← 返回
安全合规 中文

App Store

Publish and manage iOS and Android apps with account setup, submission workflows, review compliance, and rejection handling.
发布与管理iOS及Android应用,涵盖账号设置、提交流程、审核合规及驳回处理。
ivangdavila
安全合规 clawhub v1.0.0 1 版本 99777.6 Key: 无需
★ 3
Stars
📥 1,286
下载
💾 24
安装
1
版本
#latest

概述

Scope

App Store Connect (iOS) and Google Play Console (Android). Covers the full publishing lifecycle from account creation to updates. For keyword optimization, see app-store-optimization skill.


Account Setup

PlatformCostTimeKey Steps
---------------------------------
Apple Developer Program$99/year1-7 daysEnroll → D-U-N-S (orgs) → Payment → Agreements
Google Play Console$25 onceMinutes-48hRegister → Identity verification → Payment profile

Apple gotchas:

  • D-U-N-S number required for organizations (free, takes 1-2 weeks)
  • Legal entity name must match D-U-N-S exactly
  • Agreements (Paid Apps, Apple Pay) must be accepted before features work

Google gotchas:

  • Identity verification can take 48h+ for new accounts
  • Closed testing track required before production (20+ testers, 14+ days for new apps since 2023)

iOS Signing (The Hard Part)

AssetWhat It IsWhere CreatedExpires
-------------------------------------------
Distribution CertificateYour signing identityKeychain → App Store Connect1 year
Provisioning ProfileLinks cert + app ID + devicesApp Store Connect1 year
App IDUnique identifier (bundle ID)App Store ConnectNever

When Xcode says "No signing identity":

  1. Check certificate exists in Keychain Access (login keychain)
  2. Check provisioning profile includes that certificate
  3. Check bundle ID in Xcode matches App ID exactly
  4. Revoke and recreate if nothing else works

Automatic vs Manual Signing:

  • Automatic: Xcode manages everything (fine for solo devs)
  • Manual: Required for CI/CD, teams, or multiple apps
  • Never mix — pick one approach per project

Submission Checklist

Pre-submit verification (both platforms):

  • [ ] Privacy policy URL live and accessible
  • [ ] All required permissions have usage descriptions
  • [ ] App works without network (or handles offline gracefully)
  • [ ] No placeholder content, "lorem ipsum", or test data
  • [ ] Screenshots match actual app UI (no misleading marketing)
  • [ ] Contact support email valid and monitored

iOS-specific:

  • [ ] Export Compliance (ITSAppUsesNonExemptEncryption in Info.plist)
  • [ ] App Tracking Transparency if using IDFA
  • [ ] Privacy manifest (PrivacyInfo.xcprivacy) for required APIs

Android-specific:

  • [ ] Target SDK meets current requirement (currently API 34)
  • [ ] Data safety form completed
  • [ ] Content rating questionnaire filled
  • [ ] 20+ testers on closed track for 14+ days (new apps)

Common Rejections

CodeMeaningFix
--------------------
4.2 (iOS)Minimum functionalityAdd features, or argue value proposition in appeal
4.3 (iOS)Spam/duplicateDifferentiate significantly from your other apps
5.1.1 (iOS)Data collectionImplement App Tracking Transparency, update privacy manifest
2.1 (iOS)Crashes/bugsTest on real devices, check Crashlytics
Deceptive behavior (Android)Misleading metadataMatch screenshots to real functionality
Broken functionality (Android)App doesn't work as describedFull QA on production build

Appeal strategy:

  1. Read rejection reason carefully (don't assume)
  2. If misunderstanding: Explain with screenshots, video if needed
  3. If valid: Fix issue, note what changed in resolution notes
  4. Never resubmit identical binary hoping for different reviewer

Review Timeline

PlatformTypicalExpeditedSlower Periods
----------------------------------------------
Apple24-48hRequest via App Review formNew iOS launches, holidays
Google2-6hN/AInitial submissions, policy violations

Apple expedited review: Only for critical bugs, time-sensitive events. Overuse = ignored.


Monetization Setup

In-app purchases (IAP):

  1. Create products in App Store Connect / Play Console
  2. Implement StoreKit (iOS) / BillingClient (Android)
  3. Set up server-side receipt validation (don't trust client)
  4. Handle sandbox vs production environments

Subscriptions:

  • Configure introductory offers, free trials, grace periods
  • Implement subscription lifecycle: renewal, cancellation, billing retry
  • Server notifications endpoint for real-time status updates
  • Test with sandbox accounts (both platforms have quirks)

Revenue splits: Apple/Google take 15-30% (15% for Small Business Program or after year 1 of subscription).


Multi-App Management

Organization structure:

  • Apple: One enrollment, multiple apps, team roles per app
  • Google: One developer account, multiple apps, user permissions

Team roles (critical):

  • Separate "submit builds" from "release to production"
  • Marketing should access metadata only
  • Finance sees revenue, not code

Cross-platform releases:

  • Submit iOS first (longer review)
  • Hold Android release until iOS approved
  • Use phased rollout to catch issues early

When to Load More

SituationReference
----------------------
Keyword optimization, A/B testingapp-store-optimization skill
Generating release notes from gitapp-store-changelog skill
TestFlight/internal testing setuptesting.md
CI/CD automation (fastlane, APIs)automation.md

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-03-29 04:08 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

ai-intelligence

Self-Improving + Proactive Agent

ivangdavila
自我反思+自我批评+自我学习+自组织记忆。智能体评估自身工作、发现错误并持续改进。
★ 1,350 📥 317,745
security-compliance

Skill Vetter

spclaudehome
AI智能体技能安全预审工具。安装ClawdHub、GitHub等来源技能前,检查风险信号、权限范围及可疑模式。
★ 1,211 📥 266,210
security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,701