate → Request upload key reset |
| Turnaround | Not published by Google |
| Effect on the app signing key | None. Players keep receiving normal updates. |
| Unity Keystore Manager passwords | ASCII characters only |
| Unity Keystore Manager default validity | 50 years |
| Unity password storage | Unity doesn’t save keystore or key passwords |
| Version code | Every upload needs a version code you haven’t used before |

## Try recovering first

A recovered password beats a reset: no request, no waiting, nothing to re-register. It’s worth fifteen focused minutes before you create anything new.

### Where the password might still be

- **Your password manager and notes.** Search for the game’s name, the package name (for example `com.example.lanterndrift`), “keystore”, “jks”, and “alias”. Check notes apps and old messages to teammates too.
- **The other password.** Many people use one password for both the keystore and the key. Try each one in both fields.
- **Build scripts and CI.** Unity never saves these passwords, so any automated build has to set them somewhere. Search your project for `keystorePass` and `keyaliasPass` (the `PlayerSettings.Android` properties) and check your CI’s secret settings. Most CI systems won’t show a saved secret again, but whoever set it up may still have it.
- **A Unity Editor that’s still open.** Unity doesn’t write the passwords to disk, but it keeps what you typed in Player Settings while the Editor runs. If the Editor you last built with hasn’t been closed since, the script below copies the passwords to your clipboard.

**Assets/Editor/CopyKeystorePasswords.cs**

```csharp
using UnityEditor;

// Delete this file as soon as you have the passwords.
static class CopyKeystorePasswords
{
    [MenuItem("Tools/Signing/Copy keystore password")]
    static void CopyKeystorePassword() => EditorGUIUtility.systemCopyBuffer = PlayerSettings.Android.keystorePass;

    [MenuItem("Tools/Signing/Copy key password")]
    static void CopyKeyPassword() => EditorGUIUtility.systemCopyBuffer = PlayerSettings.Android.keyaliasPass;
}
```

Choose **Tools → Signing → Copy keystore password**, paste the result straight into your password manager, then do the same for the key password and delete the script. If the clipboard comes back empty, this Editor session no longer has it.

### Get keytool from Unity

The rest of this guide uses `keytool`, which ships with every Java Development Kit — including the one Unity installs with Android Build Support. In Unity, open **Edit → Preferences** (macOS: **Unity → Settings**) → **External Tools** → **Android**. With **JDK installed with Unity** enabled, the JDK folder is shown there; `keytool` is in its `bin` subfolder. With a default Unity Hub install on Windows, that’s:

**keytool folder (Windows, Unity Hub default)**

```text
C:\Program Files\Unity\Hub\Editor\<version>\Editor\Data\PlaybackEngines\AndroidPlayer\OpenJDK\bin
```

Put that folder on your PATH for the current terminal session, then every command below works as written:

**PowerShell (Windows)**

```powershell
$env:Path = "<JDK folder>\bin;" + $env:Path
keytool -help
```

**Terminal (macOS, Linux)**

```bash
export PATH="<JDK folder>/bin:$PATH"
keytool -help
```

### If you only forgot the alias

**Terminal: list the aliases in the old keystore**

```bash
keytool -list -keystore lanterndrift.keystore
```

When it asks for the password, press Enter without typing anything. keytool warns that it couldn’t verify the keystore’s integrity, but it still lists every alias name. If you know the password and have several keystores, add `-v` and type the password: keytool prints each key’s SHA-1 and SHA-256 fingerprints. The one that matches the **Upload key certificate** fingerprint on Play Console’s app signing page is your upload key.

### A word on guessing

Password-recovery tools that try huge numbers of guesses exist, but they’re only realistic when you remember most of the password — a base word, a pattern, a likely ending. If you don’t, stop here. The reset is the reliable route, and it doesn’t put your app at risk.

> **Watch out:** Keep the old keystore. Save the new one under a new file name, never over the old file. Until Google approves your reset, Play still expects the old key — if the password turns up in the meantime, you’ll want that file.

