Open-source project
ImranR98/Obtainium avatar
ImranR98/Obtainium

Obtainium: installing and updating Android apps straight from their release pages

Get Android app updates straight from the source. Obtainium Get Android app updates straight from the source.

19,969 stars609 forksDartGPL-3.0

At a glance

What is it?
Obtainium is a Flutter Android app that tracks release pages such as GitHub, GitLab and F-Droid and notifies you when a new build appears. It solves one narrow problem well, but its scraping-based sources are the part to watch.
Who is it for?
Adopt Obtainium if you already sideload APKs and want update notifications from release pages that F-Droid does not index, and if you accept that some sources are scraped and can break. Skip it if you want a curated catalogue, reproducible builds for everything you install, or automatic updates without granting install permission.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 16 days ago.
What is it written in?
Mainly Dart, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The gap Obtainium fills between app stores and release pages

Android has an update mechanism, but it only works for apps installed from a store that manages them. When a developer publishes an APK on a GitHub releases page, nothing on the phone watches that page. You find out about a new version when you happen to look. Obtainium exists to close that gap: it adds an app by its source URL, polls the source, and notifies you when a new release appears, then installs the downloaded APK.

The audience is narrow and specific. It is for people who already sideload, who run apps that are not on Google Play, and who prefer the developer's own build over a store's repackaged one. The README frames the motivation with a video titled "You should use this instead of F-Droid", which tells you the intended user is someone who wants a newer version than the F-Droid catalogue carries, or an app F-Droid does not carry at all. It is not for someone who wants a curated catalogue with human review behind every entry.

How Obtainium resolves a source URL into an installable APK

The core of the app is a set of source handlers. The README lists them by name: GitHub, GitLab, Forgejo (including Codeberg), F-Droid, third party F-Droid repos, IzzyOnDroid, SourceHut, then a second group covering APKPure, Aptoide, Uptodown, itch.io, Huawei AppGallery, Tencent App Store, vivo App Store, RuStore, Farsroid, Samsung Galaxy Store, LiteAPKs, APK4Free, CoolApk, SourceForge, Jenkins jobs, APKMirror, APKCombo and RockMods, plus app-specific handlers for the Telegram app and Neutron Code. There is also a Direct APK Link handler and an "HTML" fallback that takes any URL returning a page with links to APK files.

That list is the architecture in miniature. Where a host exposes a structured interface, the handler reads it. Where it does not, the handler parses HTML. The README states the consequence plainly under Limitations: "For some sources, data is gathered using Web scraping and can easily break due to changes in website design." Two entries in the source list are marked Track-Only, APKMirror and RockMods, meaning Obtainium can watch them but the README does not present them as install sources.

The HTML fallback is the most fragile path and also the most general one. It will accept almost any page that links to APKs, which is useful for a self-hosted build server and unreliable for a large commercial site that redesigns its markup. If you add an app through that handler, treat the configuration as something that will need revisiting.

Installing Obtainium and adding your first app

The README points to three distribution channels: the GitHub releases page, the IzzyOnDroid repository, and F-Droid. The package ID is dev.imranr.obtainium, and the README gives a SHA-256 hash of the signing certificate, noting that the same signature is valid for the F-Droid flavour because of reproducible builds. That hash is worth checking before you trust an APK from anywhere else.

On a device with F-Droid already installed, the simplest route is to add the app from the F-Droid listing. The README does not document an adb or command-line install, so there is no command to copy here; if you install the APK manually, the package ID to look for afterwards is dev.imranr.obtainium.

From there, adding an app means giving Obtainium a source URL. The README's own example of that flow is a releases page for a project you want to track. Paste the URL into the add field, and Obtainium picks the matching handler and shows the available releases. You choose the one to install, and it downloads and hands the APK to the Android installer.

For apps already configured by other users, the README points to a crowdsourced configuration site at apps.obtainium.imranr.dev. Configurations can also be shared as deep links, which the wiki documents, and the README notes you can add a badge to your own project so users can import it in one tap. If your app is not in the crowdsourced list, the README says to open a request on that site's issues page.

Where Obtainium breaks, and when it is the wrong tool

The README names one limitation, and it is the important one: scraping breaks when a site changes its design. That failure is not graceful in the sense of falling back to a working method. The README says "more reliable methods may be unavailable", so for a scraping-based source there is often no fallback at all. You get an app that silently stops finding new releases, which is worse than an error, because you may not notice for weeks.

