What Breaks on GrapheneOS (and What Doesn't): The Honest Compatibility Guide

Banking apps, Google Wallet, Android Auto, games, battery — a scannable works/breaks reference for GrapheneOS in 2026, the named apps that block it, why, and the workarounds that actually help.

Share
App tiles streaming through a gate, a few deflected and glowing rust orange
Almost everything passes. The compatibility story on GrapheneOS is really about the specific few that don't — and why.

Most apps work. That's the short version, and it's worth saying first, because the internet will tell you GrapheneOS is a compatibility nightmare, and it mostly isn't. What actually breaks is narrow, specific, and predictable — and almost all of it traces back to one design decision by Google, not a limitation in GrapheneOS. This is the honest, specific version: exactly what fails, which named apps block it, why, and what actually works around it.

Key takeaways:

  • The large majority of apps run normally, including sandboxed Google Play, most banking apps, maps, streaming, social, and everything from the GrapheneOS App Store, Accrescent, and F-Droid.
  • Google Wallet tap-to-pay is the one hard, permanent break — it needs an attestation a non-certified OS can't produce.
  • A specific, knowable set of apps actively block GrapheneOS — GrapheneOS publishes the list. Most are a few banks, some government/ID apps, and a handful of others.
  • When an app blocks GrapheneOS, that's a developer policy choice, not a GrapheneOS defect — GrapheneOS supports a stronger attestation than the check they use.
  • Battery and performance are indistinguishable from stock. The trade-off is app-specific, not a general tax.

The 30-second answer: works vs. breaks

Category Status Notes
Calls, SMS, data, Wi-Fi, Bluetooth, camera ✅ Works Core phone functions are untouched
Sandboxed Google Play + Play Store ✅ Works Installs, updates, in-app purchases, push notifications
Most everyday apps (maps, social, streaming, ride-hail, productivity) ✅ Works Unmodified
Most banking apps ✅ Works Especially with sandboxed Play installed — but see the exceptions below
Battery life & performance ✅ Works Indistinguishable from stock once the same apps are restored
Signal, messaging, 2FA authenticator apps (most) ✅ Works Aegis/others fine; Authy is a known exception (see list)
Most games ✅ Works ~majority run fine; anti-cheat titles are the exception
Google Wallet tap-to-pay ❌ Permanent Needs Google-firmware attestation; no fix. Workarounds below
A specific list of apps (some banks, gov/ID apps) ❌ Blocked by the developer Named list below; changes over time
Android Auto ⚠️ Works with setup Needs sandboxed Play + sometimes extra tweaks
Anti-cheat games (some) ⚠️ Partial A minority refuse via Play Integrity
DRM 4K streaming (Widevine L1) ⚠️ Sometimes lower quality Edge case; check your specific app

If nothing in the ❌/⚠️ rows is a dealbreaker for you, you can stop reading and go install it. If something is, the rest of this explains exactly how bad it is and what you can do.


The one thing that causes almost all of it: Play Integrity

Nearly every "GrapheneOS breaks X" story comes back to a single Google system. Understanding it once explains the whole compatibility picture, so it's worth two minutes.

Google's Play Integrity API lets an app ask Google whether the phone it's running on is a "genuine, certified Android device." It returns a verdict at three levels — basic, device, and strong integrity, and each app decides which level it demands. An unlocked or custom OS that isn't certified by Google fails the stricter verdicts, which is why banking apps refuse to run and Google Wallet stops working on most custom ROMs. As one custom-ROM guide puts it, unlocking the bootloader — a prerequisite for flashing anything custom — automatically fails the stricter checks.

Here's the part the copy-paste articles get wrong. GrapheneOS re-locks the bootloader with its own keys and has full verified boot, so it isn't an "unlocked, modified" device in the way a rooted phone is. GrapheneOS's position, documented in their attestation compatibility guide, is that any app can support GrapheneOS by using Android's standard hardware attestation API and allow-listing GrapheneOS's official verified-boot keys — and that hardware attestation is a stronger check than Play Integrity, because it verifies the OS against a hardware-backed key rather than asking Google's servers whether the device is on an approved list.

