Volkswagen blocks GrapheneOS users via Play Integrity API

Volkswagen implements Play Integrity API to block custom ROMs

Volkswagen has officially blocked the use of its mobile applications on GrapheneOS and other custom Android ROMs. The company has implemented the Google Play Integrity API (formerly Play Integrity/SafetyNet), which verifies whether a device is running a certified Android build. Devices that fail this integrity check—such as those running GrapheneOS or LineageOS—are now unable to log into the official Volkswagen and SEAT apps.

Volkswagen Digital Services has confirmed this policy in correspondence with users, stating that the app relies on "security-relevant system components and certified Android standards to ensure reliable and secure use of our digital services." The company explicitly noted that custom ROMs are not part of the supported application environment and therefore will not receive technical support.

Impact on users and third-party integrations

The shift to strict integrity checks has created several critical failures for power users and privacy-conscious owners:

Loss of App Functionality

Users report that the apps now display errors such as "Login failed," "Connection failed," or "App is under maintenance." While some users initially found temporary workarounds by enabling Sandboxed Google Play and granting specific permissions (such as Contacts and Accounts) to Play Services, these methods have largely ceased to work as the integrity checks became more stringent.

Death of Community Integrations

Beyond the official app, the implementation of Play Integrity has effectively killed community-driven projects. Because the API check happens at the server level, unofficial Home Assistant integrations and other third-party tools that relied on the Volkswagen API are no longer functional for any user whose device is not Play Protect certified.

Cross-Brand Effects

This issue is not limited to the VW brand; users of the My SEAT app have reported identical failures and the same "under maintenance" error messages, indicating a shared backend infrastructure across the Volkswagen Group.

Community reaction and technical debate

The move has sparked significant backlash among technical users, leading to discussions about the "enshittification" of modern automotive software.

Privacy and Data Concerns

Critics argue that the requirement to use a certified Google environment to control a physical vehicle is an overreach. One user noted:

Do you really need a car app? You should be aware that modern cars carry a cellular modem and report extensive telemetry to the manufacturer, dealer, and possibly third parties.

Market Consequences

Several users on Hacker News and GrapheneOS forums indicated that this software restriction is a deciding factor in their vehicle purchasing decisions. Some reported canceling orders or switching to competitors (such as BMW) whose apps reportedly maintain better compatibility with custom ROMs.

The Security Argument

Some defenders of the practice argue that integrity checks are necessary to prevent malicious apps from intercepting credentials or remotely controlling vehicles. Others counter that this is less about security and more about shifting liability to Google, ensuring that Volkswagen only supports a narrow, certified ecosystem to avoid potential lawsuits related to unauthorized software modifications.

Summary of Technical Status

Feature Status on GrapheneOS
Official VW App Blocked (Play Integrity API)
Official SEAT App Blocked (Play Integrity API)
Community APIs Blocked (Server-side check)
Workarounds None currently effective

Sources