Which provisioning profiles can install apps
Profile typeInstalls onWatch out for
DevelopmentOnly devices whose UDID is in the profileYour device must be added to the profile
Ad HocOnly devices whose UDID is in the profileYour device must be added to the profile
Enterprise (in-house)Any deviceShared enterprise certificates are revoked often
App StoreCannot install apps directlyUse a Development, Ad Hoc or Enterprise profile instead

Import into iClone or ESign

iClone is built on ESign, so the steps are the same in both apps.

  1. Save the .p12 file and the matching .mobileprovision file in the same folder. The app looks for the profile next to the certificate.
  2. Import both files into the app’s file list, either from the Files app or with the share sheet.
  3. Tap the .p12 file and choose to import it into the certificate library.
  4. Enter the certificate password.
  5. Open certificate management and check that the certificate shows as valid, together with its expiry date.

Import into KSign

Open the certificates section in KSign, add a new certificate, select the .p12 file and the .mobileprovision file, and enter the password. Exact labels can change between KSign versions. KSign 1.5.1 and later no longer accept the .ksign format, so import the original files.

Install iClone with your certificate in one step

If iClone is not installed yet, use online installation. Upload your .p12, password and .mobileprovision. The service checks the certificate with Apple before signing, then gives you an install button. The installed iClone already contains your certificate. Uploaded files are deleted after signing, and the signed app is deleted after 30 minutes.

Common import errors

  • Wrong password: the .p12 password is set by whoever exported the certificate. Ask your certificate provider for it.
  • No matching profile found: the .mobileprovision must belong to the same certificate and be in the same folder as the .p12.
  • Device not included: Development and Ad Hoc profiles only install on listed devices. You can copy your UDID from iClone’s settings and send it to your provider.
  • Expired or revoked: the certificate can no longer sign apps. See what to do when a certificate is revoked.
  • App Store profile: these profiles cannot install apps outside the App Store.

A note on free certificates

Free certificates found online are usually shared enterprise certificates used by many people. Apple revokes them often, and apps may stop opening without warning. A certificate issued for your own device is more reliable. iClone’s partner iOSclone.com offers device certificates.

Get iClone

Download the IPA, or install iClone online with your own certificate. The certificate is imported into iClone automatically.

Frequently asked questions

Can I use the same certificate in ESign, KSign and iClone?

Yes. A certificate is not tied to one signing app. Import the same .p12 and .mobileprovision into each app.

Where do I find my iPhone’s UDID?

iClone and ESign can read the device UDID in their settings, and you can copy it from there.

Why does the app say the certificate does not include this device?

The profile is a Development or Ad Hoc profile that does not list your UDID. Apps signed with it cannot be installed on this iPhone. Ask your provider to add the device or use a profile that includes it.

Does iclone.download keep my certificate?

No. Uploaded certificates, passwords and profiles are used only for the current signing job and are deleted afterwards. The signed app is deleted after 30 minutes.

ESign, KSign and AllInSign are projects or trademarks of their respective developers. iClone is an independent project and is not affiliated with, sponsored by or endorsed by them.