Credentials
Bring your own Apple certificate and Google Wallet issuer. Passes you create are signed and issued under your own identity.
Step by step setup guideBYOK is not enabled on your account
BYOK lets you sign Apple passes and issue Google Wallet objects under your own developer identity. It isn't self-serve — reach out and we'll enable it.
Talk to usApple Wallet
Generate a signing request, get your certificate from Apple, then add a push key.
- Pass Type ID
- Team ID
- Certificate expires
Generate a signing request
We hold the private key for this certificate. It was generated here and has never left our servers.
We create the keypair and keep the private key. You upload the request to Apple to get your Pass Type ID certificate. No Keychain and no openssl needed.
Use a certificate for the same Pass Type ID. Existing passes keep working and re-sign on their next update. Switching to a different pass type is rejected while live passes exist.
Request downloaded — upload it to Apple, then come back with the certificate
Upload your certificate
Generate a signing request first — Apple issues the certificate from it.
Your certificate is stored and signing passes.
Apple hands back a .cer file. Add it here to finish.
Add your push key
OptionalAdd your certificate first — the push key is tied to its team.
Push updates are enabled — installed passes receive live updates instantly.
An APNs auth key so pass updates reach installed devices.
Force remove deletes your Apple credentials even though live passes still exist. Those passes will stop updating.
Google Wallet
Your issuer ID and a service account key.
- Issuer ID
- Service account
Add your issuer ID
The numeric issuer ID from the Google Pay and Wallet Console.
Keep the same issuer ID to rotate the key. Changing it is rejected while live passes exist.
Upload your service account key
A service account with Google Wallet Objects access. It must also be authorized on your issuer, or the key authenticates but cannot manage passes.
Keys are encrypted before they're stored and never shown again.