Play Console permission declaration checker

Paste your AndroidManifest.xml, or the output of aapt2 dump permissions for your built APK. Every permission is listed, and the ones that may need a Google Play Console declaration come first, with what Google expects and what to do. It runs in your browser: nothing is uploaded.

Runs in your browser. Nothing you paste is uploaded or stored.

Why check the merged manifest, not just yours?

Every library you add brings its own manifest, and the build merges them into yours. That is how an app ends up asking for a permission nobody on the team typed: an ads SDK can add the advertising ID, an updater or file-opening library REQUEST_INSTALL_PACKAGES, a notification or scheduling library exact alarms. Google reviews the merged result.

To see the list your users will actually get:

  • Android Studio: open AndroidManifest.xml and click the Merged Manifest tab at the bottom of the editor. It also shows which library each line came from.
  • The built APK: run the command below and paste its output here.
aapt2 dump permissions app-release.apk

How do I remove a permission a library added?

Declare the same permission in your own manifest with tools:node="remove". The merge then drops it, whichever library asked for it. This works the same in native, Flutter and React Native projects (the file is android/app/src/main/AndroidManifest.xml in the last two).

<manifest xmlns:android="http://schemas.android.com/apk/res/android"
    xmlns:tools="http://schemas.android.com/tools">

    <uses-permission android:name="android.permission.QUERY_ALL_PACKAGES"
        tools:node="remove" />
</manifest>

In an Expo project, list it under android.blockedPermissions in your app config, which does the same thing at prebuild:

{
  "expo": {
    "android": {
      "blockedPermissions": ["android.permission.QUERY_ALL_PACKAGES"]
    }
  }
}

Then test whatever that library does. If it needed the permission, the feature may stop working, and the choice is between the feature and the declaration.

What can't this checker tell you?

Whether your use of a permission qualifies. Google restricts most of these to particular kinds of app, and only its review decides whether yours is one. The checker also reads only what you paste, so it cannot see what your app's SDKs collect, which API level the build targets, or whether keys were left inside it.

For those, run the free check on your built APK: it reads the merged manifest, the target API level, the SDKs that feed your Data Safety form, and looks for leaked keys.

Common questions

Which Android permissions need a Play Console declaration?
The sensitive ones Google restricts to particular kinds of app: background location, all-files access, SMS and call log, QUERY_ALL_PACKAGES, REQUEST_INSTALL_PACKAGES, exact alarms, full-screen intents, photo and video access, foreground service types and the advertising ID, among others. Whether yours is allowed depends on what your app does, which only Google's review decides.
Why does my app have a permission I never added?
Libraries bring their own manifests, and the build merges them into yours. Check the merged manifest in Android Studio, or run aapt2 dump permissions on the built APK, to see the full list.
How do I remove a permission a library added?
Declare it in your own manifest with tools:node="remove", or in Expo list it under android.blockedPermissions. Then test the feature that library provides, because it may have needed that permission.
Is my manifest uploaded anywhere?
No. The checker runs in your browser and the text you paste is never sent to a server.

Sources

May we use analytics and ad measurement? Analytics (Vercel, and Ahrefs on our public pages) count page views without cookies. Ad measurement lets Google's tag on our public pages see which visits came from our Google ads, using a Google cookie. The site works the same either way. Cookie Policy · How Google uses data ·