After reading this post apksigner ignoring java parameters when trying to include azure keyvault jca, I've tried to setup APK Signing using Azure Key Vault.
I'm wrapping the apksigner command call described in the post above into Python and passing the arguments to the command line:
cmd = [
apksigner_path,
"sign",
"--ks", "NONE",
"--ks-type", "AzureKeyVault",
"--ks-key-alias", key_name,
"--ks-pass", "pass:",
"--ks-provider-class", "com.azure.security.keyvault.jca.KeyVaultJcaProvider",
"--rotation-min-sdk-version", "28",
"--provider-class", "com.azure.security.keyvault.jca.KeyVaultJcaProvider",
"--v",
"-in", unsigned_apk,
"-out", signed_apk,
f"-J--module-path={azure_jca_jar}",
"-J--add-modules=com.azure.security.keyvault.jca",
f"-J-Dazure.keyvault.uri={keyvault_uri}",
f"-J-Dazure.keyvault.tenant-id={tenant_id}",
f"-J-Dazure.keyvault.client-id={client_id}",
f"-J-Dazure.keyvault.client-secret={client_secret}"
]
result = subprocess.run(cmd, capture_output=True, text=True)
However, when I issue the apksigner command, I get this error message:
Failed to load signer "signer #1": NONE entry "APK-Signing" does not contain a key
It looks like contacting Azure Key Vault works:
Nov 10, 2025 3:24:38 PM com.azure.security.keyvault.jca.implementation.KeyVaultClient
INFO: Using Azure Key Vault: https://.vault.azure.net
Nov 10, 2025 3:24:38 PM com.azure.security.keyvault.jca.implementation.utils.AccessTokenUtil getLoginUri
INFO: Getting login URI using: https://.vault.azure.net/certificates?api-version=7.1
Nov 10, 2025 3:24:38 PM com.azure.security.keyvault.jca.implementation.utils.AccessTokenUtil getLoginUri
INFO: Obtained login URI: https://login.microsoftonline.com/c71a16b0-e886-4269-a23c-e7b10efc22e7
Nov 10, 2025 3:24:38 PM com.azure.security.keyvault.jca.implementation.utils.AccessTokenUtil getAccessToken
INFO: Getting access token using client ID / client secret
Failed to load signer "signer #1": NONE entry "APK-Signing" does not contain a key
To me, it looks like apksigner is still looking for some kind of keystore ('NONE' is passed to '--ks' option) and tries to look for my key 'APK-Signing' in it rather than on Azure Key Vault.
Can you help me work out what's going on? Thanks.