iloader Tauri Backend Rust Commands: Complete API Reference
iloader exposes 20+ Rust commands through its Tauri backend, enabling device discovery, IPA sideloading, pairing file management, and Apple developer account operations via the #[tauri::command] attribute.
The nab138/iloader repository implements a Rust-based Tauri backend that bridges the React frontend with iOS system APIs. Each public operation available to the UI is defined as an async Rust function decorated with #[tauri::command] and registered in the Tauri application state. These commands handle everything from USB device enumeration to secure credential storage in the OS keyring.
Device Management Commands
Device handling capabilities reside in src-tauri/src/device.rs and provide the foundation for USB and network device discovery.
list_devices()
The list_devices() function scans for connected iOS devices via USB and network protocols. It returns a list of device information structs that populate the frontend device selector. According to the source code at src-tauri/src/device.rs#L35-L46, this command performs no caching and requests fresh data from the underlying iOS communication libraries on every invocation.
set_selected_device()
When a user selects a device from the UI, set_selected_device() updates the global application state with the chosen device reference and its pairing file. Located at src-tauri/src/device.rs#L23-L34, this command also cancels any previously running pairing job to prevent state conflicts.
cancel_pairing()
The cancel_pairing() command aborts an ongoing pairing operation using a CancellationToken. As implemented in src-tauri/src/device.rs#L65-L71, this provides immediate feedback to the UI when users click "Cancel" during the device trust dialog phase.
Sideloading Operations
Core installation logic lives in src-tauri/src/sideload.rs, wrapping the sideloading process in Tauri's operation tracking system for progress reporting.
sideload_operation()
The sideload_operation() command initiates a UI-visible operation that installs an IPA file onto the currently selected device. Found at src-tauri/src/sideload.rs#L73-L88, this function accepts the IPA path, application handle, and window reference to stream installation progress back to the frontend.
install_sidestore_operation()
For initial setup, install_sidestore_operation() downloads the SideStore or LiveContainer IPA, installs it to the selected device, and automatically places the required pairing file in the app's container. The implementation at src-tauri/src/sideload.rs#L90-L118 handles the complete bootstrap flow for new installations, including nightly build selection and LiveContainer mode toggles.
Pairing File Management
Pairing operations in src-tauri/src/pairing.rs manage the cryptographic relationship between iloader and iOS devices.
place_pairing_cmd()
The place_pairing_cmd() command transmits a pairing file to a specific bundle identifier on the target device. Defined at src-tauri/src/pairing.rs#L12-L28, this enables SideStore or other sideloading tools to receive the necessary pairing credentials without manual user intervention.
export_pairing_cmd()
To backup pairing files, export_pairing_cmd() opens a native file-save dialog and writes the current pairing data to disk. Located at src-tauri/src/pairing.rs#L31-L38, this uses Tauri's dialog API to ensure proper sandbox permissions on macOS and Windows.
RPPairing Cache Management
The backend maintains a cache of RPPairing files to speed up reconnection:
has_stored_rppairing(): Checks for cached pairing data atsrc-tauri/src/pairing.rs#L26-33to determine if the UI should skip the initial pairing flowdelete_stored_rppairing(): Removes cached data atsrc-tauri/src/pairing.rs#L4-5when users explicitly log out or reset their device connectioninstalled_pairing_apps(): Returns a list of installed apps known to support pairing files atsrc-tauri/src/pairing.rs#L44-49
Secure Storage Controls
The src-tauri/src/secure_storage.rs module provides OS keyring integration with manual override capabilities.
force_disable_keyring()
The force_disable_keyring() command allows users to forcibly disable the OS keyring backend, falling back to encrypted filesystem storage. Implemented at src-tauri/src/secure_storage.rs#L13-19, this addresses compatibility issues with certain Linux distributions or enterprise macOS configurations.
keyring_available()
Before attempting credential storage, the frontend queries keyring_available() at src-tauri/src/secure_storage.rs#L27-31 to determine if the keyring backend is functional and not disabled by user preference.
Apple Developer Account Commands
Developer session management in src-tauri/src/account.rs handles authentication, certificate provisioning, and App ID registration.
