Troubleshooting
The failures that actually happen
Every page here explains one error: what it means, why it happens, and how to know before a build rather than forty minutes into one. No sign-up, no gate.
iOS
Provisioning profile "X" doesn't include signing certificate "Apple Distribution: Y"Why an iOS provisioning profile stops matching your distribution certificate, how to inspect a .mobileprovision, and the regeneration order that fixes it.The provisioning profile is expiredWhat expires when in iOS code signing — the provisioning profile, and the distribution certificate — what happens to apps already in the App Store (nothing), the order to renew in, and how to be warned next time.altool: Unable to authenticateWhy altool rejects a valid App Store Connect API key: the filename convention, the exact directory it searches, and the issuer ID versus key ID confusion.Distribution certificate with fingerprint ... hasn't been imported successfullyThe three real causes: a .p12 exported without its private key, a missing Apple WWDR intermediate, and OpenSSL 3 refusing the cipher Keychain Access uses.No signing certificate "iOS Distribution" foundXcode is reading a keychain with no usable distribution identity. The difference between a certificate and an identity, and why CI fails where local succeeds.
Android
403 The caller does not have permissionThe Play Developer API 403, not the Play Console login 403: the permission chain from service account to app-level grant, and why it can fail for a day after.Version code 1 has already been used. Try another version codeWhy Play refuses a version code forever, the three reasons yours did not increment, and how to stop hitting this permanently.Your Android App Bundle is signed with the wrong keyThe upload key versus app signing key distinction behind almost every case, how to check which key signed your artifact, and how to reset a lost upload key.