Apple signing credentials
To build and sign iOS apps, BuildStack needs an App Store Connect API key. Like all credentials, it's sealed, encrypted at rest and only opened during a build. You don't manage certificates or provisioning profiles yourself — BuildStack creates and renews them automatically with your key.
What to provide
Create an App Store Connect API key, then add it in the project's Credentials panel:
- In App Store Connect go to **Users and
Access → Integrations → App Store Connect API → Team Keys**.
- Copy the Issuer ID (the UUID shown at the top of the page).
- Click Generate API Key, give it a name, and set Access = App Manager
(or Admin) so it can manage signing. Note its Key ID.
- Download API Key — this gives you a
.p8file. It can only be downloaded
once, so keep it safe.
In BuildStack's Credentials → Apple signing (iOS) panel, enter the Issuer ID, the Key ID, choose the `.p8` file, and click Upload credential.
How signing works
With the key uploaded, BuildStack signs on managed Mac agents using automatic signing: the key authenticates to Apple, so the required distribution certificate and provisioning profiles are created and renewed for you — there is no .p12 to export or profile to manage. The same key also authorizes App Store Connect submission (TestFlight / App Store).
Tips
- One App Store Connect API key is account-wide — the same
.p8works for
every app under your Apple team. Upload it to each project that needs it.
- The project's bundle identifier must match your Apple app record.
- If you revoke or lose the key, generate a new one and re-upload it.
Security
The .p8 is encrypted with a hardware-backed key and decrypted only in memory, only for the duration of a build. It's never shown back or written to logs.