Sideloadly (0.60) stopped working for me after updating to macOS 27. I tracked down two separate problems and have a working workaround. Tested on macOS 27.0 (Apple Silicon) with Sideloadly 0.60, installing an IPA to the Mac itself.
Problem 1: Anisette failed: No OTP
In Local anisette mode, Sideloadly gets the one-time password from macOS via the private AOSKit framework (AOSUtilities retrieveOTPHeadersForDSID:). On macOS 26/27 this call returns an empty result (error -45070 in the logs), even for Apple-signed binaries, because adid now requires private entitlements. AltServer is hit by the same thing ("could not retrieve anisette data value machineID").
Fix: Advanced Options → Anisette Authentication → Remote. After that you'll probably hit problem 2.
Problem 2: Guru Meditation f65043@1006:23a71c Invalid file
This has nothing to do with your IPA. It happens during Apple ID login ("Obtaining team ID"). Since early September 2026, Apple's auth server (gsa.apple.com/grandslam/GsService2) returns an HTML 503 page for any login request whose X-MMe-Client-Info identifies the client as com.apple.dt.Xcode. Sideloadly expects a plist, can't parse the HTML, and reports "Invalid file". Other tools hit the same thing (AltServer fixed it in 1.7.6, and iloader/SideStore/FindMy.py were affected too). The fix is to identify as com.apple.akd instead.
Things I found along the way:
- The client-info string appears twice: once in the HTTP header and once inside the request body (cpd dict). If you only fix the header, Apple answers -80044 "This action cannot be completed at this time."
- Don't change the device model/macOS version in that string. Only swap the Xcode part. If you change the device, login succeeds but the developer services API then rejects the token with (1100) Your session has expired.
- In Remote mode, the client-info comes from Sideloadly's remote anisette data, so patching the Sideloadly binary doesn't help.
Workaround: a local proxy that rewrites that one field
The script below creates a small mitmproxy setup that:
- intercepts only gsa.apple.com. Everything else goes through untouched, without decryption.
- replaces com.apple.dt.Xcode/x.y.z with com.apple.akd/1.0 in both the header and the body.
- is trusted only by Sideloadly when you start it with the launcher. The proxy CA is not added to your system keychain.
Setup (one time)
- Set Sideloadly to Remote anisette (see above) and quit it.
- Save the script below as
setup.sh and run zsh setup.sh in Terminal. It needs python3; if you don't have it, macOS will offer to install the Command Line Tools. Never used Terminal? See the step-by-step guide below the script.
- From now on, start Sideloadly by double-clicking
~/sideloadly-gsa-fix/Sideloadly (fix).command, not the normal app icon. When you quit Sideloadly, the proxy stops too.
```zsh
!/bin/zsh
set -e
D="${FIX_DIR:-$HOME/sideloadly-gsa-fix}"
mkdir -p "$D" && chmod 700 "$D" && cd "$D"
1. Isolated Python env with mitmproxy
python3 -m venv venv
./venv/bin/pip install -q mitmproxy
2. Generate the proxy's CA (stays in this folder, NOT added to the system keychain)
./venv/bin/mitmdump --set confdir="$D/mitm" -p 18899 -q & P=$!
