iOS Sideloading Certificate Scams: What to Watch For

Yes, buying certificate-based signing can be safe — the risk is not the idea, it’s who you trust with it. A legitimate seller never needs your Apple ID password, never promises a “lifetime” certificate, and gives you a real price, a real refund policy, and a way to reach support months later. If a seller fails any of those, treat it as a reason to walk away, not negotiate.
That question has gotten louder lately. Sideloading communities have spent the past few weeks trading warnings about certificate sellers — accusations of non-delivery, a giveaway that turned into a public argument, buyers left with dead apps and no answer from support. None of that is new, exactly. It is the same handful of failure modes repeating, just louder this time. Here is what is actually going on underneath, and how to tell a safe option from a risky one before you pay anyone.
Why sideloaded apps need a certificate at all
Every app on an iPhone has to carry a valid code signature before iOS will run it. For an App Store app, Apple signs it automatically the moment you install. A sideloaded app — anything installed outside the App Store — still needs that signature, it just comes from somewhere else: a free Apple ID, a paid individual developer account, or an enterprise certificate.
The signature is what iOS checks, not the app’s origin or intent. That is why revoking a certificate kills every app tied to it instantly, and why “getting a certificate” is the whole game behind sideloading, whichever method you use to get one.
Why a resale market exists in the first place
Apple gives developers two official ways to sign apps outside the App Store. An individual Apple Developer Program account, at $99 a year, lets you sign apps for devices you register yourself — it is built for one developer testing their own work. The Apple Developer Enterprise Program, at $299 a year, exists for a different job: a company distributing its own internal tools to its own employees, with no App Store review and no per-device Apple approval needed.
That second program is the one the certificate resale market runs on. A signing service acquires or rents access to enterprise credentials, registers paying customers as if they were employees, and signs public apps and games with it. Apple’s own developer agreement is explicit that this isn’t allowed — enterprise certificates cannot be used to distribute apps to the public, sold to customers, or shared outside the organization that owns them. Every certificate sold this way is operating outside the terms it was issued under, whether or not the seller says so.
Because it’s a violation from the start, Apple can and does pull these certificates without warning whenever it detects the pattern — a spike in device registrations, complaints, apps the App Store already rejected showing up signed. That is the root of nearly every certificate horror story: not bad luck, but a business model built on infrastructure that was never meant to serve thousands of strangers, and that Apple is actively watching for exactly this kind of use. For the technical detail on one common version of this — signing with a shared certificate and trying to block Apple’s revocation check with custom DNS — see the free certificate method for iOS sideloading, including why that workaround is itself unstable.
The red flags worth checking before you pay
Most certificate scams share the same handful of tells. None of them alone proves bad faith, but stacking up two or three is a strong reason to look elsewhere.
| Signal | Why it’s a red flag | What to do |
|---|---|---|
| Promises a “lifetime” or “unlimited” certificate | No seller controls Apple’s infrastructure. Apple can revoke any certificate at any time, so nobody can honestly guarantee one will last forever. | Treat any uptime claim longer than a few months as marketing, not a technical fact. |
| Payment only by crypto or gift cards | Neither gives you a way to dispute the charge or get your money back if the service disappears after you pay. | Prefer a payment method with buyer protection — a card or a platform that lets you file a dispute. |
| Asks for your Apple ID and password | Signing only needs your device’s UDID, never your credentials. A request for the password is a request for full control of your account. | Never hand Apple ID login details to a third party, no matter how the request is framed. |
| Sold only through DMs or private groups, no public storefront | No support address, no refund process, no company behind the sale — nothing stops the seller from going quiet after payment. | Only buy from a service with a real website, visible support channel, and a track record you can check. |
| Brand-new account running a giveaway or steep discount | A fast way to collect payments or attention before a revoke wave hits or the account disappears on its own. | Check how long the seller has been operating publicly, not just how good the offer looks today. |
| No refunds, under any circumstances | Revokes are a routine, expected part of certificate signing. A seller who won’t discuss what happens when one hits is hiding the odds, not eliminating the risk. | Get the refund or replacement policy in writing before you pay, not after something breaks. |
What actually happens when Apple revokes a certificate
One enterprise certificate signs apps for everyone who bought access to it — sometimes thousands of people. Apple does not revoke one customer’s access at a time; it disables the certificate itself. The instant that happens, every app signed with it stops opening, for every buyer, at once. Nothing is deleted — the icon stays on the home screen — but the signature is no longer valid, so iOS refuses to launch it.
This is why a sideloading setup that worked fine for weeks can go dark overnight with no warning and nothing the user did wrong. It is not a bug in the app or a problem with your phone. It’s the certificate underneath every app on that account being switched off at once. We go through the full mechanics — the different certificate types, why free Apple IDs fail differently than enterprise ones, and what recovery actually looks like — in why sideloaded apps get revoked on iPhone.

What separates a safe option from a risky one
A handful of concrete criteria separate the sellers worth trusting from the ones worth avoiding:
- Never asks for your Apple ID password. Only your device UDID is needed to register you for signing — anything more is a request you should refuse.
- Transparent pricing and a real refund policy. You can see the cost upfront, and there is a stated answer for what happens if a certificate is revoked while you’re subscribed.
- A public, identifiable business. A real support inbox, a company behind the product, and reviews or history that predate this week.
- Support that actually answers. Not just at checkout — months into your subscription, when something breaks.
- A track record measured in years, not weeks. Services that have operated openly for a long time have a reputation to protect, which changes their incentives compared to an account that can vanish and reappear under a new name.
builds.io fits this description and has been doing certificate management since 2013 — it’s a paid subscription, not a free tool, and we’re upfront about that trade-off. We don’t ask for your Apple ID password, pricing is public, and if a certificate is revoked on the Premium plan, it’s replaced rather than left as your problem to solve. That said, a paid service isn’t the only safe route. If you’d rather not pay anyone for signing, the honest free alternatives — AltStore, SideStore, and similar tools — carry no certificate-scam risk at all, because you’re signing with your own free Apple ID instead of buying access to someone else’s. We rank the realistic free options, effort versus payoff, in every free way to sideload iPhone apps, ranked.
If you’ve already handed over your Apple ID or paid
If you gave a seller your Apple ID password, act as though the account is compromised, because it effectively is:
- Change your Apple ID password immediately, from a device you trust, then sign out of Apple ID on every device you don’t recognize (Settings → your name, scroll to the device list).
- Turn on two-factor authentication if it isn’t already on — it blocks sign-in with the password alone.
- Remove any configuration profile the seller installed, under Settings → General → VPN & Device Management. Anything you don’t remember installing yourself should go.
- Check Settings → your name → sign-in & security for unfamiliar devices or recovery contacts and remove anything you don’t recognize.
- Dispute the charge with your card issuer or payment platform if you paid and the service stopped responding — this is exactly what buyer protection exists for.
- Don’t send more money to “fix” it. A common follow-up move is asking for another payment to restore access or issue a new certificate. If the first payment didn’t hold up, a second one from the same seller won’t either.
None of this requires panic — it’s the same handful of steps you’d take after any account exposure, done promptly rather than put off.

The bottom line
The certificate business isn’t inherently a scam, and most of what goes wrong traces back to the same short list: promises no one can keep, payment with no recourse, and a request for credentials that should never leave your hands. Skip a seller that trips any of those wires, and the risk mostly disappears regardless of which option you pick next. Browse the catalog at builds.io if you’d rather have signing handled for you on a transparent subscription, or use the guide above to sign with your own free Apple ID instead — either way, you don’t have to gamble on a stranger’s certificate to sideload safely.