A .p8 private key created in the Apple Developer portal that authenticates token-based push notification sending to APNs. One key serves every app on your team and does not expire.
An APNs auth key is the modern token-based credential for sending push notifications through Apple Push Notification service. Apple issues a .p8 ECDSA private key, gives you a Key ID and the Team ID, and you use those to sign short-lived JWTs that authenticate each batch of push sends. One auth key covers every app on the team, works for sandbox and production, and does not expire.
How it differs from an APNs certificate
APNs certificate (legacy)
An Apple Push Services certificate, one per app, that expires once a year. Authenticates with mutual TLS to APNs.
APNs auth key (modern)
A single .p8 ECDSA key, shared across every app, that never expires. Authenticates with a signed JWT in the authorization header.
When you create one
1
Apple Developer portal > Keys
Sign in as Account Holder or Admin, open Keys, and create a new key with APNs enabled.
2
Download the .p8 right away
Apple lets you save it once. Save the .p8 alongside the Key ID and your Team ID and put all three into your push backend's secret manager.
3
Sign a JWT and send a push
Your push backend signs an ES256 JWT with the .p8, the Key ID in the JWT header, and the Team ID as the iss claim. The JWT is reused for up to one hour before resigning.
Rotation
Auth keys do not expire, but you may need to rotate one if it leaks, if the engineer who created it leaves and you cannot account for the .p8, or if Apple's security recommendations change. The pattern is to create a new key, deploy both keys to your push backend, switch sends to the new Key ID, and then revoke the old key. Apple allows up to two active APNs auth keys per team during the overlap.
Auth key vs push certificate at a glance
APNs auth key
APNs certificate (legacy)
Scope
Every app on the team
One app per certificate
Expiry
Never expires
Expires once a year
Auth mechanism
Signed ES256 JWT
Mutual TLS handshake
File format
.p8 private key
.p12 certificate plus key
Max per team
Two active keys
One per app, per environment
Sandbox and production
Same key for both
Separate certificates
What you need to authenticate
Key ID: the 10-character identifier Apple shows next to the key.
Team ID: your 10-character Apple Developer Team ID, used as the JWT iss claim.
The .p8 private key file, loaded by your push backend to sign the JWT.
apns-topic: usually your app's bundle ID, sent as a header on each push request.
FAQ
Common questions about APNs auth key
No. An APNs auth key is a .p8 ECDSA private key that does not expire, unlike a legacy APNs push certificate that has to be renewed every year. You only replace an auth key if it leaks or you decide to rotate it for security reasons.
An APNs certificate is issued per app, expires once a year, and authenticates with mutual TLS. An APNs auth key is a single .p8 shared across every app on the team, never expires, and authenticates with a signed JWT in the authorization header. Apple recommends the auth key for new projects.
Apple allows up to two active APNs auth keys per team at a time. The overlap lets you roll to a new key without downtime: create the new key, deploy both, switch sends to the new Key ID, then revoke the old one.
Create a new key in the Apple Developer portal, deploy both the old and new .p8 to your push backend, switch your JWT signing to the new Key ID, confirm pushes still deliver, then revoke the old key. Keep the .p8, Key ID, and Team ID together in a secret manager.
HexSign tracks every Apple certificate and provisioning profile and alerts you ahead of expiry. The Free plan covers tracking and alerts. Paid plans renew them for you.