Volkswagen blocks GrapheneOS users via Play Integrity API
Volkswagen implements Play Integrity API to block custom ROMs
Volkswagen has officially blocked the use of its mobile applications on GrapheneOS and other custom Android ROMs. The company has implemented the Google Play Integrity API (formerly Play Integrity/SafetyNet), which verifies whether a device is running a certified Android build. Devices that fail this integrity check—such as those running GrapheneOS or LineageOS—are now unable to log into the official Volkswagen and SEAT apps.
Volkswagen Digital Services has confirmed this policy in correspondence with users, stating that the app relies on "security-relevant system components and certified Android standards to ensure reliable and secure use of our digital services." The company explicitly noted that custom ROMs are not part of the supported application environment and therefore will not receive technical support.
Impact on users and third-party integrations
The shift to strict integrity checks has created several critical failures for power users and privacy-conscious owners:
Loss of App Functionality
Users report that the apps now display errors such as "Login failed," "Connection failed," or "App is under maintenance." While some users initially found temporary workarounds by enabling Sandboxed Google Play and granting specific permissions (such as Contacts and Accounts) to Play Services, these methods have largely ceased to work as the integrity checks became more stringent.
Death of Community Integrations
Beyond the official app, the implementation of Play Integrity has effectively killed community-driven projects. Because the API check happens at the server level, unofficial Home Assistant integrations and other third-party tools that relied on the Volkswagen API are no longer functional for any user whose device is not Play Protect certified.
Cross-Brand Effects
This issue is not limited to the VW brand; users of the My SEAT app have reported identical failures and the same "under maintenance" error messages, indicating a shared backend infrastructure across the Volkswagen Group.
Community reaction and technical debate
The move has sparked significant backlash among technical users, leading to discussions about the "enshittification" of modern automotive software.
Privacy and Data Concerns
Critics argue that the requirement to use a certified Google environment to control a physical vehicle is an overreach. One user noted:
Do you really need a car app? You should be aware that modern cars carry a cellular modem and report extensive telemetry to the manufacturer, dealer, and possibly third parties.
Market Consequences
Several users on Hacker News and GrapheneOS forums indicated that this software restriction is a deciding factor in their vehicle purchasing decisions. Some reported canceling orders or switching to competitors (such as BMW) whose apps reportedly maintain better compatibility with custom ROMs.
The Security Argument
Some defenders of the practice argue that integrity checks are necessary to prevent malicious apps from intercepting credentials or remotely controlling vehicles. Others counter that this is less about security and more about shifting liability to Google, ensuring that Volkswagen only supports a narrow, certified ecosystem to avoid potential lawsuits related to unauthorized software modifications.
Summary of Technical Status
| Feature | Status on GrapheneOS |
|---|---|
| Official VW App | Blocked (Play Integrity API) |
| Official SEAT App | Blocked (Play Integrity API) |
| Community APIs | Blocked (Server-side check) |
| Workarounds | None currently effective |