Authentication and Session Management
login_new()(src-tauri/src/account.rs#L27-41): Authenticates with fresh Apple ID credentials, optionally stores them in the keyring, and initializes aSideloaderinstance for subsequent operationslogin_stored()(src-tauri/src/account.rs#L69-77): Retrieves cached credentials from secure storage and establishes a session without re-prompting the userdelete_account()(src-tauri/src/account.rs#L93-108): Permanently removes stored credentials from both the keyring and the internal JSON state filelogged_in_as()(src-tauri/src/account.rs#L18-25): Returns the email address of the currently active Apple account orNoneif no session existsinvalidate_account()(src-tauri/src/account.rs#L27-31): Clears the in-memorySideloaderinstance, effectively logging out while preserving stored credentialsreset_anisette_state()(src-tauri/src/account.rs#L33-50): Deletes cached anisette provisioning data from the keyring to resolve authentication errors
Certificate and App ID Management
get_certificates()(src-tauri/src/account.rs#L66-74): Retrieves all development certificates associated with the current team, including expiration dates and serial numbersrevoke_certificate()(src-tauri/src/account.rs#L86-94): Revokes a specific development certificate by serial number through the Apple Developer Portal APIlist_app_ids()(src-tauri/src/account.rs#L98-106): Fetches the complete list of registered App IDs for the current developer teamdelete_app_id()(src-tauri/src/account.rs#L110-118): Removes a specific App ID identifier from the developer portal
How to Invoke These Commands from the Frontend
All Rust commands are exposed to the TypeScript frontend via Tauri's invoke API. The React/TSX interface calls these functions asynchronously and receives strongly typed responses.
Listing connected devices:
import { invoke } from '@tauri-apps/api/tauri';
const devices = await invoke<DeviceInfo[]>('list_devices');
Selecting a device and starting background pairing:
await invoke('set_selected_device', { device: selectedDevice });
Installing SideStore with automatic pairing file placement:
await invoke('install_sidestore_operation', {
handle: appHandle,
window,
device_state,
sideloader_state,
nightly: false,
live_container: false,
});
Authenticating with Apple Developer credentials:
await invoke('login_new', {
handle: appHandle,
window,
sideloader_state,
email,
password,
anisette_server: 'anisette.apple.com',
save_credentials: true,
});
Summary
- iloader exposes its Rust backend through 20+ Tauri commands defined across five specialized modules
- Device handling in
src-tauri/src/device.rsprovideslist_devices(),set_selected_device(), andcancel_pairing()for USB and network iOS discovery - Sideloading operations in
src-tauri/src/sideload.rshandle IPA installation viasideload_operation()and SideStore bootstrapping viainstall_sidestore_operation() - Pairing file management in
src-tauri/src/pairing.rssupports placement, export, and caching of RPPairing files withplace_pairing_cmd()andexport_pairing_cmd() - Secure storage in
src-tauri/src/secure_storage.rsoffersforce_disable_keyring()andkeyring_available()for credential backend management - Apple account commands in
src-tauri/src/account.rsmanage developer sessions, certificates, and App IDs through functions likelogin_new(),get_certificates(), anddelete_app_id()
Frequently Asked Questions
How does iloader handle device communication from the Rust backend?
iloader utilizes the #[tauri::command] macro to expose Rust functions to the JavaScript frontend. Device-specific commands like list_devices() and set_selected_device() in src-tauri/src/device.rs wrap low-level iOS communication libraries, providing async interfaces that the React UI can invoke with type-safe parameters and return values.
Can iloader cache Apple Developer credentials securely?
Yes, according to the source code in src-tauri/src/account.rs and src-tauri/src/secure_storage.rs, iloader supports storing Apple ID credentials in the OS-native keyring (Keychain on macOS, Credential Manager on Windows, Secret Service on Linux). The login_stored() command retrieves these credentials automatically, while force_disable_keyring() provides a fallback to encrypted file storage when keyring access is restricted.
What is the difference between sideload_operation and install_sidestore_operation?
sideload_operation() in src-tauri/src/sideload.rs#L73-L88 is a generic IPA installer for arbitrary application packages, while install_sidestore_operation() at src-tauri/src/sideload.rs#L90-L118 is a specialized bootstrap command that downloads the SideStore IPA, installs it, and automatically transfers the pairing file required for subsequent wireless sideloading operations.
How does iloader manage pairing files for SideStore compatibility?
The backend implements specific pairing file commands in src-tauri/src/pairing.rs, including place_pairing_cmd() to transmit files to specific app bundles and export_pairing_cmd() to save backups locally. The system also maintains an RPPairing cache via has_stored_rppairing() and delete_stored_rppairing() to optimize reconnection flows without requiring repeated device trust dialogs.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →