Documentation menu
Secret Vault
Where certificates and keystores live, and how they reach a build without ever reaching a browser.
What you can store
- iOS Distribution certificate (
.p12) - iOS provisioning profile
- Android keystore
One secret per type, per project. Uploading a new one replaces the previous one immediately — there's no history of old secrets kept around.
Encryption at rest
Secrets are encrypted at rest on the server. Once uploaded, their contents are never sent back to a browser — only metadata (name, type, upload date) is shown in the UI.
How a build gets them
When you trigger a build, pkgr.app mints a short-lived, single-use run token scoped to that specific build. The GitHub Actions workflow calls back with that token to fetch exactly the secrets it needs. A token that's already been used, or was never issued, gets nothing. Triggering the generated workflow directly on GitHub doesn't work around this — without a valid token from pkgr.app, there's no signed artifact.
Generating an iOS certificate
If you don't already have an Apple Distribution certificate, the project's Certificates screen can generate a signing request and submit it through your App Store Connect API key directly — no Keychain Access or Mac required. See iOS signing for what you need before you start.