Code Signing React Native Apps

You've built a React Native app and now it's time to get it in the hands of your users. If you're used to web, dealing with mobile-specific deployment issues can be a struggle. There are native build hardware and config requirements, signing certificates, app store approvals, app versions, pushing updates, and more. You also have to consider all the tooling options -- do you manually deploy on your own, use a React Native-specific solution, or try to configure web CI/CD for mobile? This crash course will outline the build and ship process and review some common tools in the React Native ecosystem so you can feel confident deploying and get back to developing.

This talk has been presented at React Summit 2023, check out the latest edition of this React Conference.

Watch video on a separate page

FAQ

To manage signing credentials in the cloud, you need to upload these credentials to your CI-CD platform's environment. AppFlow, for example, allows you to securely store and manage these credentials, which can then be applied automatically during cloud builds or automated workflows.

If you lose your Android Keystore, you can update it using Google Play App Signing. It's crucial to handle your Keystore carefully as it is essential for updating your app in the future.

Yes, AppFlow supports automated deployments to app stores. You can configure automated workflows that trigger builds based on new commits to a specified branch, and automatically deploy the successful builds to the Apple App Store or the Google Play Store.

To start a new build in AppFlow, select your commit, choose a build target (Android or iOS), select the build stack, and choose the build type and signing credentials. You can also define custom environments or configurations, which AppFlow will use to create the build according to your specifications.

AppFlow provides a comprehensive suite for mobile CI-CD, handling native iOS and Android builds in the cloud. Features include management of signing credentials, on-demand builds, automated workflows, and automated deployments to app stores, along with support for custom environments or configurations during the build process.

For iOS apps, you need a signing certificate and a provisioning profile. The signing certificate (.P12 file) validates the identity of the developer, while the provisioning profile specifies the devices the app can run on. Both credentials require an Apple Developer Program account for generation.

To generate a signed bundle for Android, you need to create an upload Keystore using Android Studio or the Keytool CLI tool. This involves noting the Keystore path, alias, and passwords. Once created, the Keystore information must be added to the signing config block within the app.build.gradle file in your project.

Code signing is a critical step in the app development process for React Native apps, involving signing the app with secure credentials during the build process. This ensures that the app is authenticated and can run on mobile devices. It is mandatory for both iOS and Android platforms.

Cecelia Martinez
Cecelia Martinez
7 min
06 Jun, 2023

Comments

Sign in or register to post your comment.
Video Summary and Transcription
Code signing is a critical step in preparing React Native apps for mobile devices. Generating a signed bundle requires different credentials for Android and iOS. Automating signed builds using a cloud CI-CD provider like AppFlow simplifies the process. AppFlow handles native iOS and Android builds in the cloud, including managing signing credentials. It allows for on-demand builds, automated workflows, and deployment to app stores.

1. Code Signing React Native Apps

Short description:

Code signing is a critical step in preparing your React Native apps to run on mobile devices. To generate a signed bundle of your React Native app for Android, you'll need to generate an upload Keystore. For iOS apps, you need two credentials, a signing certificate, and a provisioning profile.

Hello, I'm Cecilia Martinez, Developer Advocate for AppFlow, the mobile CI CD platform built by Ionic. This is Code Signing React Native Apps. Code signing is a critical step in preparing your React Native apps to run on mobile devices. This process signs your app with secure credentials during the build process. It's required by both iOS and Android apps, but the process is different for each platform. If you plan to automate your mobile builds in CI CD, you'll need to make sure that your credentials are in your cloud environment, so understanding how they work is critical for a seamless app delivery process.

Let's start with Android. To generate a signed bundle of your React Native app for Android, you'll need to generate an upload Keystore. During the process of generating it, you want to make sure that you take note of the Keystore path, alias, Keystore password and key password. An upload Keystore can be generated in Android Studio or by using Keytool, which is a CLI tool that comes built into the Android Studio SDK. Make sure not to lose the file, as it lives on for the life of the application, although if you do lose it, you can update it if needed, but only if you're using Google Play App Signing. To generate an Android Studio, click the Generate Signed Bundle, or APK, and then follow the instructions to generate a key. Make sure to take note of the path where the Keystore is saved and the alias and passwords. For Keytool, you're going to run the Keytool command with the genKey flag and then pass the keystore file name, alias, algorithm, size, the length of the time before it expires, and the store type. The CLI will prompt you for your information and then create the Keystore in the same directory that you run the command. You can complete the process of generating a sign bundle in Android Studio, but if you want to build via the command line or in CICD, you're going to need to add your Keystore info to the signing config block within your app.build.gradle file in your React Native project. This lets Gradle know where to find your signing credentials when it's time to build.

