Auto-renewal
Distribution certs and provisioning profiles reissue themselves 30 days before expiry. The new cert keeps your existing key; profiles rebuild against the renewed cert in the same run.

HexSign automatically renews your Apple certificates and provisioning profiles before they expire. The rest lives in one place too: an encrypted vault instead of git, a dashboard for every profile and expiration, and a CLI for any CI. No more expired-cert fire drills.
iOS · macOS · tvOS · watchOS
Ships signing assets to any CI. Bring your own pipeline.
See it in action
A walkthrough of the dashboard, certificate relationships, and the provisioning profile wizard. Open the watch page →
An encrypted vault for certificates, a dashboard for every profile and expiration, and a CLI that ships signing assets to any CI. Synced with App Store Connect.
Distribution certs and provisioning profiles reissue themselves 30 days before expiry. The new cert keeps your existing key; profiles rebuild against the renewed cert in the same run.

See how certificates, profiles, and bundle IDs connect. Understand the blast radius before revoking.
Email, Slack, Teams, Jira, PagerDuty, and incident.io, with configurable thresholds and test runs. Fire only when auto-renewal can't act.

A guided flow that picks the right identifier, certificate, and devices and generates the profile through Apple's API.

Certificates live in git or shared drives. Profiles break in CI. Nobody knows which app is affected until a release fails at 5pm on a Friday. If any of the following sound familiar, HexSign is for you.
How it works
Add your App Store Connect API key (Issuer ID, Key ID, and private key). HexSign authenticates securely using Apple's official API.
HexSign pulls all your certificates, provisioning profiles, bundle IDs, and devices. Changes are detected on each sync.
See how everything connects in an interactive visual graph. Color-coded by status so problems jump out instantly.
Configure alerts to email, Slack, Microsoft Teams, or your incident tooling with custom thresholds. Get notified days before anything expires.
The HexSign CLI pulls certificates and profiles straight from the encrypted vault into any pipeline: GitHub Actions, GitLab, Bitrise, Codemagic, fastlane, or your own shell. No certs in git, no fastlane match repo, no shared Apple ID. Explore the CLI →
HexSign is a great fit if you:
See how we compare
Open-source CLI
Apple's first-party portal
CI/CD with managed signing
Mobile DevOps platform
Apple's managed CI/CD with automatic signing
Learn the fundamentals
The process of attaching a cryptographic signature to a binary so the operating system can verify who built it and that nothing has changed since. Required for every app shipped on Apple platforms.
A signed plist Apple issues that links a specific App ID, signing certificate, list of devices (for development and Ad Hoc), and entitlements. Without a matching profile, iOS will refuse to launch your build.
Apple's web console for managing App Store and TestFlight submissions, App Store Connect API keys, in-app purchases, builds, testers, and team access. Distinct from the Apple Developer portal.
Apple's paid membership program ($99/year) that lets a company or individual sign apps, distribute through the App Store and TestFlight, and access betas of Apple's developer tools.
Umbrella term for any Apple-issued certificate used to sign a binary, installer, or push token. Covers Apple Development, Apple Distribution, Developer ID, APNs, Pass Type ID, and Mac Installer certificates.
A fastlane action that stores Apple signing material (certificates, private keys, provisioning profiles) in a shared, encrypted git repo so every developer and CI runner can pull the same identities.
Ready?
Connect your App Store Connect API key and get full visibility in minutes.