Accessibility settings

Text size

100%

IoT & Devices 5 min read

Sideloading

Also known as: app sideloading, sideloading apps, sideload APK, install unknown apps, unknown sources

Definition

Sideloading is installing an app from a source other than the device's official app store, for example an APK file from a website, an email or a cable. Android asks for permission for each source, and a company that manages the device can block it with a device policy.

Cite this entry

Text

"Sideloading". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/sideloading/

HTML

<a href="https://ordergroup.co/glossary/sideloading/">Sideloading</a> - Order Group

How sideloading works

Sideloading means installing an app without the device's official store: an APK downloaded in a browser, sent by email, copied from a USB stick or pushed from a computer over a cable. Android treats these installations as coming from unknown sources. Its documentation says the system blocks installations from locations other than a trusted, first-party app store until the user opts in.

How the user opts in depends on the Android version. On Android 8.0 (API level 26) and higher, permission is granted per source: the user enables "Allow app installs" for one specific app, such as a browser or a file manager, on the "Install unknown apps" settings screen. On Android 7.1.1 and lower there was one global "Unknown sources" switch, or the user could allow a single installation. The app that starts the installation must declare the REQUEST_INSTALL_PACKAGES permission, and because the user can withdraw consent at any time, it should check canRequestPackageInstalls() before each attempt.

Under the hood, every installer uses PackageInstaller. An app opens a session, streams one or more APKs into it and commits. Committing may require the user to confirm, unless the caller is the device owner or an affiliated profile owner, in which case the installation completes automatically. That is how MDM software installs apps on managed phones without asking anyone.

Android requires every APK to be signed with a certificate before it is installed or updated. When a new version arrives, the system compares its certificates with those of the installed app and allows the update only if they match. A sideloaded file with the right package name but a different key cannot replace an existing app. The signature shows who can update the app; it says nothing about whether the app is safe.

What sideloading means for your software

Every install route is a way onto the device. On a fleet of standard Android phones the MDM policy closes or controls each one; on your own device or operating system the installation path is part of the product. A specification has to cover each route:

  • Decide per ownership model. On a company-owned device the device owner can set DISALLOW_INSTALL_UNKNOWN_SOURCES, or the device-wide DISALLOW_INSTALL_UNKNOWN_SOURCES_GLOBALLY (API level 29), so the user cannot turn on unknown sources at all. On a personal phone with a work profile, the restriction covers the profile.
  • Know what the restriction does not cover. The Android reference states that it does not apply to installs started by registered app stores or to installing those stores, and that adb is not an unknown source. A stricter restriction, DISALLOW_INSTALL_UNKNOWN_SOURCES_INCLUDING_REGISTERED_APP_STORES, also blocks registered app stores; the reference lists it as added in version 37.2, so test the policy on the Android versions your fleet actually runs.
  • Close the cable route. A device with debugging enabled accepts apps from a computer. DISALLOW_DEBUGGING_FEATURES set by the device owner disables debugging, including USB debugging.
  • Make your own store the only registered app store. On your own OS build, decide which installer may install apps without prompts and keep that list in the system image, not in a setting the user can change.
  • Validate packages before publishing. The store backend checks the package name, signing certificate, version code and minimum SDK on upload, rejects what does not match and tells the publisher why in plain words.
  • Treat signing keys as production infrastructure. If the key is lost or compromised, no new version can be released as an update to the existing app.
  • Show permissions before install. A description of what the app may access, in non-technical language, lets the user or the administrator decide before the APK lands on the device.
  • Keep an inventory. The device reports installed apps, their versions and which installer put them there, so the console can spot an app that did not come from an approved source.
Ways an app reaches an Android device and how a company controls each one
RouteWho starts the installationUser confirmationHow the company controls it
Official storeThe store appStore install flowMDM allowlist or blocklist of apps
Registered app store of the company or device makerThe store app, often with system privilegesDepends on the installer's privilegesStore backend review, signing and SDK checks
APK from a browser, email or file managerThat app, after the user allows it as a sourceYes, per source on Android 8.0 and higherDISALLOW_INSTALL_UNKNOWN_SOURCES or its device-wide version
adb from a computerA developer machine over USBRequires debugging to be enabledDISALLOW_DEBUGGING_FEATURES
MDM pushThe device policy controller through PackageInstallerNone for the device ownerThe MDM console and its audit log

