viewhack

IPA viewer: look inside an iPhone app

Got an .ipa from a developer, a company, a beta tester or a sideloading site? See what it is without a Mac: its name, version and build, the iOS it needs, every permission prompt it can show you in its own words, when its provisioning profile runs out, which devices it is allowed on, and who signed it.

The file is read by this tab only. It is not uploaded, not installed and not run.

What it shows

What it cannot do

Useful to know about .ipa files

What an .ipa is
A ZIP archive with one folder, Payload/, holding the app bundle Name.app. Rename a copy to .zip and any unzip tool opens it. Inside the bundle are the executable (a Mach-O file, sometimes a "fat" one with several processor slices), Info.plist, the signature's seal in _CodeSignature/, the resources, and, for anything but an App Store download, embedded.mobileprovision.
Profile kinds
A Development profile lists test devices and lets a debugger attach (get-task-allow is true). Ad Hoc also lists devices, up to 100 of each device type per membership year, and is how most test builds are shared. Enterprise (in-house) has no device list and installs on any device that trusts the company; Apple revokes these certificates when they are shared publicly. An App Store profile is only for uploading; Apple re-signs the app it ships to customers.
When it stops working
Paid-account Development and Ad Hoc profiles last up to a year. Profiles made with a free Apple ID, as AltStore and Sideloadly use, last 7 days, which is why sideloaded apps need refreshing every week. Once the profile has expired, iOS will not launch the app until it is re-signed. The expiry shown here is the profile's ExpirationDate, compared with your device's clock.
Permission prompts
Since iOS 10, an app that touches the camera, microphone, photos, contacts or calendars without the matching NS…UsageDescription key is closed by iOS. So the list here covers the protected data the app can ask for, and the text is what you would read in the prompt. Location has two levels: "While Using" and, asked separately later, "Always".
Encrypted or not
cryptid 1 means the code pages are FairPlay-encrypted, which is how every App Store download arrives. A developer, Ad Hoc or Enterprise build has cryptid 0, as does an App Store app that was decrypted on a device. An App Store .ipa with cryptid 1 cannot be re-signed into a working sideload, because only the buyer's devices can decrypt its code.