Important
Official ipatool version 2.4.0 and newer
now includes maintained SAP-signed App Store authentication. Functional
development and current compatibility reports belong upstream.
This repository remains public as the historical macOS fix and as a searchable answer for the error:
request failed: unexpected response from Apple (HTTP 403): empty or non-plist body
The original patch added the required X-Apple-ActionSignature through macOS
CommerceKit and removed passwords and two-factor codes from verbose logs.
Upstream shipped a cross-platform SAP implementation in v2.4.0 on August 28,
2026, followed by more authentication fixes in v2.5.0.
Official v2.5.0 was verified here on September 1, 2026 with an existing
Keychain session and a live App Store version-list request. At that time,
however, Homebrew still packaged v2.3.2, while the official v2.5.0 release
assets were compiled with the unpatched go1.25.0 toolchain.
2.3.2-sapfix.2 is therefore the final macOS transition release. It is rebuilt
with Go 1.26.6 and is published only after tests, vet, a live macOS SAP signer
smoke test, and govulncheck pass. Move to official ipatool once your package
source provides v2.5.0 or newer built with a patched Go toolchain.
Download 2.3.2-sapfix.2
and choose the archive matching uname -m:
| Mac | uname -m |
Archive |
|---|---|---|
| Apple Silicon | arm64 |
ipatool-2.3.2-sapfix.2-macos-arm64.tar.gz |
| Intel | x86_64 |
ipatool-2.3.2-sapfix.2-macos-amd64.tar.gz |
Download the matching .sha256sum file as well. Apple Silicon example:
shasum -a 256 -c ipatool-2.3.2-sapfix.2-macos-arm64.tar.gz.sha256sum
tar -xzf ipatool-2.3.2-sapfix.2-macos-arm64.tar.gz
sudo install -m 0755 \
bin/ipatool-2.3.2-sapfix.2-macos-arm64 \
/usr/local/bin/ipatool
command -v ipatool
ipatool --versionFor an Intel Mac, replace arm64 with amd64. The binaries are not notarized.
If macOS blocks one, verify its checksum first and remove only that file's
quarantine attribute:
xattr -d com.apple.quarantine bin/ipatool-2.3.2-sapfix.2-macos-arm64Check what Homebrew currently offers before upgrading:
brew update
brew info ipatoolUpgrade only when the displayed stable version is 2.5.0 or newer:
brew upgrade ipatool
ipatool --versionUntil then, use the transition build above or build the official tag with a patched Go toolchain:
git clone https://github.com/majd/ipatool.git
cd ipatool
git checkout v2.5.0
GOTOOLCHAIN=go1.26.6 go test ./...
GOTOOLCHAIN=go1.26.6 go build -trimpath \
-ldflags="-X github.com/majd/ipatool/v2/cmd.version=2.5.0-local" \
-o ipatool .
sudo install -m 0755 ipatool /usr/local/bin/ipatoolCheck the current session before logging in again:
ipatool auth infoOnly if no account is shown, authenticate interactively so the password is not stored in shell history:
ipatool auth login --email "you@example.com"Never publish raw authentication logs. Redact email addresses, passwords, two-factor codes, tokens, cookies, authorization headers, and DSIDs.
Report current ipatool behavior and feature requests in upstream Issues. Use this repository's Issues only for a security, build, or documentation problem specific to this fork. See the security policy for private reports.
The repository and its release artifacts contain no Apple account credentials or authentication state. Local authentication state remains in the user's credential store and is not part of Git.
Use Go 1.26.6 or newer. On macOS with Xcode command line tools installed:
git clone https://github.com/maksimryabkin/ipatool-sapfix.git
cd ipatool-sapfix
go generate ./...
go test ./...
go vet ./...
go build ./...GitHub Actions also runs the macOS SAP signer smoke test, govulncheck, and
CodeQL. Release automation is macOS-only, uses pinned official actions and
minimal permissions, and cannot write to an unrelated Homebrew repository.
Based on majd/ipatool and distributed under
the MIT License. The original copyright and license notice and full
Git history are preserved.