Things get a little more complicated with Apple. For iOS apps, you need two credentials, a signing certificate, and a provisioning profile. You do need an Apple Developer Program account in order to generate these. And if you plan to use Xcode for generation, make sure that you connect that Apple Developer Program account to Xcode. Signing certificates validate the identity of who generated the build and that they're authorized to do so. This is a P12 file. To generate an Xcode, you can do this by going to Settings, then Accounts, and then Manage Certificates. Click the plus icon and select the certificate type. You can then right click and export the P12 certificate, making sure that you give it a strong password. To generate a signed certificate from the Apple Developer Program, you're first going to need to generate a signed certificate request file. This is done using Certificate Assistant and Keychain Access. Then upload that request file to the Apple Developer Program to create a certificate. This will generate a .cer file, which then you can use Keychain Access or OpenSSL to convert to a P12.

2. Signing and Automating Builds with AppFlow

Short description:

To generate a signed bundle of your React Native app, you'll need to generate an upload Keystore for Android and a signing certificate and provisioning profile for iOS. If you're doing a development or ad hoc build, you will have to register your devices in the Apple Developer Program to create the Provisioning Profile. Automating signed builds using a cloud CI-CD provider can be tricky, but AppFlow makes it easier. AppFlow is the mobile CI-CD platform built by Ionic that handles your native iOS and Android builds in the cloud, including the management of signing credentials. You can upload your credentials to the AppFlow dashboard and use them for on-demand builds or automated workflows. AppFlow takes care of altering your React Native Gradle config and allows you to select the signing credentials and build specifications for each build. You can also create automated workflows and deploy to the Apple App Store or Google Play Store.

For Keychain Access, you'll go ahead and double-click that .cer file and export it as a P12. Now that you have your signed certificate, the next is the Provisioning Profile. A Provisioning Profile states what devices a signed bundle can run on. If you're doing a development or ad hoc build, you will have to register your devices in Apple Developer Program in order to create the Provisioning Profile.

You can register devices in ADP, or you can connect them to Xcode manually in order to register. If you're building locally in Xcode and using automatic signing, Xcode will build the mobile provisioning profile for you based on the build type that you select. To create a new provisioning profile in the Apple Developer Program, you'll select the profile type, the app, and then your signed certificate and any devices. You'll finally give it a name and generate. Then you can download the mobile provisioning profile or access it in Xcode if you plan to build manually.

Now, if you want to automate signed builds using a cloud CI-CD provider, you need to make sure that these credentials are in your cloud environment. This can be tricky and will vary between CI-CD providers. You'll also need to update your signing config to file check if you're in a CI environment and then dynamically apply the signing credentials from your CI provider. This will also require some customization of your workflow file. Fortunately, AppFlow makes all this much easier. AppFlow is the mobile CI-CD platform built by Ionic. It handles your native iOS and Android builds in the cloud including the management of your signing credentials. You can use these credentials for on-demand builds or in automated workflows.

In the AppFlow dashboard, you simply upload your Android or your Apple credentials and you save them. Now, they can be used by any member of your team to generate signed builds. This makes it easy to identify different signing credentials used for development, ad hoc or app store build. The best part is you don't need to alter your React Native Gradle config. AppFlow takes care of that for you. You can select the signing credentials to use from the new build screen for an on-demand or from the automation screen when building out an automated workflow. AppFlow will create a cloud build environment to create native Android or iOS builds for your application.

For an on-demand build, start a new build by selecting which commit to use, then select a build target of either Android or iOS and the build stack. Select a build type and which signing credentials you want to use. And AppFlow also lets you optionally define custom environments or native configurations to use during the build. AppFlow will then create a build based on your specifications. The process is similar for automations. You create an automated workflow by specifying which branch to trigger the workflow when a new commit is pushed. Then, you'll configure the build that will kick off automatically for each commit. You can also automatically deploy to a set destination in the Apple App Store or the Google Play Store so your new build is ready to release.

If you'd like to learn more about mobile CICD and AppFlow, scan the QR code for a copy of our free e-book and contact us at appflow.ionic.io with any questions.

