System app database

Package

com.google.android.rkpdapp

RemoteProvisioner

46device profiles
93observations
0user-facing hits
18 Sep 2026last seen

Guidance

Do not disable verified 7 Aug 2026

The Google-signed build of the Remote Key Provisioning Daemon (RKPD), labelled "RemoteProvisioner" on device. It is the same component this site documents under the AOSP-keyed name com.android.rkpdapp, shipped under a Google package name; the app still declares its internal broadcast permission under the com.android.rkpdapp namespace, which is consistent with one codebase built under two package names. AOSP places the app inside the Remote Key Provisioning Mainline APEX, stating that "The RKP Mainline APEX, com.android.rkpd, contains the Remote Key Provisioning Daemon (RKPD) application and a remote provisioning system server component". Its job is to obtain attestation certificates for the device's IRemotelyProvisionedComponent implementations, which is why it holds internet, network state and boot permissions and has no launcher entry. Remote Key Provisioning replaces the older model in which attestation keys were burned into a device at the factory. AOSP records that "Android 12 introduces Remote Key Provisioning, and Android 15 requires all devices to implement it", and that it "provides devices in the field with per app, ECDSA P256 attestation certificates" which "are shorter-lived than the factory-provisioned certificates". Android 14 is where RKP became an updatable Mainline module; before that the work was split between a RemoteProvisioner app and Keystore 2.0. Version note: the version dimension is the important part of this entry, and it continues past the Mainline change. Google's developer documentation states that "For devices that launch with Android 16, the system supports only RKP. This policy phases out factory keys", and describes this as "expanding on the Android 15 policy where RKP support was optional". Be aware that the two official pages describe Android 15 differently, and this note does not attempt to resolve the difference. AOSP says Android 15 "requires all devices to implement it", while the developer documentation calls Android 15 the release "where RKP support was optional". The most likely reading is that the two are talking about different things, one about a device supporting RKP at all and the other about RKP being the only mechanism, but that reconciliation could not be sourced and should not be relied on. What both pages agree on is the Android 16 position: on devices launching with Android 16, factory-provisioned attestation keys are out and RKP is the only route. That matches what this site records for this package name: the sample begins at version name 16 with a minimum target SDK of 35, and the newest observation carries a release codename rather than a version number, so this Google-namespaced variant is something seen on recent and preview firmware rather than across the whole history of RKP. The site's sample spans Crosscall, Fairphone, Google, OPPO, OUKITEL, OnePlus, URAO, Xiaomi, motorola, samsung and vivo devices, signed Google rather than by each maker's platform key, which distinguishes it from the AOSP-keyed variant. For Android Enterprise, EMM and kiosk fleets this is security infrastructure rather than a feature. The certificates it obtains are what hardware-backed key attestation chains up to, so anything that verifies device integrity or relies on hardware-backed keys depends on this pipeline working. Google also notes an operational consequence of the newer model that matters when troubleshooting: RKP certificates have a shorter validity period, and it is "critical" that verifiers "ensure that Remote Key Provisioning (RKP) certificates continue to have their validity period checked". Disabling or removing this package risks breaking attestation for every app on the device that uses it, and it offers no management benefit, so it should not be disabled.

Package intelligence

Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.

2
signing certs
OEM-forked / varies
10
permissions
largest set observed
1.1 MB – 1.3 MB
APK size
35 – 10000
target SDK
10000 = current beta API level
17 → 17
versions observed
29
device profiles
Declared permissions (10)

Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.

PermissionDescription
ACCESS_LOCAL_NETWORK -
ACCESS_NETWORK_STATE Allows the app to view information about network connections such as which networks exist and are connected.
FOREGROUND_SERVICE Allows the app to make use of foreground services.
INTERACT_ACROSS_USERS_FULL Signature-level system permission, for platform-signed apps.
INTERNET Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet.
QUERY_ALL_PACKAGES Allows an app to see all installed packages.
RECEIVE_BOOT_COMPLETED Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the phone and allow the app to slow down the overall phone by always running.
USE_LOOPBACK_INTERFACE -
WAKE_LOCK Allows the app to prevent the phone from going to sleep.
com.android.rkpdapp.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION -

Manage on devices

ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.

Disable for the current user
adb shell pm disable-user --user 0 com.google.android.rkpdapp
Remove for the current user - a per-user uninstall; the APK stays on /system, so Restore re-adds it (-k keeps app data)
adb shell pm uninstall -k --user 0 com.google.android.rkpdapp
Re-enable
adb shell pm enable com.google.android.rkpdapp
Restore (re-install for the current user)
adb shell pm install-existing com.google.android.rkpdapp

Seen on

Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.

