- Guides
- Signing & Certificates
- Create a distribution certificate
Create a distribution certificate
Sign apps yourself for a year, with push notifications, using an Apple Developer account and a Mac.
Updated
You'll need
- An Apple Developer Program membership — $99 a year
- A Mac (for Keychain Access)
- The UDID of every device you'll install on
- Read first: What you need before sideloading
With your own Apple Developer account you can sign apps for a year instead of seven days, and — unlike every free method — issue a certificate that carries the push notification entitlement.
This is the most involved route in the Help Center. Budget half an hour the first time.
Enroll in the Apple Developer Program first (enrollment walkthrough). You'll also need the of each device — get it from udid.io, or from a Mac with the device connected.
Careful
Push notifications still won't work for WhatsApp specifically. It needs additional modifications and a private entitlement that Apple doesn't hand out.
1. Create a Certificate Signing Request
- Open Keychain Access (in
/System/Library/CoreServices/Applications). - Menu: Keychain Access → Certificate Assistant → Request a Certificate From a Certificate Authority.
- Fill in your email and a Common Name (something like "My Distribution Key"). Leave the CA email blank.
- Choose Saved to disk, continue, and save the
.certSigningRequestfile.
Don't do this
This also creates a private key in your login keychain. Don't delete it — without it the certificate is useless, and you'll have to start again.
2. Create the certificate
- Sign in at developer.apple.com/account and go to Certificates, IDs & Profiles → Certificates.
- Click + and choose Apple Distribution.
- Upload the
.certSigningRequestfile you just saved, continue, and download the.cer. - Double-click the
.cer(or drag it into Keychain Access) on the same Mac that made the request. It appears under login → My Certificates asApple Distribution: YOUR NAME (TEAM_ID).
3. Register your devices
Go to Devices and add a name and UDID for every device you want to install on.
Note
Only devices registered before you generate the provisioning profile can install the app. Adding one later means regenerating the profile.
4. Create the App ID
- Go to Identifiers and click +.
- Select App Groups, continue, and register one — for example
group.com.YOUR_DOMAIN.distribution. - Back on Identifiers, click + again, choose App IDs, then App.
- Give it a description and an explicit bundle ID, e.g.
com.YOUR_DOMAIN.distribution. Not a wildcard. - Under Capabilities, enable Push Notifications.
- Also enable App Groups, click Configure, and select the group from step 2.
- Continue, then Register.
5. Create the provisioning profile
- Go to Profiles and click +.
- Under Distribution choose Ad Hoc.
- Select the App ID from step 4.
- Select the certificate from step 2.
- Select the devices to include.
- Name it, then Generate and download the
.mobileprovision.
6. Export the certificate as a .p12
- In Keychain Access, open the login keychain → My Certificates.
- Find your Apple Distribution certificate and expand it — confirm a private key sits underneath.
- Right-click the certificate (not the key) → Export.
- Choose Personal Information Exchange (.p12) and save.
- Set a password to protect the file, then enter your macOS password to let Keychain export the key.
The resulting .p12 contains both the certificate and its private key.
7. Sign the app
Feed both into a signing tool — GBox, Feather, ESign and others all accept them — along with the IPA from our app pages.
Related
Did it work?
Yes — what's next
You're all set. Enjoy the app.
Not yet
Check the common fixesCrashes, “Unable to Verify App”, apps that stop after a weekStill stuck? Tell us which guide and step you're on, and the exact error.