Mobile apps · Concept

App signing and keystores

Every Android and iOS app must be digitally signed by its developer; the signing key proves that each update really comes from the same publisher.

Publishing · updated

How it works

On Android the key lives in a keystore file (.jks) protected by passwords. With Play App Signing, which new apps on Google Play must use, Google keeps the real app signing key and you sign uploads with a separate upload key; if the upload key is lost or leaked, Google can reset it. Before this, losing the key meant never being able to update the app again, so the keystore and its passwords still belong in a password manager and a backup, never in the code repository.

On iOS, signing uses certificates and provisioning profiles issued through the Apple Developer Program, which state which developer, which app and, for test builds, which devices. Xcode and services such as EAS can create and renew them automatically. It is the mobile counterpart of desktop code signing.

More in Mobile apps

Publishing

All 34 Mobile apps terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.