Unique App ID prefix migration stalled; Mac App Store validation fails with 90286/91130 on a universal-purchase app

My two apps, com.qrafter.Qrafter and com.qrafter.QrafterPro, have been on the iOS App Store since 2011, and their App IDs still use my team's unique App ID prefix 99T3FA87E9 instead of the Team ID GH4CGS3B5H. I'm adding native Mac versions to the same App Store records (universal purchase), so the bundle IDs can't change.

Every profile Apple generates for these App IDs pairs com.apple.application-identifier = 99T3FA87E9.com.qrafter.Qrafter with com.apple.developer.team-identifier = GH4CGS3B5H. iOS uploads are accepted, but Mac App Store validation (xcrun altool --validate-app -t macos) rejects even a minimal one-window app with exactly two errors:

Invalid code signing entitlements. … the "99T3FA87E9.com.qrafter.Qrafter" value for the com.apple.application-identifier key … isn't supported. This value should be a string that starts with your Team ID, followed by a dot ("."), followed by the bundle ID. (90286)

Invalid Provisioning Profile. … Invalid 'com.apple.application-identifier' entitlement value. (91130)

Following "Code Signing Identifiers Explained" (thread 811970), I requested the prefix migration through Contact Us on 4 September (case 102953576372). On 20 September Developer Support asked me to confirm the one-time keychain data loss described in "App ID Prefix Change and Keychain Access" (thread 706128), and I confirmed. Since then the case has had no reply despite follow-ups on 24 and 29 September, and as of 6 October both App IDs still show 99T3FA87E9.

Two questions:

  1. Is there anything else I need to do to get case 102953576372 completed, or a better route to escalate it?
  2. Is there any way to ship a Mac App Store build for these App IDs before the migration, or is the migration the only path?

I have a minimal sample project and the full validation log if that helps.

Answered by DTS Engineer in 908131022
1- Is there anything else I need to do to get case 102953576372 completed … ?

I can’t really answer that. This case is being handled by DevPrograms and I don’t have visibility into it. However, my experience helping other developers in this case is that the answer is “Nothing other than wait.”

1- Is … a better route to escalate it?

No.

2- Is there any way to ship a Mac App Store build for these App IDs before the migration … ?

No [1].

I’ve helped a bunch of developers down this path over the years and it does work, but it can take a while for DevPrograms to enact the change.

FWIW, the main gotchas here are:

  • Keychain access — See App ID Prefix Change and Keychain Access.
  • App extensions — If your app has app extensions, make sure to request that they be migrated as well.
  • Rebuild — Once the App ID prefix has changed, you have to prod Xcode a bit to get it to rebuild all your provisioning profiles.

Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

[1] Well, technically your existing iOS binary will run an Apple silicon via iOS Apps on Mac, assuming you haven’t opted out of that. But that’s not really what your aiming for here.

Accepted Answer
1- Is there anything else I need to do to get case 102953576372 completed … ?

I can’t really answer that. This case is being handled by DevPrograms and I don’t have visibility into it. However, my experience helping other developers in this case is that the answer is “Nothing other than wait.”

1- Is … a better route to escalate it?

No.

2- Is there any way to ship a Mac App Store build for these App IDs before the migration … ?

No [1].

I’ve helped a bunch of developers down this path over the years and it does work, but it can take a while for DevPrograms to enact the change.

FWIW, the main gotchas here are:

  • Keychain access — See App ID Prefix Change and Keychain Access.
  • App extensions — If your app has app extensions, make sure to request that they be migrated as well.
  • Rebuild — Once the App ID prefix has changed, you have to prod Xcode a bit to get it to rebuild all your provisioning profiles.

Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

[1] Well, technically your existing iOS binary will run an Apple silicon via iOS Apps on Mac, assuming you haven’t opted out of that. But that’s not really what your aiming for here.

Thank you, Quinn, that's very helpful.

Thanks also for the list of gotchas. The keychain change is fine for me, and the current extensions and watch apps already use the Team ID.

I'll update this thread once the migration goes through, so anyone who finds it later knows how long it took. As it has been more than 2 weeks since the last communication from them, I am not holding my breath though.

Unique App ID prefix migration stalled; Mac App Store validation fails with 90286/91130 on a universal-purchase app
 
 
Q