iOS and Android app distribution

Share signed mobile builds with testers

Upload a signed iOS IPA or Android APK, review package details, keep Release history, and create tester links with the access rules you need. DistKit does not sign or re-sign packages.

DistKitRelease workspace
AppCurrent AppDurable product record
ReleaseCurrent ReleasePackage report attached
AudienceTester linkIndependent policy
ReadyCreate the intended tester linkPassword · Expiry · Delivery-handoff limit BlockedKeep the report and replace the packageNo usable delivery path until corrected
Signing assets, platform eligibility, and tester authorization remain with the Release owner.
Reads IPA and APK package metadata Keeps App and Release history Applies policy before file delivery

The Release path at a glance.

Inspect the package, set one audience policy, then use the installation handoff for its platform.

iOS workflow
  1. 01

    Inspect the signed package

    Read the package report before choosing a Release state.

  2. 02

    Publish for one audience

    Set the password, expiry, request limit, and enabled state.

  3. 03

    Deliver by platform

    Use the iOS manifest handoff or a direct Android APK download.

Built for recurring test distribution.

DistKit is for teams that own the signing assets and need a clearer handoff after export.

QA teams

Keep recurring builds in one App history and give each QA audience an explicit Release link.

Independent developers

Inspect provisioning details before sharing a build with collaborators or a small tester set.

Agencies

Separate client-review links by password, expiry, request limit, and current Release.

Signing remains with the publisher.

DistKit analyzes the package you provide and controls its delivery path. Apple certificates and profiles remain in Apple Developer; Android signing keys and export settings remain in your build pipeline.

DistKit
Package report · Release records · Link policy · iOS and Android delivery
Publisher tools
Apple profiles or Android signing keys · Package export · Tester authorization

Control access before file delivery.

The Security page documents the implemented storage and access path without claiming certifications DistKit does not hold.

Security details
Private IPA and APK objects

Production files live in private R2 storage and are served through authorized Worker routes.

Per-link policy

Password, expiry, delivery-handoff limit, and enabled state are checked before delivery.

Short-lived device flow

UDID collection is not MDM enrollment, and device-profile sessions expire after about 15 minutes.

Analyze your first mobile package.

Create a workspace, upload a signed IPA or APK, and review its package report before sharing.