Play Console permission declaration checker
Paste your AndroidManifest.xml, or the output of aapt2 dump permissions for your built APK. Every permission is listed, and the ones that may need a Google Play Console declaration come first, with what Google expects and what to do. It runs in your browser: nothing is uploaded.
Runs in your browser. Nothing you paste is uploaded or stored.
Why check the merged manifest, not just yours?
Every library you add brings its own manifest, and the build merges them into yours. That is how an app ends up asking for a permission nobody on the team typed: an ads SDK can add the advertising ID, an updater or file-opening library REQUEST_INSTALL_PACKAGES, a notification or scheduling library exact alarms. Google reviews the merged result.
To see the list your users will actually get:
- Android Studio: open
AndroidManifest.xmland click the Merged Manifest tab at the bottom of the editor. It also shows which library each line came from. - The built APK: run the command below and paste its output here.
aapt2 dump permissions app-release.apkHow do I remove a permission a library added?
Declare the same permission in your own manifest with tools:node="remove". The merge then drops it, whichever library asked for it. This works the same in native, Flutter and React Native projects (the file is android/app/src/main/AndroidManifest.xml in the last two).
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
xmlns:tools="http://schemas.android.com/tools">
<uses-permission android:name="android.permission.QUERY_ALL_PACKAGES"
tools:node="remove" />
</manifest>In an Expo project, list it under android.blockedPermissions in your app config, which does the same thing at prebuild:
{
"expo": {
"android": {
"blockedPermissions": ["android.permission.QUERY_ALL_PACKAGES"]
}
}
}Then test whatever that library does. If it needed the permission, the feature may stop working, and the choice is between the feature and the declaration.
What can't this checker tell you?
Whether your use of a permission qualifies. Google restricts most of these to particular kinds of app, and only its review decides whether yours is one. The checker also reads only what you paste, so it cannot see what your app's SDKs collect, which API level the build targets, or whether keys were left inside it.
For those, run the free check on your built APK: it reads the merged manifest, the target API level, the SDKs that feed your Data Safety form, and looks for leaked keys.
Common questions
- Which Android permissions need a Play Console declaration?
- The sensitive ones Google restricts to particular kinds of app: background location, all-files access, SMS and call log, QUERY_ALL_PACKAGES, REQUEST_INSTALL_PACKAGES, exact alarms, full-screen intents, photo and video access, foreground service types and the advertising ID, among others. Whether yours is allowed depends on what your app does, which only Google's review decides.
- Why does my app have a permission I never added?
- Libraries bring their own manifests, and the build merges them into yours. Check the merged manifest in Android Studio, or run aapt2 dump permissions on the built APK, to see the full list.
- How do I remove a permission a library added?
- Declare it in your own manifest with tools:node="remove", or in Expo list it under android.blockedPermissions. Then test the feature that library provides, because it may have needed that permission.
- Is my manifest uploaded anywhere?
- No. The checker runs in your browser and the text you paste is never sent to a server.
Read next
Android permissions that need a Play Console declaration
One page per restricted permission: what it allows, who Google allows to use it, and what to use instead.
Google Play pre-launch checklist for 2026
What to check before your app goes live on Google Play in 2026: closed test, target API 36, permissions, Data safety, App content and keys in the APK.
How to fill in the Data safety form for the SDKs in your app
Google Play holds you to what every SDK in your app collects. How to list the SDKs in your build, read their disclosures, and answer the Data safety form.