Set up bundle IDs, capabilities, signing certificates, provisioning profiles, and encrypted signing sync with the asc cli. Use when onboarding a new app, rotating signing assets, or sharing them across a team.
SKILL.md
asc signing setup
Use this skill when you need to create or renew signing assets for iOS/macOS apps.
Preconditions
Auth is configured (asc auth login or ASC_* env vars).
You know the bundle identifier and target platform.
You have a CSR file for certificate creation, or you will let asc certificates create --generate-csr create one.
For the Developer Portal-only PRIVATE_CLOUD_COMPUTE capability, use a
user-owned web session and the Developer Portal Bundle ID resource ID:
asc web bundle-ids capabilities enable --bundle-id "BUNDLE_RESOURCE_ID" --capability PRIVATE_CLOUD_COMPUTE --confirm
This capability is not available through the public App Store Connect
capability enum. If the cached session cannot access Developer Portal,
clear its scoped cache, then log in again with the same binary:
For App Groups, the public API can enable APP_GROUPS but cannot create or
associate App Group resources. Use an Account Holder or Admin web session:
asc web app-groups list --paginate --output table
asc web app-groups create --name "Example Shared" --identifier "group.com.example.app.shared" --confirm
asc web app-groups assign --group "GROUP_RESOURCE_ID" --bundle-id "BUNDLE_RESOURCE_ID" --confirm
Resolve the opaque group ID with asc web app-groups list and the opaque
Bundle ID resource ID with asc bundle-ids list. A changed assignment
invalidates provisioning profiles containing that App ID, so regenerate
affected profiles before the next signed build.
Create a signing certificate:
asc certificates list --certificate-type IOS_DISTRIBUTION
asc profiles local install --path "./profiles/AppStore.mobileprovision"
asc profiles local list --output table
On macOS, the default directory follows the active Xcode: Xcode 16 or newer uses ~/Library/Developer/Xcode/UserData/Provisioning Profiles; Xcode 15 or older uses ~/Library/MobileDevice/Provisioning Profiles. Hosts without a full active Xcode fall back to the legacy directory and print a note to stderr.
Pass --install-dir when automation must target a fixed directory.
Rotation and cleanup
Revoke old certificates:
asc certificates revoke --id "CERT_ID" --confirm
Audit remote provisioning profiles before deleting or rotating:
asc profiles list --profile-state ACTIVE,INVALID --paginate --output json
Apple profileState is not a complete expiration signal: some profiles can have a past expirationDate while still reporting ACTIVE. For true expired-profile audits, compare expirationDate against the current date instead of relying only on INVALID.
Delete old profiles:
asc profiles delete --id "PROFILE_ID" --confirm
Clean local Xcode provisioning profiles:
asc profiles local clean --expired --dry-run
asc profiles local clean --expired --confirm
Check the resolved directory in the dry-run output before confirming, or pin it with --install-dir.
Shared team storage with asc signing sync
Use this when you want a lightweight, non-interactive alternative to fastlane match for encrypted git-backed certificate/profile storage.
# Protect secret inputs before use
chmod 600 "./signing-sync-password" "./distribution.p12" "./distribution-p12-password"
# Push a usable private identity with its matching certificate and profile
asc signing sync push \
--bundle-id "com.example.app" \
--profile-type IOS_APP_ADHOC \
--repo "[email protected]:team/certs.git" \
--password-file "./signing-sync-password" \
--identity "./distribution.p12" \
--identity-password-file "./distribution-p12-password" \
--output json
# Pull and decrypt them into a local directory
asc signing sync pull \
--repo "[email protected]:team/certs.git" \
--password-file "./signing-sync-password" \
--output-dir "./signing" \
--output json
Notes:
App Store Connect never returns a private key. Supply the local PKCS#12 with
--identity, or use --private-key with --identity-sha256 to select its
matching App Store Connect certificate. A multi-identity PKCS#12 also needs
--identity-sha256.
Prefer --password-file; ASC_SIGNING_SYNC_PASSWORD is the non-file fallback.
--password and ASC_MATCH_PASSWORD are deprecated during 4.x and will be
rejected in 5.0.0.
Certificate/profile-only sync remains supported but reports
identityPresent: false; it is not a usable signing identity by itself.
pull reports private identities in sensitiveFiles and writes them mode
0600. Importing or using the pulled identity remains a separate explicit step.
Planning performs no mutation and may return ready: false. Apply can register
missing devices, create safe baseline App IDs, and create successor ad hoc
profiles; it never deletes or patches resources, enables capabilities, or
creates certificates. Review the plan before --confirm. Use the
asc-ad-hoc-distribution skill when these signing effects should be bound into
an end-to-end distribution plan hash.
Run one command with an ephemeral identity
On macOS, avoid persistent login-keychain and profile changes by wrapping the
child command:
The command runs directly without a shell, preserves the child's exit code,
uses an isolated temporary keychain, and cleans up its temporary profile. It
does not print success data, so the child owns stdout. Never pass identity
passwords inline.
Notes
Always check --help for the exact enum values (certificate types, profile types).
Use --paginate for large accounts.
--certificate accepts comma-separated IDs when multiple certificates are required.