OEMModelAndroidProvenanceObservationsLast seen
Crosscall Stellar-X5 Android 15 Google 1 23 Aug 2026
Fairphone Fairphone 6 Android 15 - 2 6 Nov 2025
Fairphone FP5 Android 15 Google 1 4 Aug 2026
Fezawio F11_V_US Android 15 - 1 14 Jul 2026
Google GMS on ARM64 Android 14 - 1 16 Sep 2025
Google Pixel 10 Pro Android 16 Google 1 26 Mar 2026
Google Pixel 10 Pro Android 17 Google 1 18 Sep 2026
Google Pixel 6 Android 16 - 1 13 Oct 2025
Google Pixel 6 Pro Android 15 - 9 23 Jun 2025
Google Pixel 7 Pro Android 16 Google 1 9 Mar 2026
Google Pixel 8 Android 16 - 4 3 Jun 2026
Google Pixel 8a Android 15 - 1 5 Oct 2025
Google Pixel 9 Pro XL Android 16 Google 21 29 Mar 2026
Google Pixel 9 Pro XL Android 17 Google 1 17 Sep 2026
Google Pixel 9a Android 15 - 1 15 Jun 2025
Google Pixel 9a Android 16 Google 6 2 Jun 2026
Google Pixel 9a Android 17 - 1 16 Jul 2026
Google sdk_gphone16k_arm64 Android 16 Google 2 6 Feb 2026
Google sdk_gphone64_arm64 Android 16 - 5 2 Dec 2025
Motorola moto g - 2025 Android 16 Google 1 14 Dec 2025
Motorola motorola edge 50 fusion Android 16 Google 2 10 Jun 2026
OnePlus CPH2465 Android 14 - 1 17 Jun 2025
OnePlus CPH2653 Android 16 - 1 24 Nov 2025
OnePlus KB2005 Android 14 - 1 17 Sep 2025
OPPO CPH2591 Android 15 - 1 10 Jul 2025
OPPO CPH2637 Android 15 Google 1 2 Feb 2026
OUKITEL C59 Pro Android 15 - 1 6 Nov 2025
Samsung SM-A266B Android 16 - 1 26 Jan 2026
Samsung SM-A536B Android 16 Google 1 29 Jul 2026
Samsung SM-A566B Android 16 Google 3 12 Sep 2026
Samsung SM-F766B Android 16 - 1 11 Nov 2025
Samsung SM-F971B Android 17 Google 1 18 Sep 2026
Samsung SM-G766B Android 16 Google 1 5 Sep 2026
Samsung SM-S731B Android 16 Google 1 11 Aug 2026
Samsung SM-S908U Android 16 Google 2 17 Sep 2026
Samsung SM-S921B Android 16 Google 1 17 Sep 2026
Samsung SM-S926B Android 16 Google 1 14 Apr 2026
Samsung SM-S928B Android 16 Google 2 12 Jun 2026
Samsung SM-S931B Android 16 - 1 23 Nov 2025
Samsung SM-S936B Android 16 - 1 18 Dec 2025
Samsung SM-S942B Android 17 Google 1 25 May 2026
Samsung SM-S948U Android 16 - 1 9 Sep 2026
TCL T517F Android 16 Google 1 8 Aug 2026
Urao X108 Android 16 Google 1 3 Jun 2026
vivo V2550 Android 16 Google 1 21 Jul 2026
Xiaomi 24117RN76O Android 16 Google 1 20 Mar 2026

Known labels

Locale-aware display names seen in the wild.

LabelLocaleSeen
RemoteProvisioner en-us 53
RemoteProvisioner en 41
RemoteProvisioner nl-NL 21
RemoteProvisioner en-gb 17
RemoteProvisioner it-IT 5
RemoteProvisioner 4
RemoteProvisioner nl-nl 4
RemoteProvisioner en-GB 4
RemoteProvisioner es-us 2
RemoteProvisioner en-US 2
RemoteProvisioner es-US 1
RemoteProvisioner es-mx 1
RemoteProvisioner it-it 1
RemoteProvisioner ja-jp 1
RemoteProvisioner pl-PL 1
RemoteProvisioner pl-pl 1
RemoteProvisioner vi-VN 1
RemoteProvisioner vi-vn 1
RemoteProvisioner cs-cz 1
RemoteProvisioner de-de 1
RemoteProvisioner en-ca-u-fw-mon-mu-celsius 1
RemoteProvisioner en-de 1
RemoteProvisioner en-lk 1
RemoteProvisioner en-mt 1
RemoteProvisioner en-pk 1
RemoteProvisioner en-us-u-fw-mon-ms-ussystem-mu-fahrenhe 1
RemoteProvisioner es-MX 1