REQUEST_INSTALL_PACKAGES on Google Play
Checked against Google's policy pages on .
- android.permission.REQUEST_INSTALL_PACKAGES
What does it allow?
REQUEST_INSTALL_PACKAGES lets an app ask the system to install another package, such as an APK the user downloaded. The user still confirms each install, and must also allow the app to install unknown apps in settings.
Which apps does Google Play allow to use it?
Google Play restricts it to apps whose core functionality involves sending, receiving or installing app packages at the user's request. Its examples: web browsing or search, communication services that support attachments, file sharing, transfer or management, enterprise device management, backup and restore, and device migration.
It is prohibited for updating your own app outside Google Play, and for uses "not directly related to the core purpose of the app" (peer-to-peer sharing qualifies only when it is the app's core purpose). Apps that keep it also have to meet Google's prominent disclosure and consent rules.
Why is it in my app?
Play's own policy data (the same file the TestersWiz scanner uses) notes it is often merged in by an update or file-opening library: something that downloads a newer APK, or opens a downloaded file with the system installer.
To see every permission in your build and which ones may need a declaration, paste your merged manifest into the Play Console permission declaration checker.
What can I use instead?
For updates, use Google Play: your users already receive updates through the store, and the Play In-App Updates library can prompt them to update from inside the app without this permission.
If the library that added it opens downloaded files, check whether you use that feature at all; if not, remove the permission.
How do I remove it?
Add it to your own manifest with tools:node="remove". The manifest merge then leaves it out, whichever library declared it. In Flutter and React Native the file is android/app/src/main/AndroidManifest.xml.
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
xmlns:tools="http://schemas.android.com/tools">
<uses-permission android:name="android.permission.REQUEST_INSTALL_PACKAGES" tools:node="remove" />
</manifest>In Expo, block it in your app config instead:
{
"expo": {
"android": {
"blockedPermissions": [
"android.permission.REQUEST_INSTALL_PACKAGES"
]
}
}
}Then test the feature the library provides: if it needed the permission, that feature may stop working.
How do I declare it if I keep it?
If installing packages is a core feature of your app, complete the Permissions Declaration Form in Play Console, and update it if your use changes.
Common questions
- Can I use REQUEST_INSTALL_PACKAGES to update my app?
- No. Google's policy prohibits using it to update your app or change its functionality outside Google Play. Use Play's in-app updates instead.
- I never added REQUEST_INSTALL_PACKAGES. Where did it come from?
- Almost certainly a library's manifest, merged into yours. The Merged Manifest tab in Android Studio shows which one, and tools:node="remove" takes it out.
Read next
USE_FULL_SCREEN_INTENT on Android 14 and Google Play
Notifications that take over the screen. Granted by default only to calling and alarm apps.
Foreground service types and the Play Console declaration
FOREGROUND_SERVICE_* types. Each needs a Play Console description and video on Android 14+.
The AD_ID permission and the Advertising ID declaration
The advertising ID. Usually added by an ads or analytics SDK; needs matching Play Console answers.