Every Apple Wallet pass is cryptographically signed by a certificate that Apple issues against a Pass Type ID. By default PocketPass signs your passes with ours, which works out of the box and needs nothing from you.
You can use your own instead. Settings → Apple certificate is where you set that up.
Do you need this?
Most accounts don't. The certificate isn't what your customers see on the pass - your logo, colours and text all come from your pass template either way, and passes signed with the PocketPass certificate look exactly the same as passes signed with yours.
It's worth doing if:
- You want your own Pass Type ID recorded against your passes rather than ours.
- You're moving to PocketPass from another wallet platform and already hold a certificate you want to keep using.
- Your organisation's policy requires passes to be issued under your own Apple Developer account.
You need a paid Apple Developer Program membership (currently around US$99/year). If you don't have one and don't want one, stay on the PocketPass certificate - everything works.
The one thing to know before you start
Apple identifies a pass that's already in someone's wallet by its Pass Type ID together with its serial number. That pairing is fixed for the life of the pass, and Apple gives us no way to change it.
So when you add your certificate:
- Passes you create from then on are signed with your Pass Type ID.
- Passes you've already issued stay with the certificate that signed them. They carry on updating in your customers' wallets exactly as before - nothing breaks, nothing needs re-issuing.
There's no way to migrate existing passes onto a new certificate. If you want every pass on your own Pass Type ID, set the certificate up before you start issuing at volume.
This is also why we never delete a certificate you've uploaded, even after you switch away from it - the passes signed with it still need it.
Option 1: create a signing request (recommended)
This is the path we recommend. PocketPass generates the private key and the signing request, so the key never leaves our servers and there's no password for you to manage. You only carry two files between Apple and us.
- Open Settings → Apple certificate and click Create signing request.
- Click Download cert.certSigningRequest and save the file.
- In a new tab, sign in to Certificates, Identifiers & Profiles in your Apple Developer account and open Identifiers.
- Click +, choose Pass Type IDs, and register an identifier. It must start with
pass.- for examplepass.com.yourcompany.loyalty. - Open the new Pass Type ID and click Create Certificate.
- Upload the
cert.certSigningRequestfile from step 2, then download the certificate Apple generates (pass.cer). - Back in PocketPass, upload
pass.cerunder step 3 of the same page.
That's it. We check the certificate against the request we issued, read your Pass Type ID and Team ID out of it, and switch new passes over straight away.
Don't click Start over once you've taken the request to Apple. Starting over generates a brand-new request, and any certificate Apple has already issued against the old one stops working - you'd have to create a new certificate from scratch.
Option 2: upload a .p12 you already have
If you already have a Pass Type ID certificate - from another wallet platform, or sitting in Keychain Access on a Mac - you can upload it directly.
You need a .p12 file containing both the certificate and its private key.
- In Keychain Access, find the certificate named Pass Type ID: pass.….
- Click the arrow next to it to expand it, so the private key underneath is visible.
- Select both the certificate and the key, right-click, and choose Export 2 items….
- Save as a
.p12file and set a password when prompted. - In PocketPass, open the I already have a .p12 tab, choose the file, enter that password, and upload.
The password is used once to unlock the file and is never stored. If you export without selecting the private key, the upload is rejected - the certificate on its own can't sign anything.
Renewing before it expires
Apple pass certificates last one year. When one lapses, passes signed with it stop receiving updates - they stay in your customers' wallets but go stale, and you can't issue new passes under it.
The certificate page shows the expiry date with a badge, and we email your account admins when it's within 30 days.
To renew, create a new certificate in the Apple Developer portal against the same Pass Type ID, then upload it in PocketPass. Use Replace certificate and either path above. Your old certificate stays on file so passes signed with it keep working.
Apple Developer accounts tied to one individual are a common cause of a missed renewal - if that person leaves, nobody can get in to reissue. Make sure more than one person at your organisation can access the account.
Switching back to the PocketPass certificate
Stop using it on the certificate page moves new passes back onto PocketPass's certificate. Passes already signed with yours keep working - we hold on to the key so they can still receive updates.
Who can change this
Only admins can add, replace or remove the certificate. Editors and viewers can see which certificate is in use but can't change it. See Team members and roles.
If the upload is rejected
| What you see | What it usually means |
|---|---|
| That's not an Apple Pass Type ID certificate | You've uploaded a different kind of Apple certificate. You want the one created under Identifiers → Pass Type IDs, named Pass Type ID: pass.… in Keychain Access. |
| That password didn't unlock the file | The .p12 password is wrong. It's the password you set when exporting, not your Apple ID password. |
| That .p12 doesn't contain a private key | The export didn't include the key. Expand the certificate in Keychain Access and select both items before exporting. |
| That certificate doesn't match the signing request | The .cer was issued against a different request - usually because Start over was clicked after downloading. Download the current request and create a new certificate from it. |
| That certificate expired on… | Apple issued it more than a year ago. Create a fresh one in the Apple Developer portal. |
| Issued by an Apple intermediate we don't have on file | Rare, and nothing you've done wrong - get in touch and we'll add it. |
Does this affect Google Wallet?
No. This setting is Apple-only. Google Wallet passes are issued under PocketPass's Google issuer account and aren't affected by anything on this page.
Where to go next
- How Apple & Google Wallet passes work - what a pass actually is.
- Live pass updates - how a pass changes after it's in someone's wallet.
- Pass not updating - if updates stop arriving.