Check out more articles and videos

We constantly think of articles and videos that might spark Git people interest / skill us up or help building a stellar career

Raising the Bar: Our Journey Making React Native a Preferred Choice
React Advanced 2023React Advanced 2023
29 min
Raising the Bar: Our Journey Making React Native a Preferred Choice
Watch video: Raising the Bar: Our Journey Making React Native a Preferred Choice
This Talk discusses Rack Native at Microsoft and the efforts to improve code integration, developer experience, and leadership goals. The goal is to extend Rack Native to any app, utilize web code, and increase developer velocity. Implementing web APIs for React Native is being explored, as well as collaboration with Meta. The ultimate aim is to make web code into universal code and enable developers to write code once and have it work on all platforms.
Opensource Documentation—Tales from React and React Native
React Finland 2021React Finland 2021
27 min
Opensource Documentation—Tales from React and React Native
Documentation is often your community's first point of contact with your project and their daily companion at work. So why is documentation the last thing that gets done, and how can we do it better? This talk shares how important documentation is for React and React Native and how you can invest in or contribute to making your favourite project's docs to build a thriving community
Bringing React Server Components to React Native
React Day Berlin 2023React Day Berlin 2023
29 min
Bringing React Server Components to React Native
Top Content
Watch video: Bringing React Server Components to React Native
React Server Components (RSC) offer a more accessible approach within the React model, addressing challenges like big initial bundle size and unnecessary data over the network. RSC can benefit React Native development by adding a new server layer and enabling faster requests. They also allow for faster publishing of changes in mobile apps and can be integrated into federated super apps. However, implementing RSC in mobile apps requires careful consideration of offline-first apps, caching, and Apple's review process.
React Native Kotlin Multiplatform Toolkit
React Day Berlin 2022React Day Berlin 2022
26 min
React Native Kotlin Multiplatform Toolkit
Top Content
The Talk discusses the combination of React Native and Kotlin Multiplatform for cross-platform app development. Challenges with native modules in React Native are addressed, and the potential improvements of using Kotlin Multiplatform Mobile are explored. The integration of Kotlin Multiplatform with React Native streamlines native implementation and eliminates boilerplate code. Questions about architecture and compatibility, as well as the possibility of supporting React Native Web, are discussed. The React Native toolkit works with native animations and has potential for open-source development.
Building Cross-Platform Component Libraries for Web and Native with React
React Advanced 2021React Advanced 2021
21 min
Building Cross-Platform Component Libraries for Web and Native with React
Top Content
This Talk discusses building cross-platform component libraries for React and React Native, based on a successful project with a large government-owned news organization. It covers the requirements for React Native knowledge, building cross-platform components, platform-specific components, styling, and the tools used. The Talk also highlights the challenges of implementing responsive design in React Native.
MDX in React-Native!?
React Advanced 2021React Advanced 2021
21 min
MDX in React-Native!?
Top Content
This Talk is about the development of MDX, a combination of Markdown and JSX, by a freelance full stack JavaScript developer. MDX is a powerful technology that allows for the creation of interactive content within blog posts and supports React components. The speaker developed RnMDX, a proper and polished MDX library for React Native, which can be dropped into any React Native app. RnMDX provides solutions for common issues with Markdown content in React Native and allows for the rendering of MDX content into native views. Bringing MDX into native apps is now easier, and it can be used for various purposes, such as serving the app layout from a CMS or creating interactive online magazines or blogs.

