Skip to content
Yoldaş
EN
Download

How to verify the SHA-256 hash of an APK file

A SHA-256 hash is a fingerprint of a file. Yoldaş publishes the hash of every version on the download page. If you calculate the same hash from the file you downloaded and compare the two, you know that the file you have is identical to the one that was published.

Last updated: October 6, 2026

Why verify it?

  • A damaged download: if the file downloaded only partly or with errors, the hash comes out different, so you notice before an install error appears.
  • A different file: you confirm that a file you brought in on a USB stick or in some other way is the published file.

The current hash value is published only on the download page. We do not write it in this guide so that it never goes out of date.

Step by step

  1. Find the published hash

    In the "File fingerprint (SHA-256)" box on the download page you will see a 64-character hash. You can copy it with the Copy button.

  2. Download the APK to your computer

    Download the APK only with the download button on that same page, and note where the file is saved.

  3. Calculate the hash

    Run the command that fits your computer (the commands are in the table below). The command prints a 64-character value.

  4. Compare the two values

    The calculated value and the value on the page must match letter for letter. Some tools print capital letters; ignore upper and lower case.

  5. Go on based on the result

    If the values match, you can install the file. If they differ, delete the file and download it again; if they still differ, do not install it and write to us.

Commands to calculate the hash

Replace the file name in the command with the name of your own file. Run the command in the folder where the APK is.

SystemCommand
Windows (PowerShell)Get-FileHash .\your-downloaded-file.apk -Algorithm SHA256
Windows (Command Prompt)certutil -hashfile your-downloaded-file.apk SHA256
macOSshasum -a 256 your-downloaded-file.apk
Linuxsha256sum your-downloaded-file.apk

What the hash shows and what it does not

  • It shows: that the file is the same as the file on the page where the hash is published.
  • It does not show: that the page itself is genuine. That is why you should get the APK and the hash only from yoldas.io, over HTTPS.

Updates also have their signature checked

All Yoldaş versions are signed with the same key. When Yoldaş updates itself, it checks the file's integrity, package name, version number and signature before installing; it never installs an older version as if it were new. Details are on the security page.

Advanced users who want to can compare the signing certificate of two versions with the apksigner verify --print-certs command from the Android SDK Build-Tools; because they are signed with the same key, the certificate information should come out the same.

Next step

Once the hash matches, you can install the file in the car: install an APK from a USB stick or the guide to installing apps on a BYD.

Frequently asked questions

What is a SHA-256 hash?

It is a 64-character fingerprint calculated from the contents of a file. If even a single byte in the file changes, the hash changes completely. The same file always gives the same hash.

What should I do if the hashes do not match?

Do not install the file. Delete it and download it again from the download page. If they still do not match, check your connection and that the address is yoldas.io; if the problem continues, write to us.

Can I verify the hash on the car screen?

The commands in this guide are for a computer. The easiest way is to download the APK on your computer, verify it there and then take it to the car on a USB stick.

Is there a hash for the phone app too?

No. The phone side is a web app, so there is no file to install. The hash is only for the car APK.

Other guides

Install Yoldaş in your car

Free during the pilot. Current version 0.12.26. See the steps in the install guide.