## Create a new key

Create a brand-new keystore holding one key. Unity’s Keystore Manager and the `keytool` command line both produce a keystore Unity can load; pick whichever you’re more comfortable with.

### Option A: Unity’s Keystore Manager

1. Open **Edit → Project Settings → Player**, select the **Android** tab, and expand **Publishing Settings**.
2. Select **Keystore Manager**, then **Keystore → Create New**. Choose **In Dedicated Location**, or **Anywhere** and browse to a folder outside your project — **Anywhere** starts in your project folder. Name the file after the game, for example `lanterndrift-upload.jks`.
3. Enter and confirm a keystore **Password**.
4. Under **New Key Values**, set **Alias** (for example `upload`), the key **Password**, and **Validity (years)** — the default 50 is fine. Fill in at least your name, organization, and country code: Unity doesn’t validate these fields and uses empty values for blanks.
5. Select **Add key**. When Unity asks whether to use the new keystore and key for the project, choose **Yes**.

### Option B: keytool

**Terminal: create the keystore**

```bash
keytool -genkeypair -v -keystore lanterndrift-upload.jks -alias upload -keyalg RSA -keysize 2048 -validity 10000
```

keytool asks for a keystore password twice, then your name, organizational unit, organization, city, state, and two-letter country code, and finally asks you to confirm — type `yes`. 10,000 days is about 27 years, above Google’s 25-year recommendation.

Recent keytool versions (including the JDKs Unity installs) create a PKCS12 keystore even when the file ends in `.jks`. PKCS12 keystores don’t support a separate key password, so the key password is the keystore password. Enter the same one in both of Unity’s password fields.

Whichever option you used, confirm the key meets Google’s requirements:

**Terminal: inspect the key**

```bash
keytool -list -v -keystore lanterndrift-upload.jks -alias upload
```

Look for `Subject Public Key Algorithm: 2048-bit RSA key` (or larger) and a `Valid from … until` date decades away.

**Do**

- A new file name, kept next to — not over — the old keystore
- One key per keystore, with an alias you’ll remember, such as “upload”
- A validity of 25 years or more
- A long, random password generated by your password manager
- Name, organization, and country filled in

**Don’t**

- Saving the keystore in Assets/ or anywhere your repository tracks
- Reusing your Google account or Play Console password
- Non-ASCII characters in passwords (Unity’s Keystore Manager supports ASCII only)
- Keys under 2,048 bits
- Shipping with Unity’s debug keystore (Custom Keystore turned off)

## Export the certificate

Play Console needs the public certificate of your new upload key as a `.pem` file. A certificate contains no private key, so it’s safe to upload and share.

**Terminal: export the upload certificate**

```bash
keytool -export -rfc -keystore lanterndrift-upload.jks -alias upload -file lanterndrift_upload_cert.pem
```

`-rfc` writes the printable PEM format, so the file starts with `-----BEGIN CERTIFICATE-----`; without it you’d get binary DER. `-export` is the older name for `-exportcert`, and both work. While you’re here, print the certificate’s fingerprints — you’ll compare builds against them later:

**Terminal: show the fingerprints**

```bash
keytool -printcert -file lanterndrift_upload_cert.pem
```

> **Watch out:** Export from the **new** keystore. A `.pem` you exported months ago belongs to the key you lost; sending it with the request registers the wrong certificate.

