Skip to content

Mobileprovision Viewer & Editor

Drop a .mobileprovision or .provisionprofile to see its type, expiry date, team, App ID, devices, signing certificates and entitlements — with problems flagged.

  • Reads signed profiles
  • Expiry & device checks
  • Extract entitlements
  • Never uploaded
Ready to open a file processed locally — nothing is uploaded

What gets checked

  • Expired, or expiring within 30 days
  • Required keys present with the right types (UUID, TeamIdentifier, DeveloperCertificates…)
  • Profile type: Development, Ad Hoc, App Store or Enterprise
  • Duplicate devices, empty certificate list
  • The embedded entitlements, including App ID and Team ID mismatch

From a warning to the next check

FieldDiagnosticNext step
ExpirationDateExpired or within 30 daysCheck the date before choosing a profile for a build.
TeamIdentifier / application-identifierTeam or App ID mismatchCompare the identifiers with your Xcode target and signing team.
ProvisionedDevicesRepeated device IDsInspect the list when debugging a device-specific installation issue.
DeveloperCertificatesEmpty certificate listThe built-in sample intentionally has no certificates; use your original profile for real inspection.

Read the same payload on macOS

security cms -D -i "profile.mobileprovision" -o "profile.plist"

Replace the input filename with your profile. This writes the decoded plist to profile.plist; it does not renew or re-sign the profile.

A profile’s Entitlements describe allowed capabilities, not necessarily the app’s signed claims. Review extracted values in the Entitlements editor before using them.

Apple: inside provisioning profiles

About editing

Provisioning profiles are signed by Apple. You can edit and download the contents to inspect or diff them, but Xcode and devices only accept the original signed file. Use "Extract entitlements" to inspect the profile's allowed capabilities. Review them against your app's needs before using them in an Xcode project.

Frequently asked questions

Where do I find my provisioning profiles?
On macOS they live in ~/Library/MobileDevice/Provisioning Profiles (or ~/Library/Developer/Xcode/UserData/Provisioning Profiles in newer Xcode). Inside an .ipa, look for embedded.mobileprovision.
Is the signature verified?
No — the signer names are shown and the contents are read, but the certificate chain is not checked.
Is my profile uploaded?
No. Everything runs locally in your browser.