Guide

The .pkpass file format explained

Behind every Apple Wallet pass is a .pkpass file: a signed package with a JSON description of the pass, its images, a manifest and a signature. This guide walks through each part, how passes are packaged and served, and how they update after they’ve been added - useful whether you’re building passes yourself or choosing a tool that builds them for you.

Last updated October 9, 2026. Facts about Apple Wallet and Google Wallet were checked against Apple’s and Google’s own documentation, linked in the sources.

The short answer

A .pkpass file is a ZIP archive containing pass.json (the pass’s data), image files, manifest.json (a SHA-1 hash of every file) and a signature file (a PKCS #7 signature of the manifest, made with the issuer’s Pass Type ID certificate). Wallet checks the signature and hashes before it accepts the pass.

The files in a pass

FileRequiredPurpose
pass.jsonYesThe pass’s identity, fields, colors, barcode and behavior
icon.pngYesShown in notifications and on the lock screen
Other imagesDepends on styleLogo, strip, background, thumbnail, footer
manifest.jsonYesA SHA-1 hash of every other file
signatureYesThe signature that proves who issued the pass
xx.lproj/NoLocalized text and images for each language

pass.json

pass.json is a single JSON object describing the pass. A minimal example for a store card:

{
  "formatVersion": 1,
  "passTypeIdentifier": "pass.com.example.loyalty",
  "teamIdentifier": "ABCDE12345",
  "serialNumber": "member-0042",
  "organizationName": "Example Coffee",
  "description": "Example Coffee loyalty card",
  "backgroundColor": "rgb(28, 17, 71)",
  "foregroundColor": "rgb(255, 255, 255)",
  "storeCard": {
    "primaryFields": [{ "key": "points", "label": "Points", "value": 120 }]
  },
  "barcodes": [
    { "format": "PKBarcodeFormatQR", "message": "member-0042", "messageEncoding": "iso-8859-1" }
  ]
}

Required keys

Common optional keys

Images

Images are PNG files with fixed names, supplied at standard, @2x and @3x resolutions, for example logo.png, logo@2x.png and logo@3x.png. Which images a pass can use depends on its style: strip images appear on coupons, store cards and event tickets; thumbnails on generic passes and event tickets; background images on event tickets; footer images on boarding passes.

For recommended sizes and design rules, see our wallet pass best practices guide.

manifest.json

manifest.json maps every file in the package (except itself and the signature) to the SHA-1 hash of its contents:

{
  "pass.json": "3f0c…a91e",
  "icon.png": "8b2d…04f7",
  "icon@2x.png": "c41a…9e20",
  "logo.png": "e7d9…1b33"
}

If any file changes, its hash no longer matches and Wallet rejects the pass. That’s why you can’t edit a .pkpass file by hand: you have to rebuild the manifest and sign again.

The signature

The signature file is a detached PKCS #7 signature of manifest.json, made with the private key of a Pass Type ID certificate and including Apple’s WWDR intermediate certificate. To sign passes yourself you need:

Packaging and serving

  1. Zip the files with everything at the top level of the archive - no enclosing folder.
  2. Name it with the .pkpass extension.
  3. Serve it with the file type application/vnd.apple.pkpass, so Safari opens Wallet instead of downloading a ZIP.

To deliver several passes at once, bundle them as a .pkpasses file, served as application/vnd.apple.pkpasses.

How passes update

A pass with a webServiceURL and authenticationToken can be updated after it’s been added:

  1. When the pass is added, the device registers with your web service.
  2. When the pass changes, you send that device a push notification through Apple.
  3. The device asks your service which passes changed, then downloads the new versions.
  4. When the pass is deleted, the device unregisters.

Apple notes that updates aren’t guaranteed - for example, if the phone is offline or the user turned updates off for that pass.

How Google Wallet differs

Google Wallet doesn’t use files. A Google Wallet pass is a class (the shared design) and an object (one person’s pass) created through Google’s Wallet API, and saved with an “Add to Google Wallet” link carrying a signed JSON Web Token. Updates are made by changing the object through the API. To reach both iPhone and Android, an issuer maintains both formats.

Just want to open a pass someone sent you? See what a .pkpass file is and how to open one.

Frequently asked questions

Is a .pkpass file just a ZIP file?+

Yes. It’s a ZIP archive with the pass’s files at the top level, given the .pkpass extension and served with the application/vnd.apple.pkpass file type.

Which keys are required in pass.json?+

At minimum: formatVersion (always 1), passTypeIdentifier, serialNumber, teamIdentifier, organizationName and description, plus exactly one style key - boardingPass, coupon, eventTicket, generic or storeCard - that holds the pass’s fields.

Why does editing a .pkpass file break it?+

manifest.json records a hash of every file, and the signature covers the manifest. Change any file and its hash no longer matches, so Wallet rejects the pass. Every change means rebuilding the manifest and signing it again.

What do I need to sign a pass?+

A Pass Type ID and its certificate from an Apple Developer Program account, plus Apple’s WWDR intermediate certificate. The signature is a detached PKCS #7 signature of manifest.json.

Can one file hold several passes?+

Yes. A .pkpasses file bundles several .pkpass files, such as tickets for a group, so they can be added in one go. It uses the application/vnd.apple.pkpasses file type.

Does Google Wallet use .pkpass files?+

No. Google Wallet passes are created through Google’s Wallet API and saved with a link containing a signed token. A business that wants both wallets issues each format separately.

Sources

Apple’s newer developer pages load dynamically, so where a number comes from Apple it is taken from its Wallet Developer Guide and support pages. If Apple’s or Google’s current documentation differs, follow theirs.

Your next card doesn’t need to be plastic.

Create a wallet pass your customers can save in seconds.