How to Choose an IPA Signing Service — 7 Things That Actually Matter

Dozens of IPA signing services compete on the surface. They mostly look the same: list two packages, take payment, deliver an install link. The real differences are operational — and they only matter once a certificate gets revoked or an install fails. Here's the honest 7-point checklist for picking a service that won't burn you.
1. Certificate freshness and rotation
A signing service is only as good as the certificate behind it. Older certificates accumulate Apple scrutiny — the more public installs Apple sees from a cert, the higher the revoke probability. Quality services rotate Enterprise certificates frequently (often monthly) and limit how many simultaneous installs come from any single cert.
What to ask: "When was your current Enterprise certificate issued?" or "Do you rotate certs?" Vague answers are a red flag.
2. Re-sign policy after revoke
Revokes happen. The question is what happens to your install when it does. Good services automatically re-sign within hours and notify customers; bad ones ghost you or demand additional payment.
What to ask: "If the certificate gets revoked, is the re-sign free?" Yes is the only good answer.
3. Turnaround time
Signing is technically fast — minutes — but services often introduce manual review or bottleneck steps that add hours. Real-world turnaround should be 5-30 minutes for Enterprise, slightly longer for Developer (because UDID registration is involved).
What to look for: Stated turnaround time on the homepage. "1-24 hours" usually means closer to 24.
4. Payment security and refund policy
If a service won't accept Stripe or PayPal — only crypto, or only direct bank — that's a fraud signal. Legitimate services accept mainstream payment processors because they can afford the disputes. Refund policy matters too: if signing fails, you should get your money back without a fight.
5. Customer communication
Look for: a real support address (not just a contact form), response time SLA, clear documentation. Avoid: services that only respond on Telegram or Discord. The communication channel tells you everything about the operational maturity.
6. App data preservation
When you re-sign, your app's bundle ID should stay the same — that preserves user data on re-install. Services that mangle bundle IDs (sometimes done to evade Apple detection) leave users with broken data on every update.
What to ask: "Will my bundle ID stay the same after signing?" Yes is the right answer.
7. Transparent pricing
Hidden add-ons after checkout, surprise "VIP" tiers, escalating fees — all warning signs. Honest services show the full price plus a small list of $5 add-ons (extra devices, IPAs, re-signs) on the package page.
Our pricing: $99 Developer (extras at $5 each), $259 Enterprise (flat). No hidden fees.
Red flags that should make you walk away
- Price under $20 for "unlimited Enterprise" — that's a scam. Real Enterprise certs cost the operator $299/year minimum and they need to make margin.
- "Lifetime" signing offers — Apple revokes certs. Nothing in this space is lifetime.
- No Terms of Service or contact info
- Crypto-only payment
- Promises of "no revoke ever" — impossible to guarantee
Honest evaluation matrix
| Criterion | Good service | Red flag |
|---|---|---|
| Cert rotation | Frequent, transparent | "Same cert for years" |
| Re-sign on revoke | Free | Extra cost |
| Turnaround | < 1 hour stated | "24-48 hours" |
| Payment | Stripe/PayPal | Crypto only |
| Support | Email, < 24h SLA | Telegram only |
| Bundle ID | Preserved | Changed silently |
| Pricing | Flat + clear add-ons | Hidden fees |
If you've been burned before
If you've used services like Scarlet (shut down) or ESign and want alternatives, see: Scarlet and ESign alternatives.