Workshops on related topic

Introducing FlashList: Let's build a performant React Native list all together
React Advanced 2022React Advanced 2022
81 min
Introducing FlashList: Let's build a performant React Native list all together
Top Content
WorkshopFree
David Cortés Fulla
Marek Fořt
Talha Naqvi
3 authors
In this workshop you’ll learn why we created FlashList at Shopify and how you can use it in your code today. We will show you how to take a list that is not performant in FlatList and make it performant using FlashList with minimum effort. We will use tools like Flipper, our own benchmarking code, and teach you how the FlashList API can cover more complex use cases and still keep a top-notch performance.You will know:- Quick presentation about what FlashList, why we built, etc.- Migrating from FlatList to FlashList- Teaching how to write a performant list- Utilizing the tools provided by FlashList library (mainly the useBenchmark hook)- Using the Flipper plugins (flame graph, our lists profiler, UI & JS FPS profiler, etc.)- Optimizing performance of FlashList by using more advanced props like `getType`- 5-6 sample tasks where we’ll uncover and fix issues together- Q&A with Shopify team
Detox 101: How to write stable end-to-end tests for your React Native application
React Summit 2022React Summit 2022
117 min
Detox 101: How to write stable end-to-end tests for your React Native application
Top Content
WorkshopFree
Yevheniia Hlovatska
Yevheniia Hlovatska
Compared to unit testing, end-to-end testing aims to interact with your application just like a real user. And as we all know it can be pretty challenging. Especially when we talk about Mobile applications.
Tests rely on many conditions and are considered to be slow and flaky. On the other hand - end-to-end tests can give the greatest confidence that your app is working. And if done right - can become an amazing tool for boosting developer velocity.
Detox is a gray-box end-to-end testing framework for mobile apps. Developed by Wix to solve the problem of slowness and flakiness and used by React Native itself as its E2E testing tool.
Join me on this workshop to learn how to make your mobile end-to-end tests with Detox rock.
Prerequisites- iOS/Android: MacOS Catalina or newer- Android only: Linux- Install before the workshop
How to Build an Interactive “Wheel of Fortune” Animation with React Native
React Summit Remote Edition 2021React Summit Remote Edition 2021
60 min
How to Build an Interactive “Wheel of Fortune” Animation with React Native
Top Content
Workshop
Oli Bates
Oli Bates
- Intro - Cleo & our mission- What we want to build, how it fits into our product & purpose, run through designs- Getting started with environment set up & “hello world”- Intro to React Native Animation- Step 1: Spinning the wheel on a button press- Step 2: Dragging the wheel to give it velocity- Step 3: Adding friction to the wheel to slow it down- Step 4 (stretch): Adding haptics for an immersive feel
Deploying React Native Apps in the Cloud
React Summit 2023React Summit 2023
88 min
Deploying React Native Apps in the Cloud
WorkshopFree
Cecelia Martinez
Cecelia Martinez
Deploying React Native apps manually on a local machine can be complex. The differences between Android and iOS require developers to use specific tools and processes for each platform, including hardware requirements for iOS. Manual deployments also make it difficult to manage signing credentials, environment configurations, track releases, and to collaborate as a team.
Appflow is the cloud mobile DevOps platform built by Ionic. Using a service like Appflow to build React Native apps not only provides access to powerful computing resources, it can simplify the deployment process by providing a centralized environment for managing and distributing your app to multiple platforms. This can save time and resources, enable collaboration, as well as improve the overall reliability and scalability of an app.
In this workshop, you’ll deploy a React Native application for delivery to Android and iOS test devices using Appflow. You’ll also learn the steps for publishing to Google Play and Apple App Stores. No previous experience with deploying native applications is required, and you’ll come away with a deeper understanding of the mobile deployment process and best practices for how to use a cloud mobile DevOps platform to ship quickly at scale.
Effective Detox Testing
React Advanced 2023React Advanced 2023
159 min
Effective Detox Testing
Workshop
Josh Justice
Josh Justice
So you’ve gotten Detox set up to test your React Native application. Good work! But you aren’t done yet: there are still a lot of questions you need to answer. How many tests do you write? When and where do you run them? How do you ensure there is test data available? What do you do about parts of your app that use mobile APIs that are difficult to automate? You could sink a lot of effort into these things—is the payoff worth it?
In this three-hour workshop we’ll address these questions by discussing how to integrate Detox into your development workflow. You’ll walk away with the skills and information you need to make Detox testing a natural and productive part of day-to-day development.
Table of contents:
- Deciding what to test with Detox vs React Native Testing Library vs manual testing- Setting up a fake API layer for testing- Getting Detox running on CI on GitHub Actions for free- Deciding how much of your app to test with Detox: a sliding scale- Fitting Detox into you local development workflow
Prerequisites
- Familiarity with building applications with React Native- Basic experience with Detox- Machine setup: a working React Native CLI development environment including either Xcode or Android Studio
Building for Web & Mobile with Expo
React Day Berlin 2022React Day Berlin 2022
155 min
Building for Web & Mobile with Expo
Workshop
Josh Justice
Josh Justice
We know that React is for the web and React Native is for Android and iOS. But have you heard of react-native-web—for writing an app for Android, iOS, and the web in one codebase? Just like React Native abstracts away the details of iOS and Android, React Native Web extracts away the details of the browser as well. This opens up the possibility of even more code sharing across platforms.
In this workshop you’ll walk through setting up the skeleton for a React Native Web app that works great and looks awesome. You can use the resulting codebase as a foundation to build whatever app you like on top of it, using the React paradigms and many JavaScript libraries you’re used to. You might be surprised how many types of app don’t really require a separate mobile and web codebase!
What's included1. Setting up drawer and stack navigators with React Navigation, including responsiveness2. Configuring React Navigation with URLs3. Setting up React Native Paper including styling the React Navigation drawer and headers4. Setting up a custom color theme that supports dark mode5. Configuring favicons/app icons and metadata6. What to do when you can’t or don’t want to provide the same functionality on web and mobile
Prerequisites- Familiarity with building applications with either React or React Native. You do not need to know both.- Machine setup: Node LTS, Yarn, be able to successfully create and run a new Expo app following the instructions on https://docs.expo.dev/get-started/create-a-new-app/