Security and access
Security and access
Patch separates who can publish updates (CLI and dashboard auth) from whether clients trust updates (optional code signing).
Authentication
Dashboard sign-in
Sign-in uses GitHub, Bitbucket Cloud, or GitLab OAuth. Installs with domains require at least one configured provider; the first admin email must match the verified primary address on that account when REGISTRATION_MODE=invite_only.
See Install for OAuth app setup.
CLI sign-in
- React Native
- Capacitor
Developers sign in through the browser — cmpatch login opens the dashboard and completes over a localhost redirect (pass --token to sign in with a personal access token instead):
cmpatch login --server-url https://updates.example.com
In a project set up with cmpatch init, the server URL is already known and
cmpatch login needs no flag. Credentials are stored locally in ~/.codemagic-patch/.
cmpatch-capacitor login opens the dashboard in a browser and completes sign-in through a localhost redirect. To sign in with a personal access token, pass --token:
cmpatch-capacitor login --server-url https://updates.example.com
If CODEMAGIC_PATCH_SERVER_URL or a default server (cmpatch-capacitor config set --server-url) is set, --server-url is not needed. Credentials are stored in ~/.codemagic-patch/credentials-capacitor.json, readable only by your user and separate from cmpatch credentials. --no-browser prints the sign-in URL instead of opening it. The URL must be opened on the same machine, so use --token over SSH.
API tokens (CI and automation)
For CI and scripting, create personal access tokens:
- React Native
- Capacitor
cmpatch token create --name ci
cmpatch-capacitor token create --name ci --expires-in-days 365
- Prefix:
cm_pat_… - Shown once at creation: store in your secret manager
- Supply via
CODEMAGIC_PATCH_TOKENor--token - Revoke with
token revoke(or from the dashboard) when compromised
Treat cm_pat_… tokens like production credentials. Scope pipeline access and rotate on schedule.
Auth precedence
--token → CODEMAGIC_PATCH_TOKEN → the credential stored by login
Code signing (update integrity)
Beyond server authentication, Patch supports cryptographic signing of release manifests so clients only install packages signed with your private key.
Enable at app creation or later:
- React Native
- Capacitor
cmpatch app create --name MySignedApp-iOS --require-code-signing
cmpatch app setting --app MyApp-iOS --require-code-signing=true
cmpatch-capacitor app create --name MySignedApp-iOS --require-code-signing
cmpatch-capacitor app setting --app MyApp-iOS --require-code-signing=true
Create a private and public key pair with OpenSSL:
# generate private RSA key
openssl genrsa -out patch-private-key.pem 2048
# export public key
openssl rsa -in patch-private-key.pem -pubout -out patch-public-key.pem
- React Native
- Capacitor
Copy the public key (cat patch-public-key.pem, including the BEGIN / END lines) into native config as CodemagicPatchPublicKey. See Native setup for Info.plist, strings.xml, or Expo plugin wiring.
Copy the public key (cat patch-public-key.pem, including the BEGIN / END lines) into capacitor.config.ts as publicKey in each platform block. A CodemagicPatchPublicKey native resource overrides this value. See Native setup.
Publish signed releases with the private key:
- React Native
- Capacitor
cmpatch release-react --platform ios --deployment Staging \
--private-key-path ./patch-private-key.pem --yes
cmpatch-capacitor release create --bundle-path www \
--app MyApp-iOS --deployment Staging --target-binary-version "1.2.0" \
--private-key-path ./patch-private-key.pem
The signature is an RS256 JWT of the bundle's package hash. The SDK verifies it on the device.
- React Native
- Capacitor
When building a .cmpatch artifact with code signing enabled, pass --private-key-path to cmpatch bundle as well.
cmpatch-capacitor release create signs the bundle during upload; there is no separate bundle step.
The SDK reads the public key from the binary at launch, so ship a new native build (and reinstall on devices) before clients can verify signed OTAs. OTA updates cannot add or change the public key.
With the key in the binary, the client rejects releases with missing or invalid signatures.
If no public key is configured, the client does not verify signatures and installs both signed and unsigned releases.
Server secrets
.env.selfhost contains production secrets (Postgres, MinIO, OAuth, worker keys). Back it up and never commit it. See Configuration reference.
CI hygiene
- Store
CODEMAGIC_PATCH_TOKENin CI secret stores only - Use separate tokens per pipeline or environment where possible
- Release to Staging before Production (CI integration)