So when a banking app blocks GrapheneOS, it's not that GrapheneOS can't prove it's secure. It's that the developer chose to trust Google's certified-device list instead of the hardware attestation that would confirm it. GrapheneOS is blunt about what's going on: the apps enforcing stock-OS-only are protecting Google's business interests rather than security, since GrapheneOS keeps the full Android security model and reinforces it. That's a policy decision — which is why the same bank can work for one person and fail for another after an app update. The check is on the developer's side, and it moves.

The practical upshot: breakage isn't random. It's a specific set of apps that chose to enforce Google certification, and that set is small and largely known in advance.


The apps that actually block GrapheneOS

GrapheneOS maintains a public list of apps that ban it via Play Integrity — the single most useful reference before you switch, because it's specific and maintained by the people who track it. As of 2026 it includes, among others:

  • Finance / payments: Revolut, mada Pay (Saudi NFC payments), PostePay-style national wallets.
  • Government / digital ID: myGov (Australia), gov.br (Brazil), IO and PosteID/SPID (Italy), Singpass (Singapore), SwissID.
  • Insurance / health: several TK apps (TK-Doc, TK-Ident, TK-App — blocking access to German health-insurance features), BKK Faber-Castell & Partner.
  • Other consumer apps: Strava, Authy, TextNow, Ticketcorner, Dott, My SEAT and Volkswagen (car connectivity), and the McDonald's international app (in many, though not all, countries).

Two things about this list. First, it's the exceptions — the notable part is how short it is relative to the millions of apps that just work. Second, GrapheneOS's framing is deliberate: these apps could support GrapheneOS with a few lines using the hardware attestation API, and the reason they don't is Google-Mobile-Services licensing, not a real security or compatibility problem. GrapheneOS actively encourages users to file feedback asking these developers to allow it.

If an app you depend on is on that list, that's your dealbreaker to weigh — check the live version of the list before switching, since apps get added and removed.


Google Wallet tap-to-pay — the one permanent break

This is the genuine, unfixable one. Google Wallet's contactless payments need an attestation confirming official Google firmware, and a custom OS can't produce it, so Google Wallet tap-to-pay is not available on GrapheneOS. The NFC hardware works fine — it's specifically the Google Wallet payment path that's blocked, and no setting or workaround inside the phone changes that.

What actually works instead:

  • A smartwatch with its own payment app — Garmin Pay, or Google Wallet running on a separate Wear OS watch paired to the phone — handles contactless independently.
  • Your bank's own NFC payment feature, if it has one. Some banks ship a payment path that doesn't route through Google Wallet and works on GrapheneOS; many don't. This is bank-specific — check yours.
  • A physical card. Not a joke — for a lot of people the honest answer is that phone tap-to-pay is the only thing they lose, and a card in the wallet closes it.

Banking apps — mostly fine, with specific failure modes

Most banking apps work, especially with sandboxed Google Play installed. When one fails, it fails in one of a few recognizable ways, and knowing them saves you panic:

Geography matters more than people expect. German banking coverage is broad — major providers (ING, N26, DKB, Sparkassen, Volksbanken) install and run without preinstalled Google services. UK and US coverage is patchier. The name that comes up repeatedly as actively hostile is Revolut, which GrapheneOS has accused of specifically detecting and blocking its users — an ongoing back-and-forth, not a one-off.

The only reliable test is your own bank. Community lists like privsec.dev's banking-app compatibility page are a good starting point, but they're a snapshot of a moving target — verdicts change with app updates.


Games — most work, anti-cheat is the exception

Gaming is better than the reputation suggests. In one test of 50 games on a Pixel running GrapheneOS, the large majority ran flawlessly, a few needed minor workarounds, and only a handful failed outright — and the failures were the ones using strict Play Integrity for anti-cheat. If you play competitive titles with kernel-level or integrity-based anti-cheat, those are the ones at risk. Casual and most mainstream games are unaffected, and in-app purchases work through sandboxed Play.


Android Auto — works, with setup friction

Android Auto isn't a hard break, but it's not zero-effort. It relies on Google Play services, so it needs sandboxed Google Play installed and configured, and some car/phone combinations need extra tweaks or don't work cleanly. If in-car navigation is non-negotiable, test it specifically before switching rather than assuming.


