| name | google-play-setup |
| description | Set up Google Play Console, create an Android app listing, configure EAS credentials for Android builds, and set up the service account for CI/CD submissions. Use when publishing a new Android app, setting up Play Store automation, or troubleshooting AAB uploads. |
Google Play Setup
Prerequisites
- Google Play Console account ($25 one-time fee) at play.google.com/console
- EAS CLI:
npm install -g eas-cli && eas login
Required reading — Expo official guides:
Step 1: Configure Android Package Name
Set the package name in app.json before the first build — it cannot be changed after the app is published:
{
"expo": {
"android": {
"package": "com.yourorg.appname"
}
}
}
Use reverse domain notation. Must be globally unique on Play Store.
Step 2: Create Play Console App Listing
- Go to play.google.com/console → Create app
- Fill in:
- App name: Display name
- Default language: English
- App or game: App
- Free or paid: your choice
- Accept policies → Create app
Note the Application ID from the URL: play.google.com/console/u/0/developers/.../app/XXXXXXXXXXXXXXXXXX/
Step 3: Complete App Setup Requirements
Google requires these before you can upload any build:
App content declarations (Play Console → Policy → App content):
Store listing (Play Console → Grow → Store presence → Main store listing):
None of this blocks the first upload but it does block publishing to users.
"Finish setting up your app" banner — Play Console shows this dashboard banner after app creation. It lists required items before you can publish. Work through them in order — all must be green before the app goes live. This is separate from the store listing itself.
Step 4: Configure EAS Credentials
cd mobile
eas credentials
Select Android → production → Let EAS manage the keystore (recommended).
EAS generates and stores the Android signing keystore. Never lose this keystore — you cannot update your app without it. EAS stores it encrypted.
To verify:
eas credentials --platform android
Step 5: First Build and Manual Upload
Google requires the very first AAB to be uploaded manually via Play Console. Subsequent uploads work via eas submit.
cd mobile
eas build --platform android --profile production
eas build:list --platform android
eas build:download --platform android --latest
Upload manually:
- Play Console → Release → Internal testing → Create new release
- Upload the downloaded
.aab file
- Add release notes → Save → Review release → Start rollout
After this first manual upload, eas submit will work for all future releases.
Sharing the internal testing link — Unlike TestFlight (email invites), Google Play internal testing uses a shareable opt-in link. After rollout:
- Play Console → Testing → Internal testing → Testers tab
- Copy the opt-in URL and send it to testers
- Testers open the link on their Android device and click "Accept invitation"
They won't find the app by searching — they must use the link.
Step 6: Service Account for CI/CD
Required for non-interactive submissions from GitHub Actions.
Create service account:
- Play Console → Setup → API access
- Click Link to a Google Cloud Project (or create new)
- In Google Cloud Console: IAM & Admin → Service Accounts → Create Service Account
- Name:
eas-submit
- Role: Skip (add via Play Console)
- Click the service account → Keys → Add Key → Create new key → JSON
- Download the JSON file
Grant Play Console permissions:
- Back in Play Console → Setup → API access
- Find the service account → Manage Play Console permissions
- Grant: Release manager (minimum) or Admin
- Apply and save
Add to EAS:
eas secret:create --scope project --name GOOGLE_SERVICE_ACCOUNT_KEY --value "$(cat service-account.json)"
Or store locally and reference in eas.json:
{
"submit": {
"production": {
"android": {
"serviceAccountKeyPath": "./google-services.json",
"track": "internal",
"releaseStatus": "draft"
}
}
}
}
Step 7: Submit via EAS
After the first manual upload and service account setup:
eas submit --platform android --profile production --latest
This uploads to the internal testing track with draft status by default. You manually promote to production in Play Console.
Track Strategy
| Track | Who sees it | When to use |
|---|
| Internal | Up to 100 testers (your team) | Every build for QA |
| Closed testing (Alpha) | Invited users | Beta before launch |
| Open testing (Beta) | Anyone who opts in | Public beta |
| Production | All users | Launch |
Start with Internal track. Promote builds through tracks in Play Console — no rebuild needed.
Gotchas
"Package name already taken" — The package name is globally unique. Use a specific reverse domain.
Upload rejected: "Version code already used" — Always use appVersionSource: "remote" + autoIncrement: true in eas.json.
"You need to upload an AAB first" — You must manually upload the very first build. eas submit will fail until then.
Service account upload fails with 403 — The service account needs Release manager or Admin permissions in Play Console (not just Google Cloud IAM). Check Play Console → API access → service account permissions.
"App not found" during submit — The applicationId in eas.json must exactly match the package name in app.json and Play Console.
Data safety form blocks publishing — Fill it in Play Console → Policy → App content → Data safety. Must declare all data collected (Supabase auth = email/user ID, PostHog = device info).
First submission review takes 3–7 days — Build your buffer into the timeline. Subsequent updates usually review in hours.
Camera/microphone/location access requires a public Privacy Policy URL — Google will reject or unpublish apps that request sensitive permissions without a publicly accessible privacy policy. The URL must be reachable without login.
Data safety form blocks publishing — Fill it in Play Console → Policy → App content → Data safety. Must declare all data collected (Supabase auth = email/user ID, PostHog = device info, camera = photos if saved).