Open an Apple Wallet pass (.pkpass) on Windows or Android
A .pkpass is the file an airline, ticket shop or café sends for Apple Wallet. An iPhone opens it in Wallet; Windows, Android and Linux have nothing that does. Drop it here to see the pass the way Wallet draws it, in its own colours with every field, and its barcode large enough to scan at the gate or the door.
The pass is read on your device. It is not uploaded, and the issuer's update server named in the pass is never contacted.
What it shows
- The front of the pass. Drawn in the pass's own background, text and label colours, with its logo, icon and strip, thumbnail, background or footer picture (whichever its style uses), and the header, primary, secondary and auxiliary fields in Wallet's places. A boarding pass shows its two airports with the flight, train, bus or boat between them.
- The barcode, large. QR, PDF417, Aztec and Code 128, the four formats Wallet supports, drawn with their quiet zone on white so a gate scanner can read them from a phone or laptop screen. The message inside each barcode is shown as text, and each barcode can be saved as a PNG.
- The back of the pass. Terms, contact details, booking references: every back field. Links in them are shown as text and not opened.
- Dates and places. Fields with a date are shown in your own time zone, or as written when the pass says the time is local to the place (a departure time, for example). The relevant date, the expiry date and the places where Wallet would put the pass on the lock screen are listed with their coordinates and lock-screen text.
- Translations. When the pass carries pass.strings files in language folders (en.lproj, de.lproj …), a language picker applies them, and dates and prices are formatted for that language.
- Who issued and signed it. The organisation, pass type ID, team ID and serial number from pass.json; the name in the certificate that signed it, and whether its pass type ID and team ID match; and every file checked against the SHA-1 list in manifest.json, which shows whether anything was changed after the pass was made.
- Bundles. A .pkpasses file (several passes in one, as a group booking arrives) shows every pass in it, one after another.
What it cannot do
- Add the pass to Apple Wallet or Google Wallet. It shows the pass; it does not install it anywhere. On an iPhone, open the file from Mail or Files and Wallet offers Add.
- Verify Apple's signature. viewhack reads the name in the signing certificate, but it does not check the signature's cryptography, that Apple issued the certificate, or whether it was revoked. A pass that looks right here can still be refused by Wallet, and a forged pass can look right here.
- Update the pass. Wallet fetches new versions (a gate change, a new balance) from the web address in the pass. viewhack never contacts that address, so you see the pass as it was when the file was saved; the address is shown as text.
- Send NFC payloads or show Apple Pay cards. A pass with an NFC payload is tapped on a reader by an iPhone; no browser can do that. Payment cards are not .pkpass files at all.
- Draw every newer layout. The iOS 18 "poster" event ticket and the semantic tags some passes carry are not drawn in their own style; their fields are shown in the ordinary layout, and the full pass.json is there to read.
Useful to know about .pkpass files
- What is inside one
- A .pkpass is a ZIP archive.
pass.jsonholds the fields, colours and barcodes; PNG files hold the pictures (usually twice, plain and@2x);manifest.jsonlists the SHA-1 hash of every file; andsignatureis a PKCS#7 signature over that manifest, made with the issuer's Apple "Pass Type ID" certificate. Change one byte of any file and Wallet refuses the pass, which is why the manifest check above is useful. - Why the attachment will not open on Windows or Android
- The file arrives with the type
application/vnd.apple.pkpass, which nothing on Windows or stock Android is registered to open. Renaming it to .zip lets you see the files inside, but not the card or a scannable barcode. - Is a picture of the barcode enough at the gate?
- The barcode in a .pkpass is fixed text written in pass.json, so a clear picture of it scans the same as the pass in Wallet: turn the screen brightness up and hold it flat. Two cautions: an issuer can push a newer version of the pass (with a new barcode) to Wallet through its web service, which a saved file never receives; and some event tickets refuse static barcodes and only work in the issuer's own app.
- What a boarding pass barcode says
- Airlines use the IATA “BCBP” text in the barcode, and anyone who reads it can see what it holds. Its fields have fixed widths, so the spaces count. For example
M1BJORNSEN/KARI EXK7Q2P OSLCPHSK 1467 287Y012A0042 100is one flight leg (M1) for passenger Kari Bjørnsen (writtenBJORNSEN/KARI: the format allows only plain letters), electronic ticket (E), booking referenceXK7Q2P, from Oslo (OSL) to Copenhagen (CPH) on SK 1467, on day 287 of the year (14 October in 2026), cabinY, seat 12A, check-in sequence number 42. The surname and booking reference are enough to log in to most airlines' “manage booking” pages, which is why a boarding pass should not be posted online. - Which barcode formats exist
- Wallet draws only four: QR and Aztec (square, used by most event tickets and European rail), PDF417 (wide and stacked, used by most airlines) and Code 128 (a one-line barcode, used by shops and loyalty cards; Apple Watch cannot show it). A pass may list several; Wallet shows the first one the device supports. This page draws all of them.