Guideline 4.7.2 – Native capabilities for signed B2B HTML5/JavaScript mini apps

Guideline 4.7.2 – Native capabilities for signed B2B HTML5/JavaScript mini apps

We are developing a B2B iOS application using .NET MAUI.

The application acts as a host for dynamically downloaded HTML5/JavaScript mini apps displayed inside a WebView/HybridWebView.

The mini apps are created and distributed exclusively by us. Third parties and end users cannot upload or provide their own mini apps.

Each mini app package is digitally signed by us, and the host application verifies its signature and integrity before allowing it to run.

The mini apps contain only HTML, CSS and JavaScript and do not contain downloaded native executable code.

Some mini apps need access to a very small, predefined set of capabilities implemented by the native host application, for example:

  • Take a photo
  • Scan a QR code or barcode
  • Select a file
  • Potentially print to a supported printer

For example, a mini app could call a predefined JavaScript bridge method such as:

TakePhoto()

The .NET MAUI host application would then present the native iOS camera UI and return the result to that specific mini app.

The mini apps would not receive unrestricted access to native iOS APIs. Only an explicitly defined allowlist of host capabilities would be exposed.

Access to privacy-sensitive capabilities such as the camera would only occur following an explicit user action, and the normal iOS permission flow would still apply.

Would this architecture be acceptable under App Review Guideline 4.7.2?

Does the fact that this is a controlled B2B environment, where all mini apps are created, signed, distributed and verified exclusively by us, affect the requirement for prior permission from Apple?

If prior permission is still required, what is the correct process for requesting that permission before submitting the application for App Review?

Guideline 4.7.2 – Native capabilities for signed B2B HTML5/JavaScript mini apps
 
 
Q