## Store the key safely

Before you send anything to Google, put the new key somewhere you’ll still find it in three years. This is the step that would have prevented the whole problem. Keep these together:

| Item | Details |
| --- | --- |
| Keystore file | lanterndrift-upload.jks |
| Keystore password | The one you set when you created the keystore |
| Key alias and key password | upload, plus its password (the same as the keystore password for keytool-made keystores) |
| Certificate | lanterndrift_upload_cert.pem, with its SHA-1 and SHA-256 fingerprints |
| Scope | Package names of every game signed with this key |

### What works

- **One password-manager item per key.** Put the passwords, alias, and fingerprints in a single item and attach the keystore file to it. Most password managers handle attachments; in 1Password, for example, it’s **Edit → Add More → Attach a File**.
- **An offline backup.** Keep a second copy on encrypted storage away from your computer. Accounts get locked and laptops get stolen.
- **A shared vault for teams.** If someone else builds releases, share the item through the password manager rather than sending the file over chat or email.
- **Nothing in version control.** Keep the keystore outside the project entirely. The `.gitignore` lines below are a safety net, not a plan.

**.gitignore**

```text
# Android signing keys: never commit these
*.jks
*.keystore
```

> **Watch out:** A keystore pushed to a public repository is compromised even if you delete it later, because git history keeps it. Treat it like a lost key: create a new one and request an upload key reset.

## Request the reset

With the new key stored and its `.pem` exported, ask Google to register it. The request is per app: if the lost key signed several of your games, repeat it on each game’s page. You can register the same new certificate for all of them.

1. Sign in to Play Console and open the game.
2. Go to **Protected with Play → Play Store protection → Manage Play app signing**. Google’s help also reaches this page through **Protected with Play → Play Store distribution → Go to Play app signing**; older versions of the console had it under **Test and release → Setup → App signing**.
3. Scroll to the **Upload key certificate** section and select **Request upload key reset**.
4. Enter the reason for the reset.
5. Upload `lanterndrift_upload_cert.pem` and select **Request**.

Keep the reason short and factual — what happened and what you’re attaching:

**Good — lost password**

```text
We lost the password for our upload keystore and can no longer sign releases. We created a new upload key and attached its certificate. Please register it as the upload key for this app.
```

**Good — compromised key**

```text
Our upload keystore was accidentally pushed to a public repository on 3 October 2026, so we consider it compromised. The attached certificate belongs to a newly generated upload key. Please register it as the upload key for this app.
```

### What happens next

*Figure: After you select Request. The waiting stretch between steps 2 and 3 is the part you can’t speed up, so use it to set up Unity.*

1. **You submit the request** — A reason, plus the new upload certificate as a .pem file.
2. **Google reviews it** — Not instant. Google doesn’t publish a turnaround time.
3. **You get the approval notice** — It says from what date and time the new key is valid.
4. **You upload with the new key** — From that moment on. Players and the app signing key are unaffected.

Google reviews each request, and Google doesn’t publish a turnaround time. When it’s approved you’re notified — Google has described this as a Play Console Inbox message and an email to the account owner and admins — and the notice tells you from when the new key is valid. Developers often report around 48 hours, but go by the date and time Google gives you, not a rule of thumb.

Until then, Play keeps expecting the old key, so a bundle signed with the new one is rejected. After that, the new certificate is your app’s registered upload key — sign every future release with it.

> **Pro tip:** No **Request upload key reset** button? Google’s help says configuring Play App Signing needs admin permission — it said account owner until recently. Ask the account owner to make the request or to grant you admin access, and confirm the app shows an App signing key section at all.

## Configure Unity

Point Unity at the new keystore while you wait. Unity remembers which keystore you chose but never the passwords, so you’ll re-enter them every time you restart the Editor.

1. Open **Edit → Project Settings → Player → Android → Publishing Settings**.
2. Enable **Custom Keystore**, open the **Select** dropdown, choose **Browse**, and pick `lanterndrift-upload.jks`. If you created it in the Keystore Manager and chose Yes, it’s already selected.
3. Enter the keystore password. Unity loads the keystore when the password is correct.
4. Pick `upload` as the key alias and enter the key password.
5. Raise **Bundle Version Code** (**Other Settings → Identification**) above your last upload.
6. In **File → Build Profiles** (Unity 6) or **File → Build Settings** (Unity 2022.3), enable **Build App Bundle (Google Play)** and build.

| Item | Details |
| --- | --- |
| Unity 2022.3 LTS field names | Project Keystore: Custom Keystore, Select, Path, Password. Project Key: Alias, Password. |
| Unity 6 field names | Project Keystore: Custom Keystore, Select, Keystore path, Keystore password, Key alias, Key password. |

> **Watch out:** With **Custom Keystore** turned off, Unity signs with a debug keystore, and app stores decline debug-signed builds. Check the toggle before every release build.

## Verify the signature

Before uploading, prove the bundle is signed with the new key. It takes ten seconds and turns a confusing Play Console rejection into a local check.

**Terminal: check an app bundle**

```bash
keytool -printcert -jarfile LanternDrift.aab
```

Compare the SHA-1 and SHA-256 under `Signer #1` with your certificate’s fingerprints and, once the reset is approved, with the **Upload key certificate** fingerprints on the Play app signing page. They must match exactly.

For an APK you built for local testing, `keytool -printcert -jarfile` works too, or use `apksigner` from the Android SDK `build-tools` folder that Unity installs:

**Terminal: check an APK**

```bash
apksigner verify --print-certs LanternDrift.apk
```

### Update anything that used the old fingerprint

Google APIs and many other services identify your app by package name plus a certificate fingerprint. Which fingerprint they see depends on how the build was installed:

- **Installed from Google Play, on any track.** Signed with the app signing key, which Google says is the fingerprint to register with API providers. A reset doesn’t change it, so these registrations keep working.
- **Built and signed on your machine, installed directly.** Signed with the upload key. If you registered the old upload key’s SHA-1 so local release builds could use Google Sign-In, Firebase, or a restricted API key, add the new key’s fingerprint and remove the old one.

## Common errors

The first four messages below are keytool’s exact wording. The three password messages come from Java itself, so Unity’s Gradle build can show the same text inside a longer signing error.

- **`Keystore was tampered with, or password was incorrect`** Wrong keystore password for a JKS keystore — or the wrong file. Check which keystore Unity has loaded, then re-enter the password.
- **`keystore password was incorrect`** The same problem for a PKCS12 keystore.
- **`Cannot recover key`** The keystore password was right, but the key password wasn’t. For a keytool-made keystore, use the keystore password.
- **`Alias <upload> does not exist`** The alias is misspelled or belongs to another keystore. List the aliases with `keytool -list`.
- **Play Console says the bundle is signed with the wrong key.** The error lists the SHA-1 it expected and the one it got. Either the reset isn’t active yet (Play still wants the old key), or Unity is still pointing at the old keystore. Compare fingerprints before changing anything.
- **Play Console refuses a debug-signed bundle.** **Custom Keystore** was off when you built.
- **Play Console says the version code is already used.** Raise **Bundle Version Code** and rebuild; Play won’t accept a version code you’ve used before.
- **The password fields are empty after restarting Unity.** Expected. Unity never saves them; paste them from your password manager.

## Testing and iterating

Ship the first bundle signed with the new key to internal testing, not production. An internal test reaches up to 100 testers you add by email, and a new bundle usually reaches them within minutes.

1. Wait for the date and time in Google’s approval notice.
2. Build the AAB with the new key and run `keytool -printcert -jarfile` on it.
3. Upload it under **Test and release → Testing → Internal testing** and roll it out.
4. On a test device that already has the live game and is signed in as an internal tester, update from the Play Store. It should install as an update and keep save data — proof that the app signing key didn’t change.
5. Test everything tied to a fingerprint: sign-in, cloud saves, purchases, and restricted API keys.
6. Release the same bundle to production.

If an upload is rejected for the wrong key, don’t generate yet another keystore — compare fingerprints first. The usual causes are Unity still pointing at the old keystore, or uploading before the activation time.

Then test your backup while everything is fresh: restore the keystore from your password manager into a temporary folder and run `keytool -list -v` on it with the stored password. A backup you’ve never restored is only a hope.