Rules and standards

In the EU, the Digital Markets Act, Regulation (EU) 2022/1925, applies from May 2, 2023 to large platforms designated as gatekeepers. The European Commission designated the first six gatekeepers on September 6, 2023 and gave them six months to comply, so Article 6(4) has bound them since March 2024. Article 6(4) requires a gatekeeper to allow and technically enable the installation and effective use of third-party apps and app stores on its operating system, and to let them be accessed by means other than its own platform services. The gatekeeper may still take measures that are strictly necessary and proportionate to protect the integrity of the hardware or operating system, and settings that help users protect their security, provided it justifies them. The obligation falls on the gatekeeper, not on a company that ships its own device or locks down its own fleet.

Google is adding a separate layer to Android. Its developer verification guides state that Android requires all apps to be registered by verified developers for users to install them on Android devices that ship with Google services, regardless of where the app is downloaded from. Sideloading stays possible: apps from unregistered developers go through an advanced flow with extra safeguards, and the adb workflow stays the same. The checks went live on September 30, 2026 for users in Brazil, Indonesia, Singapore and Thailand, and Google plans to expand them globally to all apps on such devices in 2027.

From our projects

For Raw Control we built RAW Secure Phone, a hardened Android-based phone system with its own app store, RAW Store, that offers only pre-approved apps. In October 2021 we fixed the message shown when RAW Store rejected an imported app built with too old an SDK. In November 2021, in the RAW OS system layer, we added blocking of installs from any source other than RAW Store. The client's request also covered installing apps from outside RAW Store on the Android side, and that part followed between December 2021 and January 2022; the client accepted it in January 2022.

For Mudita, our engineers work on the App Store for the Mudita Kompakt phone. In 2026 that work covered access to the App Store from the device (completed in March), APK upload for developers (April), a view of the APK scanner report (June) and non-technical descriptions of Android permissions (September). We did not build Mudita's operating system.

Sources

  1. Alternative distribution options: user opt-in for unknown apps and sources - Android Developers
  2. UserManager: DISALLOW_INSTALL_UNKNOWN_SOURCES and related restrictions - Android Developers
  3. PackageInstaller (Android API reference) - Android Developers
  4. Sign your app - Android Developers
  5. Android developer verification - Android Developers
  6. Android developer verification: guides - Android Developers
  7. Regulation (EU) 2022/1925 (Digital Markets Act) - EUR-Lex
  8. Digital Markets Act: Commission designates six gatekeepers (IP/23/4328) - European Commission

FAQ

Maciej Sułek
Maciej Sułek
Co-founder & CTO
Talk to an engineer
  • It depends on the source. Android checks that an update is signed with the same key as the installed app, but a signature only shows who can update an app, not that the app is harmless. On company devices, limit installs to sources you control.

  • Yes. On company-owned Android devices the device owner can block unknown sources for one user or for the whole device and disable debugging. Check how your Android version treats registered app stores, because the basic restriction does not cover them.

  • Article 6(4) applies to gatekeepers designated under the DMA, the largest platforms. A company that makes its own device or manages its own fleet is not a gatekeeper because of that, so it can decide which sources its devices trust.

  • Push them through your MDM, which installs as the device owner without prompts, or run your own store and make it the only registered app store. Either way, keep the signing key safe and log every install.

Building a system that depends on Sideloading?

See how we build software for this domain, with case studies and the stack we use.

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.

Your checklist is empty. Use the plus next to a term to add it.

    Order Group sp. z o.o. (Warsaw) uses your e-mail to send the checklist (Art. 6(1)(b) GDPR) and keeps a record of the request (Art. 6(1)(f) GDPR). Marketing consent is optional and can be withdrawn at any time. Read the Privacy Policy