The Come install path follows the same device-side sequence every time. Below is each Android setting you will touch and the reason that setting exists, so a blocked install is not a guessing game. The verified package signature must match the published hash.
The four-step verified install path
Settings → Security
Open Settings, then Security. Android 13 hides this under "More settings" on some devices.
Allow this source
Toggle "Install unknown apps" for your browser. Android resets this per source after every install.
Download the verified package
Use the verified install path only. The package signature must match the published hash.
Verify and open
Open the package, confirm the install dialog and start the app. KYC begins on first open.
Troubleshooting matrix
Each row below pairs a real install symptom with the device-side setting that resolves it. The matrix is built from the same support tickets that pass through the Come support desk - every row is reproducible end-to-end on Android 7.0 and above.
| Symptom | Cause | Fix | Verify |
|---|---|---|---|
| Install blocked | Source toggle off | Settings → Apps → Special access | Re-run install |
| Parse error | Partial download | Re-download, check storage | Hash matches |
| Low storage | < 200 MB free | Clear app cache | Install completes |
| Signature mismatch | Wrong package source | Use verified route only | App opens to lobby |
| App won't open | Android version | Confirm Android 7.0+ | Lobby renders |
What the verified package signature proves
The package signature is a hash the device recomputes against the published hash. Verified: the hash matches and the install proceeds. Unverified: the hash differs and the install is refused before any code runs. The Come install route only ships the package once, and the signature is locked at that point - a re-shimmed package cannot pass the device check.
Where the published hash and the device-computed hash disagree, the install stops at the dialog. This is the right outcome: a blocked install is cheaper to recover from than a tampered one. The Come support desk resolves signature-mismatch tickets by re-pointing the requester at the verified install route and asking them to re-download - never by sideloading a different package.
After install: KYC and the lobby
First open triggers the KYC flow before any contest can be entered. The KYC steps are the same ones the support desk verifies on a withdrawal request: identity document, address proof and a payout route. Verified: KYC is required before the first withdrawal, regardless of contest activity. The lobby renders while KYC is pending, but deposit, contest entry and withdraw routes stay locked until the document set is complete.
If KYC fails or stalls, the support desk handles it through /contact/. The published response window is 24 hours on weekdays. Ticket volume may extend that window on weekends; the support desk publishes the current window on its own page.