Scarlet and ESign Alternatives — What to Use After They Shut Down

If you've been in the iOS sideloading world for any length of time, you know names like Scarlet, ESign, Cydia Impactor, and others. Many of them are gone, others are unreliable. Here's the honest current state and what to use instead in 2026.
What happened to Scarlet
Scarlet was a popular iOS app installer that used a single shared Enterprise certificate to distribute apps to a massive user base. As is inevitable with that model, Apple eventually revoked the cert. After repeated revokes and ownership changes, Scarlet effectively ceased to function as a reliable installer. Many users found themselves with apps that wouldn't launch and no recourse.
The structural problem
Free shared-cert installers all share the same flaw: one cert serves thousands of unrelated apps and users. Apple's revoke heuristics light up immediately on that pattern. The bigger the user base, the faster the revoke. There's no way around this — it's not a Scarlet problem, it's the model.
ESign's current state
ESign is still around but has the same structural issue. Periods of stable operation, followed by sudden mass revokes, followed by re-signs that customers wait days for. If you're using ESign in 2026, expect ~70% uptime, not 99%.
What actually works as an alternative
The reliable alternatives split into three groups depending on your use case:
1. Free + you-only — AltStore / SideStore / TrollStore
If you only need apps on your own device and don't mind weekly re-signs, the free tools work. Comparison here. These avoid the shared-cert revoke problem entirely because each user has their own free Apple ID certificate. The tradeoff is you can't share with others.
2. Paid + per-customer Enterprise signing
This is the model where you pay for signing and the service uses a fresh-rotated Enterprise cert with limited install volume per cert. Because cert exposure is small, Apple revoke pressure is much lower. When a revoke does happen, the service re-signs with the next rotated cert — usually within minutes.
This is the model we run. See: how to evaluate a signing service.
3. Paid + Developer cert (small, very reliable)
For Developer-signed IPAs, revoke risk is essentially zero — you only need to re-sign every 7 days because the cert expires naturally. For small audiences, this is the most reliable option in the entire ecosystem.
What to look for in any alternative
From hardest-earned lessons in the post-Scarlet era:
- No shared/mass certificate — if a service signs apps for "everyone" with the same cert, it'll get revoked. Often.
- Free re-sign after revoke — non-negotiable.
- Real email support — not Telegram, not Discord.
- Stripe/PayPal payment — crypto-only is a fraud signal.
- Clear pricing on the homepage — no hidden tiers.
The honest tradeoff
Free shared-cert installers like Scarlet were appealing because they cost nothing. The cost was actually paid in reliability. Paid signing costs money but the math works out: $259 for an Enterprise sign that lasts months is cheaper per-install than reinstalling a $0 service every few weeks.
If you've been burned by Scarlet, ESign, or any similar service and want a reliable path forward, both Developer and Enterprise signing are below.