Help › Getting started

Adding an Apple Certificate

Issue your Apple Wallet passes under your own Apple Developer account.

Do you need this?

Probably not. This is optional. By default, WalletPassBuilder signs your Apple Wallet passes for you, so you can create and share passes without an Apple Developer account. Add your own certificate only if you want your passes issued under your own Apple Developer identity.

A certificate is what proves to Apple Wallet who issued a pass. When you add yours, you create it in your own Apple Developer account from a signing request (CSR) that WalletPassBuilder generates for you. Our server keeps the matching private key, encrypted; it is never sent to your browser or shown anywhere.

What you need

A WalletPassBuilder account with Full access

The certificate belongs to the whole account, so only Full access members with whole-account access can manage it. Don’t have an account yet? Sign up.

An Apple Developer Program membership

Apple only lets members of the Apple Developer Program create Pass Type ID certificates. Membership costs 99 USD per year, for individuals and organizations. Learn about the Apple Developer Program. Google Wallet has no equivalent requirement.

Step by step

These steps add a new certificate. To renew one, follow the same steps with a fresh CSR. Apple’s own instructions are here if its portal looks different from what’s described below.

  1. 1

    Download the CSR from WalletPassBuilder

    • In WalletPassBuilder, open Settings → Apple Certificate.
    • Click Download CSR. A file named CertificateSigningRequest.certSigningRequest is saved to your computer.

    Keep the file handy

    You’ll upload it to Apple in step 6. If you download it again before uploading your certificate, you get the same file, so it doesn’t matter which copy you use.
  2. 2

    Sign in to your Apple Developer account

  3. 3

    Open Certificates, Identifiers & Profiles

    • From the account page, choose Certificates, Identifiers & Profiles.
  4. 4

    Register a Pass Type ID

    A Pass Type ID is the name your passes are issued under. If you already have one you want to use, skip to step 5.

    • In the sidebar, click Identifiers, then the + button at the top left.
    • Select Pass Type IDs and click Continue.
    • Enter a description and an identifier, then click Continue, and Register on the review screen.

    Choose the identifier carefully

    Use reverse-domain style, beginning with pass. — for example pass.com.yourcompany.loyalty. It identifies your passes permanently, so pick one that represents your organization.
  5. 5

    Create a Pass Type ID Certificate

    • In the sidebar, click Certificates, then the + button.
    • Under Services, select Pass Type ID Certificate and click Continue.
    • Choose the Pass Type ID you registered in step 4, then click Continue.
  6. 6

    Upload the CSR to Apple

    • Click Choose File and select the CertificateSigningRequest.certSigningRequest file from step 1.
    • Check that it’s the right file, then click Continue.

    Use the CSR from WalletPassBuilder

    WalletPassBuilder only accepts certificates created from the CSR it gave you, because that’s the one whose private key it holds. A certificate made from a CSR you generated yourself won’t match.
  7. 7

    Download the certificate

    • Click Download. The certificate is a file ending in .cer, usually saved to your Downloads folder.

    Download it before you close the page

    The .cer file is what you upload to WalletPassBuilder. You can also download it again later from the Certificates list in the Apple Developer portal.
  8. 8

    Upload the certificate to WalletPassBuilder

    What we check

    WalletPassBuilder confirms the certificate was issued by Apple, is a Pass Type ID certificate, hasn’t expired, and was made from the CSR we gave you. It then shows your Pass Type ID, Team ID and expiry date on the Apple Certificate page.

If the upload is rejected

These are the messages you may see and what to do.

MessageWhat it means
“That certificate wasn’t created from a CSR we generated for your account.”The certificate was made from a different CSR. Download the CSR from the Apple Certificate page, create a new certificate from it, and upload that one.
“That certificate wasn’t issued by Apple.”Upload the file you downloaded from the Apple Developer portal, not one from another source.
“That’s an Apple certificate, but not a Pass Type ID certificate.”You downloaded a different kind of certificate. In the Apple Developer portal, create a Pass Type ID Certificate (step 5).
“That’s a .p12 file”A .p12 bundles a private key, and ours stays on our server. Upload the .cer file Apple gave you instead.
“That’s a certificate signing request (CSR), not a certificate.”You uploaded the CSR back to us. The CSR goes to Apple (step 6); the file Apple gives you in return goes to us (step 8).
“That certificate expired on …”Create a new certificate from a new CSR. Download a fresh CSR first.
“That certificate was issued by an older Apple intermediate certificate…”The certificate predates Apple’s current intermediate certificate. Create a new Pass Type ID certificate in the Apple Developer portal from a fresh CSR; new ones use the current intermediate.
“… of your passes are signed with this certificate, so it can’t be removed.”Passes keep the Pass Type ID they were created with. Archive or delete those passes, or upload a renewed certificate for the same Pass Type ID first, then remove the old one.

Important to know

Certificates expire

Every certificate has an expiry date, shown on the Apple Certificate page; WalletPassBuilder flags it when it’s within 30 days. If a certificate expires, passes already saved on phones keep working, but you can’t create new passes, edit passes signed with it, or send them updates until you upload a renewed certificate.

Renewing

Before it expires, download a new CSR from the Apple Certificate page, repeat steps 5 to 8, and upload the new certificate. Use the same Pass Type ID: your existing passes are re-signed with the new certificate automatically, and updates to them are sent with it. The previous certificate is kept on file until you remove it.

Keep your membership active

Your certificates depend on an active Apple Developer Program membership. Set a reminder to renew it, and a second one about a month before your certificate expires.

Need help?

If something doesn’t work, we’re happy to help you get your certificate set up. Contact support.

Quick links