Sometimes you just can't.
For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.
The check seems to be purely store-based and never enforced later.
Same. Twint (basically the Swiss Venmo) insists that my phone is not compatible with it.
But using Aurora I can install it just fine and it works flawlessly.
This is exactly why I switched to Aurora. I couldn't even install Balatro from the Play Store.
I have similar problems installing region locked apps as someone who's fairly frequently in different regions.
Do you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with.
(for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)
Android apps are signed. Can't you verify the signature?
Can you?
I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store
Maybe not in practice, but in theory, it works. I don't think there's a better way of handling this without relying on some centralised authority (Google) to validate the authorship of an app, which is hardly desirable.
Doesn't AppVerifier allow you to do just that?
Doesn't Aurora download the packages directly from Google?
Presumably the parent does not want to have to trust Aurora to do that