Help › Getting started
Adding an Apple Certificate
Issue your Apple Wallet passes under your own Apple Developer account.
Do you need this?
Probably not. This is optional. By default, WalletPassBuilder signs your Apple Wallet passes for you, so you can create and share passes without an Apple Developer account. Add your own certificate only if you want your passes issued under your own Apple Developer identity.
A certificate is what proves to Apple Wallet who issued a pass. When you add yours, you create it in your own Apple Developer account from a signing request (CSR) that WalletPassBuilder generates for you. Our server keeps the matching private key, encrypted; it is never sent to your browser or shown anywhere.
What you need
A WalletPassBuilder account with Full access
The certificate belongs to the whole account, so only Full access members with whole-account access can manage it. Don’t have an account yet? Sign up.
An Apple Developer Program membership
Apple only lets members of the Apple Developer Program create Pass Type ID certificates. Membership costs 99 USD per year, for individuals and organizations. Learn about the Apple Developer Program. Google Wallet has no equivalent requirement.
Step by step
These steps add a new certificate. To renew one, follow the same steps with a fresh CSR. Apple’s own instructions are here if its portal looks different from what’s described below.
- 1
Download the CSR from WalletPassBuilder
- In WalletPassBuilder, open Settings → Apple Certificate.
- Click Download CSR. A file named
CertificateSigningRequest.certSigningRequestis saved to your computer.
Keep the file handy
You’ll upload it to Apple in step 6. If you download it again before uploading your certificate, you get the same file, so it doesn’t matter which copy you use. - 2
Sign in to your Apple Developer account
- Open a new tab and go to developer.apple.com/account.
- Sign in with the Apple ID you use for the Apple Developer Program.
- 3
Open Certificates, Identifiers & Profiles
- From the account page, choose Certificates, Identifiers & Profiles.
- 4
Register a Pass Type ID
A Pass Type ID is the name your passes are issued under. If you already have one you want to use, skip to step 5.
- In the sidebar, click Identifiers, then the + button at the top left.
- Select Pass Type IDs and click Continue.
- Enter a description and an identifier, then click Continue, and Register on the review screen.
Choose the identifier carefully
Use reverse-domain style, beginning withpass.— for examplepass.com.yourcompany.loyalty. It identifies your passes permanently, so pick one that represents your organization. - 5
Create a Pass Type ID Certificate
- In the sidebar, click Certificates, then the + button.
- Under Services, select Pass Type ID Certificate and click Continue.
- Choose the Pass Type ID you registered in step 4, then click Continue.
- 6
Upload the CSR to Apple
- Click Choose File and select the
CertificateSigningRequest.certSigningRequestfile from step 1. - Check that it’s the right file, then click Continue.
Use the CSR from WalletPassBuilder
WalletPassBuilder only accepts certificates created from the CSR it gave you, because that’s the one whose private key it holds. A certificate made from a CSR you generated yourself won’t match. - Click Choose File and select the
- 7
Download the certificate
- Click Download. The certificate is a file ending in
.cer, usually saved to your Downloads folder.
Download it before you close the page
The.cerfile is what you upload to WalletPassBuilder. You can also download it again later from the Certificates list in the Apple Developer portal. - Click Download. The certificate is a file ending in
- 8
Upload the certificate to WalletPassBuilder
- Go back to Settings → Apple Certificate.
- Drag the
.cerfile into the upload area, or click to browse for it. - Click Upload certificate.
What we check
WalletPassBuilder confirms the certificate was issued by Apple, is a Pass Type ID certificate, hasn’t expired, and was made from the CSR we gave you. It then shows your Pass Type ID, Team ID and expiry date on the Apple Certificate page.
If the upload is rejected
These are the messages you may see and what to do.
| Message | What it means |
|---|---|
| “That certificate wasn’t created from a CSR we generated for your account.” | The certificate was made from a different CSR. Download the CSR from the Apple Certificate page, create a new certificate from it, and upload that one. |
| “That certificate wasn’t issued by Apple.” | Upload the file you downloaded from the Apple Developer portal, not one from another source. |
| “That’s an Apple certificate, but not a Pass Type ID certificate.” | You downloaded a different kind of certificate. In the Apple Developer portal, create a Pass Type ID Certificate (step 5). |
| “That’s a .p12 file” | A .p12 bundles a private key, and ours stays on our server. Upload the .cer file Apple gave you instead. |
| “That’s a certificate signing request (CSR), not a certificate.” | You uploaded the CSR back to us. The CSR goes to Apple (step 6); the file Apple gives you in return goes to us (step 8). |
| “That certificate expired on …” | Create a new certificate from a new CSR. Download a fresh CSR first. |
| “That certificate was issued by an older Apple intermediate certificate…” | The certificate predates Apple’s current intermediate certificate. Create a new Pass Type ID certificate in the Apple Developer portal from a fresh CSR; new ones use the current intermediate. |
| “… of your passes are signed with this certificate, so it can’t be removed.” | Passes keep the Pass Type ID they were created with. Archive or delete those passes, or upload a renewed certificate for the same Pass Type ID first, then remove the old one. |
Important to know
Certificates expire
Every certificate has an expiry date, shown on the Apple Certificate page; WalletPassBuilder flags it when it’s within 30 days. If a certificate expires, passes already saved on phones keep working, but you can’t create new passes, edit passes signed with it, or send them updates until you upload a renewed certificate.
Renewing
Before it expires, download a new CSR from the Apple Certificate page, repeat steps 5 to 8, and upload the new certificate. Use the same Pass Type ID: your existing passes are re-signed with the new certificate automatically, and updates to them are sent with it. The previous certificate is kept on file until you remove it.
Keep your membership active
Your certificates depend on an active Apple Developer Program membership. Set a reminder to renew it, and a second one about a month before your certificate expires.
Need help?
If something doesn’t work, we’re happy to help you get your certificate set up. Contact support.