Fouad's Tweaks

Create a distribution certificate

Sign apps yourself for a year, with push notifications, using an Apple Developer account and a Mac.

Updated

About 30 minutesAdvanced

You'll need

With your own Apple Developer account you can sign apps for a year instead of seven days, and — unlike every free method — issue a certificate that carries the push notification entitlement.

This is the most involved route in the Help Center. Budget half an hour the first time.

Enroll in the Apple Developer Program first (enrollment walkthrough). You'll also need the of each device — get it from udid.io, or from a Mac with the device connected.

Careful

Push notifications still won't work for WhatsApp specifically. It needs additional modifications and a private entitlement that Apple doesn't hand out.

1. Create a Certificate Signing Request

  1. Open Keychain Access (in /System/Library/CoreServices/Applications).
  2. Menu: Keychain Access → Certificate Assistant → Request a Certificate From a Certificate Authority.
  3. Fill in your email and a Common Name (something like "My Distribution Key"). Leave the CA email blank.
  4. Choose Saved to disk, continue, and save the .certSigningRequest file.

Don't do this

This also creates a private key in your login keychain. Don't delete it — without it the certificate is useless, and you'll have to start again.

2. Create the certificate

  1. Sign in at developer.apple.com/account and go to Certificates, IDs & Profiles → Certificates.
  2. Click + and choose Apple Distribution.
  3. Upload the .certSigningRequest file you just saved, continue, and download the .cer.
  4. Double-click the .cer (or drag it into Keychain Access) on the same Mac that made the request. It appears under login → My Certificates as Apple Distribution: YOUR NAME (TEAM_ID).

3. Register your devices

Go to Devices and add a name and UDID for every device you want to install on.

Note

Only devices registered before you generate the provisioning profile can install the app. Adding one later means regenerating the profile.

4. Create the App ID

  1. Go to Identifiers and click +.
  2. Select App Groups, continue, and register one — for example group.com.YOUR_DOMAIN.distribution.
  3. Back on Identifiers, click + again, choose App IDs, then App.
  4. Give it a description and an explicit bundle ID, e.g. com.YOUR_DOMAIN.distribution. Not a wildcard.
  5. Under Capabilities, enable Push Notifications.
  6. Also enable App Groups, click Configure, and select the group from step 2.
  7. Continue, then Register.

5. Create the provisioning profile

  1. Go to Profiles and click +.
  2. Under Distribution choose Ad Hoc.
  3. Select the App ID from step 4.
  4. Select the certificate from step 2.
  5. Select the devices to include.
  6. Name it, then Generate and download the .mobileprovision.

6. Export the certificate as a .p12

  1. In Keychain Access, open the login keychain → My Certificates.
  2. Find your Apple Distribution certificate and expand it — confirm a private key sits underneath.
  3. Right-click the certificate (not the key) → Export.
  4. Choose Personal Information Exchange (.p12) and save.
  5. Set a password to protect the file, then enter your macOS password to let Keychain export the key.

The resulting .p12 contains both the certificate and its private key.

7. Sign the app

Feed both into a signing tool — GBox, Feather, ESign and others all accept them — along with the IPA from our app pages.

Did it work?

Yes — what's next

You're all set. Enjoy the app.

Not yet

Check the common fixesCrashes, “Unable to Verify App”, apps that stop after a week

Still stuck? Tell us which guide and step you're on, and the exact error.