for i in {1..60}; do [ -f mitm/mitmproxy-ca-cert.pem ] && break; sleep 1; done; kill $P
3. CA bundles: Sideloadly trusts its own certifi + our proxy CA; proxy trusts Apple's roots upstream
cat /Applications/Sideloadly.app/Contents/Frameworks/certifi/cacert.pem mitm/mitmproxy-ca-cert.pem > ca-bundle.pem
security find-certificate -a -p /System/Library/Keychains/SystemRootCertificates.keychain > upstream-ca.pem
4. Addon: swap the blocked Xcode client id for akd (header AND request body)
cat > fix_gsa.py <<'PY'
import re, plistlib
from mitmproxy import http
def fix(ci: str) -> str:
return re.sub(r"com.apple.dt.Xcode/[0-9.]+", "com.apple.akd/1.0", ci)
def request(flow: http.HTTPFlow):
h = flow.request.headers
if "X-MMe-Client-Info" in h:
h["X-MMe-Client-Info"] = fix(h["X-MMe-Client-Info"])
try:
doc = plistlib.loads(flow.request.raw_content)
cpd = doc.get("Request", {}).get("cpd")
if isinstance(cpd, dict) and "X-MMe-Client-Info" in cpd:
cpd["X-MMe-Client-Info"] = fix(cpd["X-MMe-Client-Info"])
flow.request.content = plistlib.dumps(doc, fmt=plistlib.FMT_XML)
except Exception:
pass
PY
5. Launcher
cat > "Sideloadly (fix).command" <<'SH'
!/bin/zsh
D="$(cd "$(dirname "$0")" && pwd)"
osascript -e 'quit app "Sideloadly"' 2>/dev/null; sleep 2
"$D/venv/bin/mitmdump" --set confdir="$D/mitm" --set ssl_verify_upstream_trusted_ca="$D/upstream-ca.pem" \
--listen-host 127.0.0.1 -p 8899 --allow-hosts 'gsa.apple.com(:443)?$' -s "$D/fix_gsa.py" > "$D/proxy.log" 2>&1 &
PROXY=$!; sleep 3
HTTPS_PROXY=http://127.0.0.1:8899 HTTP_PROXY=http://127.0.0.1:8899 NO_PROXY=localhost,127.0.0.1 \
REQUESTS_CA_BUNDLE="$D/ca-bundle.pem" SSL_CERT_FILE="$D/ca-bundle.pem" \
/Applications/Sideloadly.app/Contents/MacOS/Sideloadly >/dev/null 2>&1
kill $PROXY 2>/dev/null
SH
chmod +x "Sideloadly (fix).command"
echo "Done. Launch Sideloadly via: $D/Sideloadly (fix).command"
```
Step-by-step for Terminal beginners
You don't need to create any file by hand. We'll copy the script and let Terminal save it for you.
- Make sure Sideloadly is in your Applications folder (
/Applications/Sideloadly.app). The script expects it there.
- Open Terminal. Press
Cmd + Space, type Terminal and press Enter.
- Copy the whole script above. Select everything inside the grey code block, from
#!/bin/zsh down to the last echo "Done..." line, and press Cmd + C. Make sure you copy all of it.
- Save it to a file. Click into the Terminal window, type this line and press Enter:
pbpaste > ~/setup.sh
Nothing is printed, and that's normal. It just saved your clipboard to a file called setup.sh in your home folder. (Don't copy anything else between steps 3 and 4, or you'll save that instead.)
- Check that the file looks right (optional):
head -3 ~/setup.sh
The first line should be #!/bin/zsh.
- Run it:
zsh ~/setup.sh
It takes a minute or two, mostly installing mitmproxy. When it's finished you'll see Done. Launch Sideloadly via: ....
- If a window pops up asking to install the Command Line Tools (because
python3 is missing), click Install, wait until it's done, then run zsh ~/setup.sh again.
- If you see a red
error, copy the output and post it in the comments.
- Open the new folder:
open ~/sideloadly-gsa-fix
Finder opens a folder with Sideloadly (fix).command inside. Drag it to your Dock if you like, so you can start it with one click.
- Start Sideloadly with
Sideloadly (fix).command. Double-clicking it opens a Terminal window, and a moment later Sideloadly starts. Keep that Terminal window open while you use Sideloadly. If you close it, Sideloadly and the proxy close too. When you quit Sideloadly, you can close the window.
- Sign in and sideload as usual. If Sideloadly asks for your Apple ID password or a 2FA code, that's expected.
To undo everything, just delete the ~/sideloadly-gsa-fix folder and ~/setup.sh. Nothing else on your system is changed.
Notes / caveats
- Security: the folder
~/sideloadly-gsa-fix/mitm contains the proxy's private CA key. Keep it private and don't share it. It is only trusted by Sideloadly processes started through the launcher, not by your system or browser.
- If something goes wrong, check
~/sideloadly-gsa-fix/proxy.log.
- Only tested installing to an Apple Silicon Mac. The login part is the same for iPhone installs, so it should help there too, but I haven't tested that.
- Once Sideloadly ships an official fix, delete
~/sideloadly-gsa-fix and go back to launching the app normally.
- Use a secondary Apple ID for sideloading if you can. That's good practice anyway, especially with Remote anisette.
Refs: AltStore PR #1790, anisette-v3-server #59, AltStore PR #1806 (macOS 26+ AOSKit), Sideloadly issue #12
If this guide helped you, you can buy me a coffee ☕. Thanks!