Documentation menu
iOS signing
What pkgr.app needs to produce a signed .ipa for staging and production.
What you need
- An Apple Developer Program membership
- An Apple Distribution certificate (
.p12) — generate one from the Secret Vault, or upload your own. One certificate covers both environments. - An Ad Hoc provisioning profile, for
stagingbuilds - An App Store provisioning profile, for
productionbuilds
Environment-aware exports
The same Apple Distribution certificate signs both environments — what changes is the provisioning profile. staging builds export Ad Hoc, signed for the device UDIDs listed in your Ad Hoc profile, and stay installable over the air. productionbuilds export App Store, using your App Store provisioning profile, and produce an .ipa that's ready to upload to App Store Connect. Android isn't affected by any of this — it already signs with your uploaded keystore for production, unrelated to iOS profiles.
Uploading to the Vault
From the project's Secrets screen, upload your certificate once — it isn't tied to an environment. Provisioning profiles are: when you upload one, pick Staging orProduction so pkgr.app knows which export it belongs to. Uploading a new profile only replaces the one for that same environment; the other stays untouched. Every subsequent build reuses whichever profile matches its environment, delivered via a run token — see Secret Vault.
Adding a device to the Ad Hoc profile
Adding a UDID means regenerating the Ad Hoc provisioning profile in your Apple Developer account and re-uploading it as your Staging profile — pkgr.app doesn't manage device registration on your behalf. This only applies to the Ad Hoc profile; App Store profiles don't list devices.