What gets checked
- Expired, or expiring within 30 days
- Required keys present with the right types (UUID, TeamIdentifier, DeveloperCertificates…)
- Profile type: Development, Ad Hoc, App Store or Enterprise
- Duplicate devices, empty certificate list
- The embedded entitlements, including App ID and Team ID mismatch
From a warning to the next check
| Field | Diagnostic | Next step |
|---|---|---|
| ExpirationDate | Expired or within 30 days | Check the date before choosing a profile for a build. |
| TeamIdentifier / application-identifier | Team or App ID mismatch | Compare the identifiers with your Xcode target and signing team. |
| ProvisionedDevices | Repeated device IDs | Inspect the list when debugging a device-specific installation issue. |
| DeveloperCertificates | Empty certificate list | The built-in sample intentionally has no certificates; use your original profile for real inspection. |
Read the same payload on macOS
security cms -D -i "profile.mobileprovision" -o "profile.plist"Replace the input filename with your profile. This writes the decoded plist to profile.plist; it does not renew or re-sign the profile.
A profile’s Entitlements describe allowed capabilities, not necessarily the app’s signed claims. Review extracted values in the Entitlements editor before using them.