Skip to content

Entitlements Editor

Open an Xcode .entitlements file, edit capabilities in a tree, catch mistakes before code signing fails, and download a clean file with key order preserved.

  • Checks types & values
  • Flags risky exceptions
  • Key order preserved
  • Never uploaded
Ready to open a file processed locally — nothing is uploaded

What gets checked

  • Boolean capabilities (sandbox, network, hardened runtime) are real booleans, not strings
  • Array keys such as keychain-access-groups and application-groups contain only strings
  • Associated domains carry a service prefix (applinks:, webcredentials:) and no http://
  • aps-environment is development or production; get-task-allow is flagged for release builds
  • Hardened-runtime exceptions like disable-library-validation are flagged as security risks
  • Sandbox permission keys without com.apple.security.app-sandbox enabled

Example: fix a type and a domain entry

These are fragments inside a plist dictionary. Both entries below trigger diagnostics:

<key>com.apple.security.app-sandbox</key>
<string>true</string>
<key>com.apple.developer.associated-domains</key>
<array><string>https://example.com</string></array>

Use a Boolean for app-sandbox, and a service-prefixed domain for associated-domains:

<key>com.apple.security.app-sandbox</key>
<true/>
<key>com.apple.developer.associated-domains</key>
<array><string>applinks:example.com</string></array>

This fixes those two local checks. It does not verify the domain’s association file, account permissions, or the app’s signature. Apple’s associated domains setup

Compare with a signed app on macOS

codesign --display --entitlements - --xml "/path/to/App.app" > app.entitlements

Open the exported file here. Keep build-setting variables in your Xcode source when appropriate; the signed output is useful for comparison. Check permitted capabilities with the provisioning profile viewer.

Apple: profile entitlements and signed claims

Frequently asked questions

Can I check what entitlements an app was signed with?
On macOS, run codesign --display --entitlements - --xml /path/to/App.app > app.entitlements, then open app.entitlements here. This shows the signed app's claims; the Xcode source file may contain build-setting variables instead.
Are Xcode variables like $(AppIdentifierPrefix) supported?
Yes. Build-setting variables are kept as-is and not reported as errors.
Is my file uploaded?
No. Everything runs locally in your browser.