How to Revoke IPATool Credentials: CLI and Go Implementation Guide

Run ipatool auth revoke to remove stored Apple ID credentials from your system keychain.

IPATool stores authentication data in the operating system keychain through its internal appstore package. When you need to securely log out or delete saved credentials, the tool provides a dedicated revocation mechanism that removes the account entry directly from the keychain. This guide explains how to revoke IPATool credentials using both the command-line interface and programmatic Go code, based on the source implementation in majd/ipatool.

Understanding IPATool Credential Storage

IPATool persists Apple ID credentials using the OS-native keychain rather than plaintext files. The appstore package manages this storage through a dedicated keychain interface, saving the account data under the key "account". Because authentication relies entirely on this keychain entry, removing it effectively logs the tool out of your Apple ID without requiring additional cleanup of secondary tokens or configuration files.

How to Revoke IPATool Credentials from the Command Line

The simplest method to revoke credentials is using the built-in auth revoke sub-command. This command triggers the removal of the stored account information from your system keychain.


# Revoke the stored Apple ID credentials

ipatool auth revoke

When executed successfully, the command removes the "account" entry from the keychain. If the removal fails (for example, if no credentials were previously stored), the CLI returns an error indicating the failure.

Revoking Credentials Programmatically in Go

You can also revoke credentials programmatically by calling the Revoke method on an appstore instance. This approach is useful when building custom tooling or automation around IPATool's core functionality.

import (
    "github.com/majd/ipatool/v2/pkg/appstore"
)

// Assuming you have an appstore instance named `store`
if err := store.Revoke(); err != nil {
    // handle error – revocation failed
    log.Fatalf("failed to revoke credentials: %v", err)
}
fmt.Println("credentials revoked")

The Revoke method handles the keychain interaction internally, returning an error only if the underlying keychain operation fails.

Implementation Details

The revocation flow involves three distinct layers in the codebase: CLI command registration, business logic implementation, and low-level keychain operations.

CLI Command Registration

The revoke sub-command is defined in cmd/auth.go within the revokeCmd function (lines 53-58). This function binds the ipatool auth revoke command to the appstore's Revoke method, handling flag parsing and error output before delegating to the core logic.

Core Revocation Logic

The actual credential removal is implemented in pkg/appstore/appstore_revoke.go (lines 7-13). The Revoke method executes t.keychain.Remove("account"), which targets the specific keychain entry where the Apple ID credentials are stored. This implementation ensures that only the account data is removed, leaving other tool configurations intact.

Keychain Interaction

The Remove operation utilized by the Revoke method is defined in pkg/keychain/keyring.go. This abstraction layer provides the interface between IPATool and the operating system's native keychain services (such as macOS Keychain or Windows Credential Manager), ensuring secure deletion of sensitive authentication data.

Summary

  • Command-line method: Execute ipatool auth revoke to delete stored credentials instantly.
  • Programmatic method: Call store.Revoke() on an appstore instance within Go applications.
  • Storage mechanism: Credentials are removed from the OS keychain via keychain.Remove("account").
  • Source locations: CLI entry point is in cmd/auth.go; core logic resides in pkg/appstore/appstore_revoke.go.
  • Security: No residual tokens or files remain after revocation; only the keychain entry is deleted.

Frequently Asked Questions

What happens when I revoke IPATool credentials?

Revoking credentials deletes the "account" entry from your system keychain. This removes the stored Apple ID and password, effectively logging IPATool out. No local configuration files or cached data persist; the tool will require re-authentication on the next use.

Where does IPATool store Apple ID credentials?

IPATool stores credentials exclusively in the operating system keychain through its pkg/keychain implementation. Unlike tools that use plaintext files or environment variables, IPATool relies on the OS-native secure storage mechanism accessible via the keyring.go abstraction layer.

Can I revoke credentials programmatically?

Yes. Import github.com/majd/ipatool/v2/pkg/appstore and call the Revoke() method on your appstore instance. This method mirrors the CLI behavior by invoking the keychain removal logic directly from your Go code.

What if the revoke command fails?

If ipatool auth revoke returns an error, it typically indicates that either no credentials were present in the keychain or the keychain access was denied. Verify that you have the necessary permissions to modify system keychain entries and that credentials were previously stored using ipatool auth login.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →