How to Download an IPA File Using IPATool

IPATool is a command-line utility that downloads iOS .ipa packages from the Apple App Store using a three-step workflow: authenticate with your Apple ID, identify the app by bundle identifier, and run the download command with optional version and output path flags.

The majd/ipatool repository provides a Go-based CLI that interfaces directly with Apple's private App Store APIs to retrieve encrypted IPA files. Whether you need to inspect app binaries, archive specific versions, or automate app acquisition, IPATool handles authentication, architecture resolution, and streaming downloads in a single command.

Prerequisites

Before downloading IPAs, ensure you have the following:

  • macOS running a recent version (the tool stores credentials in the macOS keychain)
  • An Apple ID with permissions to access the target app
  • The IPATool binary installed (available via Homebrew or GitHub releases)

Step-by-Step Guide to Download an IPA

1. Authenticate with Your Apple ID

Before any download operation, you must establish a session with Apple's servers. IPATool stores a short-lived authentication token in the macOS keychain, allowing subsequent commands to reuse your credentials without re-entering your password.

Run the login command and follow the prompts for your Apple ID, password, and two-factor authentication code if enabled:

ipatool login

The authentication logic resides in cmd/auth.go, which handles the secure credential exchange and keychain storage mechanism.

2. Identify the App Bundle ID

IPATool requires the bundle identifier (e.g., com.apple.Pages) rather than the app's display name. You can locate this identifier by searching the App Store web interface or examining the app's iTunes URL structure.

3. Execute the Download Command

Use the download subcommand with the required --bundle-id flag and optional --output path. According to the source code in cmd/download.go, this command builds the API request, handles the response stream, and writes the encrypted IPA to disk:

ipatool download --bundle-id com.example.MyApp --output MyApp.ipa

Behind the scenes, as implemented in pkg/appstore/appstore_download.go, the tool contacts Apple's private App Store endpoints, resolves the latest compatible version for your device's architecture, streams the encrypted IPA, and optionally verifies the SHA-256 checksum before completing the write operation.

Common Download Options and Flags

IPATool provides several flags to customize the download behavior:

  • --bundle-id (required): The application's unique bundle identifier
  • --output: Destination path for the IPA file (defaults to current directory with app name)
  • --version: Specific version string to download instead of the latest release
  • --platform: Force a specific platform (ios, ipad, or macos) instead of auto-detection based on user-agent
  • --output-format: Change output style to json for machine-readable logging

Practical Code Examples

Download the Latest Version


# Basic download of the most recent compatible version

ipatool download \
    --bundle-id com.example.MyApp \
    --output ./MyApp.ipa

Download a Specific Version

For testing older builds or regression analysis, specify an exact version string:

ipatool download \
    --bundle-id com.example.MyApp \
    --version 2.3.1 \
    --output ./MyApp-2.3.1.ipa

Machine-Readable Output

For CI/CD pipelines or scripting environments, use JSON formatting to parse progress and completion status:

ipatool download \
    --bundle-id com.example.MyApp \
    --output ./MyApp.ipa \
    --output-format json

How the Download Works Under the Hood

The IPATool architecture separates concerns across several key files in the majd/ipatool repository:

  • cmd/root.go: Defines the root command structure, global flag parsing, and configuration loading that all subcommands inherit
  • cmd/download.go: Implements the download command interface, validates flags, and orchestrates the download workflow
  • pkg/appstore/appstore_download.go: Contains the low-level App Store API client that constructs HTTP requests to Apple's endpoints, handles response streaming, and manages the encrypted IPA file construction
  • cmd/auth.go: Manages Apple ID authentication and secure token storage in the macOS keychain

When you execute the download command, the CLI first loads your stored session from the keychain, constructs a purchase/download request with the appropriate user-agent headers for platform detection, streams the encrypted IPA chunks from Apple's CDN, and writes them to the specified output path while calculating checksums for integrity verification.

Summary

  • IPATool requires authentication via ipatool login before downloading, storing tokens in the macOS keychain for reuse
  • Use bundle identifiers (not app names) with the --bundle-id flag to specify target applications
  • The download command supports version pinning with --version and platform forcing with --platform
  • Source code in cmd/download.go and pkg/appstore/appstore_download.go handles API communication, streaming, and checksum verification
  • Output can be formatted as JSON for automation using --output-format json

Frequently Asked Questions

Do I need to log in every time I download an IPA?

No. The ipatool login command stores a short-lived session token in the macOS keychain, allowing subsequent download commands to reuse your authentication until the session expires. You only need to re-authenticate when the token becomes invalid or when Apple requires fresh credentials.

Can I download specific versions of iOS apps with IPATool?

Yes. Use the --version flag followed by the specific version string (e.g., --version 2.3.1) to request that exact build from Apple's servers. This is useful for security research or compatibility testing against older app releases.

Where does IPATool store authentication credentials?

IPATool stores authentication tokens securely in the macOS keychain, not in plain text configuration files. The cmd/auth.go implementation handles this keychain integration, ensuring your Apple ID credentials remain encrypted and accessible only to the tool.

Is it possible to download IPAs for macOS using IPATool?

Yes. While IPATool automatically detects the platform based on the user-agent string it sends to Apple's APIs, you can explicitly request macOS IPAs by passing --platform macos. The tool also supports --platform ios and --platform ipad for forcing specific mobile architectures.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →