F-Droid released version 2.0 of its Android client on September 24, a rewrite in Kotlin and Jetpack Compose after more than a year of work and 14 test releases. Six days later, on September 30, Google starts enforcing Android developer verification in Brazil, Indonesia, Singapore and Thailand. Certified phones in those countries will refuse a normal install of any app whose developer has not registered an identity with Google. F-Droid's whole model depends on never asking for one.
So the project shipped its largest update in ten years, and the platform it runs on is about to make its apps harder to install than they have been since the first Android phone.
What changed in the client
The old F-Droid app was Java and XML layouts with roots going back to 2010. The 2.0 announcement says that codebase is gone. Navigation collapses to three tabs: Discover, Search and My Apps. Search now covers descriptions, categories and translated text, with better handling of Chinese, Japanese and Korean. Filters combine category, device compatibility and anti-features in one screen. Games split into 17 genres instead of one bucket. The minimum Android version moves from 6 to 7.
The install path is the biggest change for anyone who has used F-Droid for long. The client now uses Android's pre-approval install API, so the user confirms once, right after tapping install, instead of waiting for the download and confirming again. Updates apply on their own by default. F-Droid credits the EU's Digital Markets Act for that API existing at all. Google added it because regulators made alternative stores a compliance problem, and F-Droid is collecting the benefit.
Some things were cut. The Privileged Extension, which let F-Droid install silently on rooted devices and custom ROMs, is no longer supported. The panic feature that wiped apps on a trigger is gone until someone volunteers to maintain it. Tor auto-detection is replaced by plain proxy settings. Pull to refresh now scrolls, and the manual update check moved into a menu.
Funding came from NLnet's Mobifree fund, the Open Technology Fund, NGI and the Calyx Institute. OTF's Security Lab and Convocation did an independent security review before release. That is more audit than most app stores get.
What Google turns on September 30
Google's June announcement set the schedule. On September 30, certified devices running Android 7 or later in the four launch countries begin checking that an app's package name is registered to a verified developer before allowing a standard install. The check applies to Google Play and to six partner stores: Samsung's Galaxy Store, Xiaomi's GetApps, OPPO App Market, vivo's V-Appstore, HONOR App Market and Transsion's Palm Store. Google says 99% of apps on Play were registered automatically. Every APK a user pulls from a website or an alternative store is held to the same rule. Global rollout follows in 2027.
Verification means creating an account, paying $25 once, and uploading a government ID. There is a free Limited Distribution tier with no ID check, capped at 20 devices. Google built that tier for students and hobbyists. Twenty devices is a classroom, not a distribution channel.
Unregistered apps are not blocked outright. They can be installed over ADB from a computer, or through what Google calls the advanced flow. The Register walked through that flow:
- Confirm that nobody is pressuring you to install the app.
- Enable developer mode.
- Reboot the phone.
- Wait 24 hours.
- Click through several warning screens.
- Choose whether the permission lasts a week or indefinitely.
Google designed it that way. The 24 hour wait exists to defeat scam callers who walk a victim through a sideload while they are on the phone, and it will do that. It also defeats a normal person who wants to install an app today.
The whole flow runs through Google Play Services. Google can change or remove it in a background update without asking anyone.
Why F-Droid cannot register
F-Droid builds most of its 4,455 apps from source on its own servers and signs them with its own keys. As far as Android is concerned, the developer of record for those builds is F-Droid. Google's scheme ties each package name to one verified identity. Either F-Droid puts a nonprofit's name behind thousands of apps it did not write, or every upstream developer registers their own package name and hands Google a passport scan.
Many of them won't. A good share of F-Droid contributors are pseudonymous on purpose. Some ship censorship circumvention tools, or apps for people in places where a government ID attached to that work is a personal risk. F-Droid has no user accounts and tracks nothing, and it has told Google it will not start.
Marc Prud'hommeaux, an F-Droid board member, said it in September 2025: "If it were to be put into effect, the developer registration decree will end the F-Droid project and other free/open source app distribution sources as we know them today." The project followed with an open letter in February and the Keep Android Open campaign, which now has more than 70 organizations in 23 countries signed on. Google adjusted the edges, adding the hobbyist tier and the advanced flow, and kept the core requirement.
Reproducible builds are the technical way out, and F-Droid already uses them for a subset of apps. When a build reproduces byte for byte, F-Droid ships the APK signed with the upstream developer's key rather than its own. If that developer registers with Google, the F-Droid copy passes the check. Coverage is partial. Getting a Gradle build to reproduce across machines is tedious, and not every upstream cares enough to do it.
The store gets better as the door closes
I've run infrastructure long enough to know this pattern. A platform owner has a real security problem, in this case malware sideloaded onto phones in markets where Play was never the only store. The fix chosen is identity, because identity is the control the platform owner can operate from one console. The fix also makes every distribution channel the platform owner does not run more expensive to use. Both effects are real, and the second one is not an accident.
For developers who ship Android apps, the answer is dull. Register your package names now, through Play Console if you have one or the Android Developer Console if you don't. It costs $25 and a photo of your license. If you distribute through F-Droid, make your build reproducible so the F-Droid copy carries your signature. If you have users in the four launch countries, test the install path on a device there next week, because that is where the behavior changes first.
For F-Droid users, 2.0 is the best version of the app that has shipped. It installs in one tap and updates without asking. On October 1 in São Paulo or Jakarta, a new user will need a laptop and ADB, or a day of waiting, to get it onto a phone.
My prediction: Google ships 2027 global enforcement on schedule, the advanced flow survives because the EU makes removing it expensive, and F-Droid's install base shrinks anyway. A 24 hour wait is a wall for anyone who is not already a believer. The apps will still be there. Fewer people will find them.