pkpass/pkpass

PHP PKPass class for iOS Wallet

Fund package maintenance!
tschoffelen

Installs: 2 581 327

Dependents: 4

Suggesters: 0

Security: 0

Stars: 961

Watchers: 55

Forks: 193

Open Issues: 2

pkg:composer/pkpass/pkpass

v2.5.0 2025-09-13 08:20 UTC

README

Packagist Version Packagist Downloads Packagist License

This class provides the functionality to create passes for Wallet in Apple's iOS. It creates, signs and packages the pass as a .pkpass file according to Apple's documentation.

Requirements

  • PHP 7.0 or higher (may also work with older versions)
  • PHP ZIP extension (often installed by default)
  • Access to filesystem to write temporary cache files

Installation

Simply run the following command in your project's root directory to install via Composer:

composer require pkpass/pkpass

Or add to your composer.json: "pkpass/pkpass": "^2.0.0"

Usage

Please take a look at the examples/example.php file for example usage. For more info on the JSON for the pass and how to style it, take a look at the docs at developers.apple.com.

Included demos

API Documentation

API documentation is available for all main classes:

Requesting the Pass Certificate

  1. Go to the iOS Provisioning portal.
  2. Create a new Pass Type ID, and write down the Pass ID you choose, you'll need it later.
  3. Click the edit button under your newly created Pass Type ID and generate a certificate according to the instructions shown on the page. Make sure not to choose a name for the Certificate but keep it empty instead.
  4. Download the .cer file and drag it into Keychain Access.
  5. Choose to filter by Certificates in the top filter bar.
  6. Find the certificate you just imported and click the triangle on the left to reveal the private key.
  7. Select both the certificate and the private key it, then right-click the certificate in Keychain Access and choose Export 2 items….
  8. Choose a password and export the file to a folder.

Exporting P12 file

Getting the example.php sample to work

  1. Request the Pass certificate (.p12) as described above and upload it to your server.
  2. Set the correct path and password on line 22.
  3. Change the passTypeIdentifier and teamIndentifier to the correct values on lines 29 and 31 (teamIndentifier can be found on the Developer Portal).

After completing these steps, you should be ready to go. Upload all the files to your server and navigate to the address of the examples/example.php file on your iPhone.

Debugging

Using the Console app

If you aren't able to open your pass on an iPhone, plug the iPhone into a Mac and open the 'Console' application. On the left, you can select your iPhone. You will then be able to inspect any errors that occur while adding the pass:

Console with Passkit error

  • Trust evaluate failure: [leaf TemporalValidity]: If you see this error, your pass was signed with an outdated certificate.
  • Trust evaluate failure: [leaf LeafMarkerOid]: You did not leave the name of the certificate empty while creating it in the developer portal.

OpenSSL errors

When you get the error 'Could not read certificate file', this might be related to using an OpenSSL version that has deprecated some older hashes - more info here.

There may be no need to configure OpenSSL to use legacy algorithms. It's easier and more portable just to convert the encrypted certificates file. The steps below use a .p12 file but it should work to swap these commands for a .pfx file.

Instructions:

  1. openssl pkcs12 -legacy -in key.p12 -nodes -out key_decrypted.tmp (replace key.p12 with your .p12 file name).
  2. openssl pkcs12 -in key_decrypted.tmp -export -out key_new.p12 -certpbe AES-256-CBC -keypbe AES-256-CBC -iter 2048 (use the newly generated key_new.p12 file in your pass generation below)

The key_new.p12 file should now be compatible with OpenSSL v3+.

Changelog

Version 2.4.0 - October 2024

  • Add PKPassBundle class to bundle multiple passes into a single .pkpasses file.

Version 2.3.2 - September 2024

  • Fix order mime type, add better error reporting.

Version 2.3.1 - March 2024

  • Chore: add gitattributes.

Version 2.3.0 - February 2024

  • Add support for Wallet Orders.

Version 2.2.0 - December 2023

  • Update default WWDR certificate to G4.

Version 2.1.0 - April 2023

  • Add alternative method for extracting P12 contents to circumvent issues in recent versions of OpenSSL.

Version 2.0.2 - October 2022

  • Switch to ZipArchive::OVERWRITE method of opening ZIP due to PHP 8 deprecation (#120).

Version 2.0.1 - October 2022

  • Update WWDR certificate to v6 (#118).

Version 2.0.0 - September 2022

  • Changed signature of constructor to take out third $json parameter.
  • Remove deprecated setJSON() method.
  • Removed checkError() and getError() methods in favor of exceptions.

Support & documentation

Please read the instructions above and consult the Wallet Documentation before submitting tickets or requesting support. It might also be worth to check Stackoverflow, which contains quite a few questions about this library.



Get professional support for this package →
Custom consulting sessions available for implementation support and feature development.