Auto-renewal
Distribution certs and provisioning profiles reissue themselves 30 days before expiry. The new cert keeps your existing key; profiles rebuild against the renewed cert in the same run.

HexSign automatically renews your Apple certificates and provisioning profiles before they expire. The rest lives in one place too: an encrypted vault instead of git, a dashboard for every profile and expiration, and a CLI for any CI. No more expired-cert fire drills.
iOS · macOS · tvOS · watchOS
Ships signing assets to any CI. Bring your own pipeline.
See it in action
A walkthrough of the dashboard, certificate relationships, and the provisioning profile wizard. Open the watch page →
An encrypted vault for certificates, a dashboard for every profile and expiration, and a CLI that ships signing assets to any CI. Synced with App Store Connect.
Distribution certs and provisioning profiles reissue themselves 30 days before expiry. The new cert keeps your existing key; profiles rebuild against the renewed cert in the same run.

See how certificates, profiles, and bundle IDs connect. Understand the blast radius before revoking.
Email, Slack, Teams, Jira, PagerDuty, and incident.io, with configurable thresholds and test runs. Fire only when auto-renewal can't act.

A guided flow that picks the right identifier, certificate, and devices and generates the profile through Apple's API.

Certificates live in git or shared drives. Profiles break in CI. Nobody knows which app is affected until a release fails at 5pm on a Friday. If any of the following sound familiar, HexSign is for you.
How it works
Add your App Store Connect API key (Issuer ID, Key ID, and private key). HexSign authenticates securely using Apple's official API.
HexSign pulls all your certificates, provisioning profiles, bundle IDs, and devices. Changes are detected on each sync.
See how everything connects in an interactive visual graph. Color-coded by status so problems jump out instantly.
Configure alerts to email, Slack, Microsoft Teams, or your incident tooling with custom thresholds. Get notified days before anything expires.
The HexSign CLI pulls certificates and profiles straight from the encrypted vault into any pipeline: GitHub Actions, GitLab, Bitrise, Codemagic, fastlane, or your own shell. No certs in git, no fastlane match repo, no shared Apple ID. Explore the CLI →
HexSign is a great fit if you:
See how we compare
Open-source CLI
Apple's first-party portal
CI/CD with managed signing
Mobile DevOps platform
Apple's managed CI/CD with automatic signing
Ready?
Connect your App Store Connect API key and get full visibility in minutes.