A second constraint follows from how Android works rather than from Obtainium's code. Installing an APK requires the install permission, and updating an app installed from one source with a build from another can fail on signature mismatch. If you installed an app from F-Droid and then point Obtainium at the developer's GitHub release, the signatures will not match unless the project signs both the same way. Obtainium cannot paper over that. The README's note that its own F-Droid flavour shares a signature with the GitHub build is an exception, not the rule, and it exists because that project builds reproducibly.

There is also a trust question the app does not answer. Obtainium verifies that a file came from the URL you configured. It does not tell you whether that URL is the right place to get the app. The README links to a separate verification tool, "Verified Apps", and recommends it, which is an implicit acknowledgement that source selection is the user's problem.

Obtainium compared with F-Droid as an update channel

F-Droid and Obtainium solve overlapping problems with opposite methods. F-Droid is a catalogue: a build server compiles apps from source, signs them with F-Droid's key, and serves a signed index. Updates arrive through that index, and the trust model rests on F-Droid's review and its signing infrastructure. The trade-off is latency and coverage. An app has to be in the catalogue, and it has to be built by F-Droid's infrastructure before you see the update.

Obtainium inverts this. There is no catalogue of reviewed builds and no central signing. It reads the developer's own release page and installs the developer's own artefact, so you get the update as soon as it is published and you get exactly what the developer shipped. The cost is that nothing sits between you and that artefact, and the mechanism that finds it may be a scraper. For a GitHub-hosted project with a stable releases interface this is a reasonable trade. For a source reached through the HTML fallback, you are relying on page markup that nobody promised to keep stable.

The two are not mutually exclusive. You can run F-Droid for the apps it covers and Obtainium for the ones it does not, which is close to what the README's framing suggests.

Licence, maintenance and what upgrading costs you

Obtainium is GPL-3.0. For someone installing the app, that changes nothing about use. For someone who wants to fork it or ship a modified build, the copyleft terms apply to the distributed result, and the repository includes a LICENSE.txt at the top level along with sign.sh and build.sh, so the build and signing path is visible rather than hidden. If you are evaluating it for redistribution inside a product, read the licence text rather than this summary.

The repository is not archived. The last push was on 2026-08-29, which is recent, and the release history shows v1.6.12, v1.6.13 and v1.6.14 within the same week in August 2026. That pattern suggests active release work, though the version numbers moving in small increments also suggests incremental fixes rather than large changes.

Upgrade cost is low for the user and potentially higher for the maintainer. The app updates itself through the same mechanism it uses for everything else, so staying current is a matter of accepting the notification. The maintenance burden sits with whoever keeps the source handlers working, because every host that changes its page layout is a handler that needs attention. The repository layout includes a test directory and an integration_test directory, which indicates the project has some automated coverage for those handlers, but the README does not describe how handler breakage is detected in practice.

Editorial conclusion

Adopt Obtainium if you already sideload APKs and want update notifications from release pages that F-Droid does not index, and if you accept that some sources are scraped and can break. Skip it if you want a curated catalogue, reproducible builds for everything you install, or automatic updates without granting install permission. Before committing, verify the signing certificate hash against the README value, test one GitHub app end to end, and check whether your target app is served by a scraping source or a structured interface.

Frequently asked questions

What is Obtainium?

Obtainium is an Android app that installs and updates apps directly from their releases pages and notifies you when new releases appear. It supports sources including GitHub, GitLab, Forgejo, F-Droid, IzzyOnDroid, SourceHut and several app stores. It is licensed GPL-3.0.

Which is better, F-Droid or Obtainium?

They use different methods rather than competing on the same axis. F-Droid serves a curated catalogue of builds signed by its own infrastructure, while Obtainium reads the developer's release page and installs the developer's artefact. The README links to a video arguing for using Obtainium instead of F-Droid, and the two can be run side by side for different apps.

How do I install Obtainium on Android?

The README points to three channels: the GitHub releases page, the IzzyOnDroid repository, and F-Droid. The package ID is dev.imranr.obtainium, and the README publishes a SHA-256 hash of the signing certificate you can check against a downloaded APK.

How do I use Obtainium to add an app?

You give Obtainium the URL of the app's releases page, and it selects the matching source handler and lists available releases for you to install. Crowdsourced configurations for many apps are available at apps.obtainium.imranr.dev, and configurations can also be imported through deep links.

Is Obtainium emulation legal?

The README and the source list do not address emulation. Obtainium is an Android app for installing and updating apps from release pages, and the project documentation does not describe any emulation feature, so this question cannot be answered from what the project publishes.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/imranr98-obtainium.svg)](https://hysenlabs.com/projects/imranr98-obtainium)