How to test Android restore keys in Android Studio before April 2027
From April 2027, Google Play judges zero-tap sign-in by one thing: whether your app retrieves its restore key on a new device. Android Studio can back up an app and restore it onto an emulator, so you can test this without a second phone. Every fact below was checked on its linked Google page on 10 October 2026.
For the server side, Play Restore Keys checks your setup for free (10 checks a day, no account). It does not test your app.
What Google checks
Google's technical quality requirements say: "Successful user sign in restoration is determined through the successful restore key retrieval." A restore key is what Google's code calls a Restore Credential. Your test should end with the app signed in on the restored device without the user doing anything.
What you need
- Android Studio Otter (2025.2.1) or later.
- An Android Studio emulator with Google Play services and Android 9 or later. A second emulator lets you test a move to a separate device.
- A debug build of your app (
debuggable true). - For the Cloud backup test, set
android:allowBackuptotruein your manifest, as Google recommends. Withfalse, Android Studio restores the sign-in only for Device to Device backups. - Your app already creates a restore key after sign-in and retrieves it on first launch, as in Google's implementation guide.
Back up the signed-in app
These steps follow Google's Test Restore Credentials page.
- Run your app on the emulator.
- Sign in with any method your app offers: password, passkey or Sign in with Google.
- In the running device window, click Backup App Data.
- For the backup type, choose Device to Device or Cloud, then click OK.
Restore and check the sign-in
- Same emulator: uninstall and reinstall the app, which clears its data. Second emulator: install the app there.
- Google's page then has you open the app before restoring: it shows your sign-in screen because the restore key is not on the device yet. If your app looks for the key only on its very first launch, skip this step.
- In the running device window, click Restore App Data and pick the backup you just made.
- Open the app again. It should sign you in with the restore key.
Run the test twice, once with each backup type. A key created with cloud backup off cannot be retrieved after a restore from a cloud backup, so users who restore that way are not signed in. Google's implementation guide recommends creating the key with isCloudBackupEnabled set to true.
What the emulator test does not show
Android Studio simulates the new-phone setup step. On a real phone, Google's overview adds conditions your test may not hit:
- Cloud backup needs the user to be signed in to a Google Account, to have Android backup on and to have a screen lock. Without them, creating the key with cloud backup throws
E2eeUnavailableException. Create it again with cloud backup off, so the key can still move by a direct transfer from the old phone. - A restore key covers one account per app. If users can sign in to several, pick the main or most recent one.
- On a phone with a work profile and a personal profile, the key is only available to the profile set up first.
- Restore keys need Android 9 or later, Google Play services core 24220000 or later and
androidx.credentials1.5.0 or later.
Checklist before April 2027
- The app creates the restore key after each sign-in, with cloud backup on.
- If that throws
E2eeUnavailableException, the app creates the key again with cloud backup off. - On first launch, the app retrieves the key and your server checks it, much like a passkey sign-in.
- Signing out, or your server ending the session, deletes the key with
clearCredentialState. - The Android Studio test passes with a Device to Device backup and with a Cloud backup.
If your app uses Firebase Authentication, read what Firebase apps need for the rule. Firebase has no restore key server of its own. For other Google Play, Firebase and Apple dates up to October 2027, see the app store deadline list.
Check your setup for free
Play Restore Keys reads your package name, signing fingerprints and domain. It checks the assetlinks.json file on that domain and gives you the file to publish, the server endpoints to build, the app calls and a checklist. It has 10 free checks a day and needs no account. Nothing you enter is stored. It does not test your app and is not a Google Play compliance review.