Skip to content
Documentation menu

iOS signing

What pkgr.app needs to produce a signed .ipa for staging and production.

What you need

  • An Apple Developer Program membership
  • An Apple Distribution certificate (.p12) — generate one from the Secret Vault, or upload your own. One certificate covers both environments.
  • An Ad Hoc provisioning profile, for staging builds
  • An App Store provisioning profile, for production builds

Environment-aware exports

The same Apple Distribution certificate signs both environments — what changes is the provisioning profile. staging builds export Ad Hoc, signed for the device UDIDs listed in your Ad Hoc profile, and stay installable over the air. productionbuilds export App Store, using your App Store provisioning profile, and produce an .ipa that's ready to upload to App Store Connect. Android isn't affected by any of this — it already signs with your uploaded keystore for production, unrelated to iOS profiles.

Uploading to the Vault

From the project's Secrets screen, upload your certificate once — it isn't tied to an environment. Provisioning profiles are: when you upload one, pick Staging orProduction so pkgr.app knows which export it belongs to. Uploading a new profile only replaces the one for that same environment; the other stays untouched. Every subsequent build reuses whichever profile matches its environment, delivered via a run token — see Secret Vault.

Adding a device to the Ad Hoc profile

Adding a UDID means regenerating the Ad Hoc provisioning profile in your Apple Developer account and re-uploading it as your Staging profile — pkgr.app doesn't manage device registration on your behalf. This only applies to the Ad Hoc profile; App Store profiles don't list devices.