## Recovery checklist

### Before the request

- [ ] App: enrolled in Play App Signing (you’ve uploaded an .aab, or the app signing page shows an App signing key section)
- [ ] Recovery tried: password manager, notes, build scripts, CI secrets, a still-open Unity Editor
- [ ] Old keystore: kept, not overwritten
- [ ] New keystore: new file name, RSA ≥ 2,048 bits, validity ≥ 25 years
- [ ] Certificate: exported from the new keystore with keytool -export -rfc
- [ ] Storage: keystore file, passwords, alias, and fingerprints in one password-manager item, plus an offline backup
- [ ] Repository: no keystore inside the Unity project or any repository

### The request

- [ ] Requested from Protected with Play → Play Store protection → Manage Play app signing
- [ ] Repeated for every app the lost key signed
- [ ] Activation date and time from Google’s notice noted

### After approval

- [ ] Unity: Custom Keystore on, new keystore and alias selected, both passwords entered
- [ ] Bundle Version Code higher than any previous upload
- [ ] Fingerprints: keytool -printcert -jarfile output matches the new upload certificate
- [ ] Internal testing: release installed as an update over the live game
- [ ] Fingerprint registrations: old upload key replaced wherever local builds used it
- [ ] Backup: restored once and opened with the stored password

## Sources

Rules, requirements, and UI paths in this guide were checked against these sources in October 2026. The keytool commands and messages were run against the OpenJDK 11 and 17 builds bundled with Unity 2022.3 and Unity 6.

- [Use Play App Signing — Play Console Help](https://support.google.com/googleplay/android-developer/answer/9842756)
- [About Android App Bundles — Play Console Help](https://support.google.com/googleplay/android-developer/answer/9844279)
- [Set up an open, closed, or internal test — Play Console Help](https://support.google.com/googleplay/android-developer/answer/9845334)
- [Sign your app — Android Developers](https://developer.android.com/studio/publish/app-signing)
- [Build your app from the command line — Android Developers](https://developer.android.com/build/building-cmdline)
- [apksigner — Android Developers](https://developer.android.com/tools/apksigner)
- [Version your app — Android Developers](https://developer.android.com/studio/publish/versioning)
- [Authenticating your client — Google Play services](https://developers.google.com/android/guides/client-auth)
- [The keytool command — Java SE 17 documentation](https://docs.oracle.com/en/java/javase/17/docs/specs/man/keytool.html)
- [Android Player settings (Unity 6) — Unity Manual](https://docs.unity3d.com/6000.0/Documentation/Manual/class-PlayerSettingsAndroid.html)
- [Android Player settings (Unity 2022.3) — Unity Manual](https://docs.unity3d.com/2022.3/Documentation/Manual/class-PlayerSettingsAndroid.html)
- [Keystore Manager window reference — Unity Manual](https://docs.unity3d.com/6000.0/Documentation/Manual/android-keystore-manager.html)
- [Create a new keystore — Unity Manual](https://docs.unity3d.com/6000.0/Documentation/Manual/android-keystore-create.html)
- [Add keys to a keystore — Unity Manual](https://docs.unity3d.com/6000.0/Documentation/Manual/android-keystore-add-keys.html)
- [Load a keystore — Unity Manual](https://docs.unity3d.com/6000.0/Documentation/Manual/android-keystore-load.html)
- [Android External Tools reference — Unity Manual](https://docs.unity3d.com/6000.0/Documentation/Manual/android-external-tools-reference.html)
- [Android build settings — Unity Manual](https://docs.unity3d.com/6000.0/Documentation/Manual/android-build-settings.html)
- [PlayerSettings.Android.keystorePass — Unity Scripting API](https://docs.unity3d.com/6000.0/Documentation/ScriptReference/PlayerSettings.Android-keystorePass.html)
- [Store files in 1Password — 1Password Support](https://support.1password.com/files/)
