Skip to content
Documentation menu

Secret Vault

Where certificates and keystores live, and how they reach a build without ever reaching a browser.

What you can store

  • iOS Distribution certificate (.p12)
  • iOS provisioning profile
  • Android keystore

One secret per type, per project. Uploading a new one replaces the previous one immediately — there's no history of old secrets kept around.

Encryption at rest

Secrets are encrypted at rest on the server. Once uploaded, their contents are never sent back to a browser — only metadata (name, type, upload date) is shown in the UI.

How a build gets them

When you trigger a build, pkgr.app mints a short-lived, single-use run token scoped to that specific build. The GitHub Actions workflow calls back with that token to fetch exactly the secrets it needs. A token that's already been used, or was never issued, gets nothing. Triggering the generated workflow directly on GitHub doesn't work around this — without a valid token from pkgr.app, there's no signed artifact.

Generating an iOS certificate

If you don't already have an Apple Distribution certificate, the project's Certificates screen can generate a signing request and submit it through your App Store Connect API key directly — no Keychain Access or Mac required. See iOS signing for what you need before you start.