The small stuff

  • DRM 4K streaming — a minority of apps that lean on hardware-backed DRM (Widevine L1) can drop to lower resolution. Edge case; check your specific streaming apps if phone-screen 4K matters to you.
  • Authenticator apps — most (Aegis, and others) are fine. Authy is a notable exception on the ban list; if you use it, migrate to a different authenticator before switching.
  • Work/MDM apps — corporate device-management apps sometimes enforce certification. If your employer mandates one, test it before committing a work phone.

What doesn't break

The list of things that just work is far longer and much less dramatic, which is why it gets ignored: sandboxed Google Play and the Play Store, the overwhelming majority of everyday apps, all core phone functions, and — importantly — battery life and performance, which the daily-driver consensus puts as indistinguishable from stock Pixel Android once you've restored the same apps and push services. A clean install often shows lower standby drain, not higher. For most people the daily experience is a normal, fast Pixel that happens to be dramatically more private.


Is it a dealbreaker for you? A 3-step check

Don't guess, and don't trust a stranger's list as gospel — check the things that matter to you, in this order:

  1. Your bank + any must-have app. Cross-check the GrapheneOS ban list, the privsec.dev list, and a search of the app name plus "GrapheneOS" on the community forum. Loud silence usually means it works.
  2. Contactless payments. If phone tap-to-pay is essential, accept that Google Wallet won't work and decide whether a watch, a bank's own NFC app, or a physical card covers you.
  3. Hardware-dependent apps — Android Auto, work MDM, anti-cheat games, DRM 4K. Test these specifically rather than assuming.

Most people run this and find nothing they can't live with. The rest find exactly one thing — usually tap-to-pay — and decide whether a smartwatch closes the gap. Two of these you can settle before you even own the hardware: whether your Pixel is supported, and what day-one setup looks like.


Frequently Asked Questions

Do banking apps work on GrapheneOS?
Most do, especially with sandboxed Google Play installed. A minority fail because the developer relies on Google's Play Integrity certified-device check rather than the hardware attestation GrapheneOS supports. It varies by bank and region and changes with app updates, so check your bank against GrapheneOS's ban list and the privsec.dev list before switching.

Why does my banking app say my device isn't secure?
Because it's checking Google's Play Integrity verdict, and a non-Google-certified OS fails the stricter levels — even though GrapheneOS has verified boot and supports a stronger hardware-backed attestation. It's the app developer's policy choice, not a security weakness in GrapheneOS. Watch out for apps that warn but keep working, then lock you out after a grace period.

Does Google Pay / Google Wallet work on GrapheneOS?
No, and it's permanent. Tap-to-pay through Google Wallet needs an attestation a custom OS can't produce. A smartwatch with its own payment app, a bank app with its own NFC path, or a physical card are the workarounds.

Can I play games on GrapheneOS?
Most games work, including in-app purchases through sandboxed Play. The exception is titles with strict anti-cheat that use Play Integrity — a minority — which may refuse to run.

Does Android Auto work?
Yes, with setup. It needs sandboxed Google Play installed and configured, and some car/phone combinations need extra tweaks. Test it before switching if it's essential.

Is battery life worse?
No meaningful difference from stock Pixel Android once the same apps are installed. Battery depends on screen time, signal, and background apps — not the OS.

Which apps are known to block GrapheneOS?
GrapheneOS publishes a maintained list. As of 2026 it includes Revolut, Strava, Authy, several government/ID apps (myGov, gov.br, Singpass, SwissID, Italy's IO/PosteID), some health-insurance apps, and others. Check the current list before switching, since it changes.


The bottom line

GrapheneOS breaks less than its reputation suggests, and what it does break is concentrated in one place: features and apps that depend on Google certifying the device rather than verifying it. Google Wallet tap-to-pay is the one hard loss. A short, published list of apps actively block it. Everything else — the actual daily use of the phone — is a normal, fast, full-battery Android experience with far better privacy.

If that trade sounds worth it, the install guide covers the switch and the first 24 hours covers the setup. For the wider context on why any of this matters, the complete Android privacy guide has the threat model behind it.

## Convertkit Newsletter