How to install an APK safely on Android
Installing an app from outside the Play Store is routine, but a few of the steps are easy to get wrong. Here is the order to do them in.
Written by The in7club team
Published · Updated · 6 min read
Sideloading — installing an Android app from a file rather than the Play Store — is a normal thing to do, and Android supports it directly. The risk is not the act itself; it is where the file came from and what you allow it to do afterwards.
Before you download
Check who is distributing the file. A link from the publisher's own site or their official channel is the one you want. A link from an aggregator that has repackaged the app is not, because repackaging means the file no longer matches what the publisher signed. Download buttons on in7club lead to the operator's own page for exactly this reason.
The settings to change
Android does not have one global 'allow unknown sources' switch any more. Permission is granted per app, to whichever app is doing the installing — usually your browser.
Open Settings, then Apps.
Find Special access, then Install unknown apps.
Pick the browser you downloaded with.
Turn on Allow from this source, and turn it back off when you are done.
After it installs
Open the app's permission list before you open the app itself. Storage and network access are expected. Contacts, SMS and precise location are not, for a card game, and an app that asks for them is worth deleting. Read that list yourself, every time: we do not test the apps we list, so nobody has read it on your behalf.
Four common mistakes
Leaving 'install unknown apps' switched on for the browser permanently.
Installing a file that is much smaller than the listed size — usually a downloader stub, not the app.
Ignoring a signature warning on an update, which means the new file was signed by someone else.
Granting every permission at first launch without reading them.