FocusBottle has no accounts at all, which is exactly why I noticed how much of a week vanished into signing fingerprints for a product that does. Two of them are real. The one printed largest on the Play page is not.
The app with nothing to sign into
FocusBottle has no accounts. You open it, tap 25, 50 or 90 minutes, and a bottle fills with light that shifts while you work — nothing to configure, nothing to verify, nothing to remember. So it was a strange week I spent chasing login fingerprints for a different product of mine, the one where people genuinely do sign in.
The strangeness wore off fast. A fingerprint is the SHA-1 of whichever certificate signed the app sitting on a phone, and Google only hands out an id_token to a package name and signature it already knows about. Get it wrong and nothing dramatic happens. The account picker just never appears.
Two builds, two certificates
A development build and the build someone installs from Play are not signed by the same thing. The dev APK carries your own upload keystore — in an Expo project, the one EAS generated for you. The Play build is signed by Google with the deployment certificate, because Play re-signs whatever you hand it before it ever reaches a device.
So there are two fingerprints worth registering, and registering only one means the other build quietly cannot log in. In Google Cloud, one Android OAuth client holds both: edit the client, hit *+ ADD AN ITEM*, and add each SHA-1 in turn. That client does no verification work itself — it is a gate, confirming that the app asking for a token really is your package with your signature.
The decoy at the top of the page
The Play app-signing page leads with the *upload key certificate*, SHA-1 printed in full, and it looks precisely like the thing you went looking for. It is not. That key only shows Google which bundle you submitted; it is gone before a user's phone ever sees the app. The page also offers `hybrid_classical_cert.der` and `hybrid_pqc_cert.der` — same signing family, still not the file you need.
The file you need is `deployment_cert.der`, and it is usually the least eye-catching download on the page. Check the certificate the page actually installs from, not the certificate the page makes the most noise about.
Pulling each one, then proving it
The dev fingerprint is the easy half: EAS lists it in the project's credentials, `keytool -list -v -keystore <file> -alias <alias>` will print it from the keystore, or you can upload the APK and let the console read it out. The Play half means downloading the DER and hashing it yourself — `openssl x509 -inform DER -in deployment_cert.der -noout -fingerprint -sha1`. No openssl on the machine? Four lines of PowerShell around `SHA1.Create().ComputeHash` produce the identical colon-separated string.
Then stop trusting the screen and prove the chain: post a deliberately invalid token to your own auth endpoint. A 401 back means your server really did reach Google and attempt a match. FocusBottle has no login to test that way, and I have started reading that absence as the feature rather than the gap.