Guide

Publish an iOS app to the App Store without owning a Mac

You can publish an iOS app without owning a Mac. You cannot do it without macOS. Building and signing the app needs Xcode. Almost everything else happens in a browser or on your iPhone. A rented Mac or a CI runner covers the one step that needs macOS.

What Apple requires in October 2026

  • A paid membership. The Apple Developer Program is 99 USD per membership year, per Apple's enrollment page. Nonprofits, schools and government bodies can ask for a fee waiver.
  • A recent Xcode. Since April 28, 2026, uploads must be built with Xcode 26 or later and an iOS 26 SDK. That is on Apple's upcoming requirements page.
  • A recent macOS. Xcode 26.6 needs macOS Tahoe 26.2 or later, per Apple's Xcode system requirements.

So the build happens on a Mac. The question is only whose Mac.

What you can do from Windows or Linux

  • Enroll in the program on the web or in the Apple Developer app.
  • Create the app record in App Store Connect.
  • Create an App Store Connect API key (steps below).
  • Add testers, write the store listing and submit for review.
  • Upload a finished build. Apple's Transporter command-line tool supports Windows 11 and Red Hat Enterprise Linux. On those systems it needs the AppStoreInfo.plist that Xcode writes on export. So the upload can run on your PC, but the file still comes from a Mac.

Create an API key first

An API key lets tools on the Mac talk to Apple. No password or two-factor prompt is needed. Apple's steps for a team key:

  • In App Store Connect, open Users and Access, then Integrations.
  • Choose App Store Connect API, then the Team Keys tab.
  • Click Generate API Key, name it, pick a role, and generate.
  • Download the .p8 file. Apple lets you download it once only.

You need the Admin role to create team keys. Write down the Key ID and the Issuer ID shown on that page. Keep the .p8 out of your repository.

Signing without a keychain of your own

Signing needs a distribution certificate and a provisioning profile. There are two ways to get them on a Mac you rent.

Automatic signing. xcodebuild accepts the API key. With the allowProvisioningUpdates flag, its help text says it will create and update profiles, app IDs and certificates for automatically signed targets. Apple also offers cloud-managed distribution certificates. Apple keeps those, so no private key sits on the rented machine.

Manual signing. Create a certificate signing request with Keychain Access on the rented Mac. Then make an Apple Distribution certificate and an App Store profile in Certificates, Identifiers and Profiles. Wipe the keychain before you hand the Mac back.

Build and upload from the cloud Mac

Archive the app. Replace the names, the key ID and the issuer ID with yours.

xcodebuild -workspace MyApp.xcworkspace -scheme MyApp \
  -configuration Release -destination 'generic/platform=iOS' \
  -archivePath build/MyApp.xcarchive archive \
  -allowProvisioningUpdates \
  -authenticationKeyPath ~/private_keys/AuthKey_ABC123DEF4.p8 \
  -authenticationKeyID ABC123DEF4 \
  -authenticationKeyIssuerID YOUR-ISSUER-ID

Then export it. With destination set to upload, the export sends the build straight to App Store Connect. The method name app-store-connect replaced the older app-store value.

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>method</key><string>app-store-connect</string>
  <key>destination</key><string>upload</string>
  <key>signingStyle</key><string>automatic</string>
  <key>teamID</key><string>YOURTEAMID</string>
</dict>
</plist>
xcodebuild -exportArchive -archivePath build/MyApp.xcarchive \
  -exportOptionsPlist ExportOptions.plist -exportPath build/export \
  -allowProvisioningUpdates \
  -authenticationKeyPath ~/private_keys/AuthKey_ABC123DEF4.p8 \
  -authenticationKeyID ABC123DEF4 \
  -authenticationKeyIssuerID YOUR-ISSUER-ID

Prefer a separate upload step? Set destination to export, then use altool. It finds the key file in ~/private_keys by its ID.

xcrun altool --upload-package build/export/MyApp.ipa \
  --api-key ABC123DEF4 --api-issuer YOUR-ISSUER-ID

fastlane users can do the same with two actions from its docs: app_store_connect_api_key loads the key, and pilot uploads to TestFlight.

We checked every flag above against the help output of xcodebuild and altool in Xcode 26.6. We have not run a signed upload with these exact lines. Your project's signing setup decides the details.

Version and build numbers

Apple matches each upload to your app by its bundle ID and version number. The build string identifies each build, so it must be unique. Raise the build number for every upload. In CI, the run number is a handy source for it. Keep the version number for what users see in the store.

TestFlight on your iPhone

Apple processes each upload and emails you when it is ready. Then the rest happens in App Store Connect and on the phone. Per Apple's TestFlight overview:

  • Up to 100 internal testers from your App Store Connect team.
  • Up to 10,000 external testers by email or public link.
  • The first build for external testers goes to App Review.
  • Each build can be tested for up to 90 days.

Testers install the free TestFlight app and accept the invite. You do not need a Mac for any of this. Store screenshots are easy to take in the Simulator on the rented Mac.

Who should not rent a Mac for this

On Expo, EAS Build and EAS Submit do the build and upload in Expo's cloud. If you ship twice a year, a hosted CI runner costs cents per build. Read iOS CI/CD with GitHub Actions for that setup. MacRun does not offer managed code signing. You own your certificates and keys.

A rented Mac fits when you ship often. It also fits when you need Xcode's screen to fix signing by hand. Our M6 plans are on the pricing page.

Frequently asked questions

Can you publish an iOS app without a Mac?

+

Yes, if you can reach macOS somewhere. The build and signing need Xcode on a Mac, which can be a rented or cloud Mac. Enrollment, App Store Connect, TestFlight and review all work from a browser or an iPhone.

Can I upload an .ipa to App Store Connect from Windows?

+

Apple's Transporter command-line tool supports Windows 11 and Red Hat Enterprise Linux. On those systems it needs the AppStoreInfo.plist that Xcode exports with the build, so the .ipa still has to be built on a Mac.

Which Xcode do I need to upload in 2026?

+

Since April 28, 2026, Apple requires apps uploaded to App Store Connect to be built with Xcode 26 or later using an iOS 26 SDK. Xcode 26.6 runs on macOS Tahoe 26.2 or later.

How much does it cost to publish on the App Store?

+

The Apple Developer Program is 99 USD per membership year. Fee waivers exist for eligible nonprofits, schools and government bodies. The Mac time for building is extra, from cents per build on hosted CI to a monthly rental.

Related guides