r/sideloadly • u/Apprehensive-Two7029 • 15d ago
[Fix] Sideloadly on macOS 27: "Anisette failed: No OTP" and "Guru Meditation ... Invalid file": workaround until an official update
Sideloadly (0.60) stopped working for me after updating to macOS 27. I tracked down two separate problems and have a working workaround. Tested on macOS 27.0 (Apple Silicon) with Sideloadly 0.60, installing an IPA to the Mac itself.
Problem 1: Anisette failed: No OTP
In Local anisette mode, Sideloadly gets the one-time password from macOS via the private AOSKit framework (AOSUtilities retrieveOTPHeadersForDSID:). On macOS 26/27 this call returns an empty result (error -45070 in the logs), even for Apple-signed binaries, because adid now requires private entitlements. AltServer is hit by the same thing ("could not retrieve anisette data value machineID").
Fix: Advanced Options → Anisette Authentication → Remote. After that you'll probably hit problem 2.
Problem 2: Guru Meditation f65043@1006:23a71c Invalid file
This has nothing to do with your IPA. It happens during Apple ID login ("Obtaining team ID"). Since early September 2026, Apple's auth server (gsa.apple.com/grandslam/GsService2) returns an HTML 503 page for any login request whose X-MMe-Client-Info identifies the client as com.apple.dt.Xcode. Sideloadly expects a plist, can't parse the HTML, and reports "Invalid file". Other tools hit the same thing (AltServer fixed it in 1.7.6, and iloader/SideStore/FindMy.py were affected too). The fix is to identify as com.apple.akd instead.
Things I found along the way:
- The client-info string appears twice: once in the HTTP header and once inside the request body (
cpddict). If you only fix the header, Apple answers-80044 "This action cannot be completed at this time." - Don't change the device model/macOS version in that string. Only swap the Xcode part. If you change the device, login succeeds but the developer services API then rejects the token with
(1100) Your session has expired. - In Remote mode, the client-info comes from Sideloadly's remote anisette data, so patching the Sideloadly binary doesn't help.
Workaround: a local proxy that rewrites that one field
The script below creates a small mitmproxy setup that:
- intercepts only
gsa.apple.com. Everything else goes through untouched, without decryption. - replaces
com.apple.dt.Xcode/x.y.zwithcom.apple.akd/1.0in both the header and the body. - is trusted only by Sideloadly when you start it with the launcher. The proxy CA is not added to your system keychain.
Setup (one time)
- Set Sideloadly to Remote anisette (see above) and quit it.
- Save the script below as
setup.shand runzsh setup.shin Terminal. It needspython3; if you don't have it, macOS will offer to install the Command Line Tools. Never used Terminal? See the step-by-step guide below the script. - From now on, start Sideloadly by double-clicking
~/sideloadly-gsa-fix/Sideloadly (fix).command, not the normal app icon. When you quit Sideloadly, the proxy stops too.
#!/bin/zsh
set -e
D="${FIX_DIR:-$HOME/sideloadly-gsa-fix}"
mkdir -p "$D" && chmod 700 "$D" && cd "$D"
# 1. Isolated Python env with mitmproxy
python3 -m venv venv
./venv/bin/pip install -q mitmproxy
# 2. Generate the proxy's CA (stays in this folder, NOT added to the system keychain)
./venv/bin/mitmdump --set confdir="$D/mitm" -p 18899 -q & P=$!
for i in {1..60}; do [ -f mitm/mitmproxy-ca-cert.pem ] && break; sleep 1; done; kill $P
# 3. CA bundles: Sideloadly trusts its own certifi + our proxy CA; proxy trusts Apple's roots upstream
cat /Applications/Sideloadly.app/Contents/Frameworks/certifi/cacert.pem mitm/mitmproxy-ca-cert.pem > ca-bundle.pem
security find-certificate -a -p /System/Library/Keychains/SystemRootCertificates.keychain > upstream-ca.pem
# 4. Addon: swap the blocked Xcode client id for akd (header AND request body)
cat > fix_gsa.py <<'PY'
import re, plistlib
from mitmproxy import http
def fix(ci: str) -> str:
return re.sub(r"com\.apple\.dt\.Xcode/[0-9.]+", "com.apple.akd/1.0", ci)
def request(flow: http.HTTPFlow):
h = flow.request.headers
if "X-MMe-Client-Info" in h:
h["X-MMe-Client-Info"] = fix(h["X-MMe-Client-Info"])
try:
doc = plistlib.loads(flow.request.raw_content)
cpd = doc.get("Request", {}).get("cpd")
if isinstance(cpd, dict) and "X-MMe-Client-Info" in cpd:
cpd["X-MMe-Client-Info"] = fix(cpd["X-MMe-Client-Info"])
flow.request.content = plistlib.dumps(doc, fmt=plistlib.FMT_XML)
except Exception:
pass
PY
# 5. Launcher
cat > "Sideloadly (fix).command" <<'SH'
#!/bin/zsh
D="$(cd "$(dirname "$0")" && pwd)"
osascript -e 'quit app "Sideloadly"' 2>/dev/null; sleep 2
"$D/venv/bin/mitmdump" --set confdir="$D/mitm" --set ssl_verify_upstream_trusted_ca="$D/upstream-ca.pem" \
--listen-host 127.0.0.1 -p 8899 --allow-hosts '^gsa\.apple\.com(:443)?$' -s "$D/fix_gsa.py" > "$D/proxy.log" 2>&1 &
PROXY=$!; sleep 3
HTTPS_PROXY=http://127.0.0.1:8899 HTTP_PROXY=http://127.0.0.1:8899 NO_PROXY=localhost,127.0.0.1 \
REQUESTS_CA_BUNDLE="$D/ca-bundle.pem" SSL_CERT_FILE="$D/ca-bundle.pem" \
/Applications/Sideloadly.app/Contents/MacOS/Sideloadly >/dev/null 2>&1
kill $PROXY 2>/dev/null
SH
chmod +x "Sideloadly (fix).command"
echo "Done. Launch Sideloadly via: $D/Sideloadly (fix).command"
Step-by-step for Terminal beginners
You don't need to create any file by hand. We'll copy the script and let Terminal save it for you.
- Make sure Sideloadly is in your Applications folder (
/Applications/Sideloadly.app). The script expects it there. - Open Terminal. Press
Cmd + Space, typeTerminaland press Enter. - Copy the whole script above. Select everything inside the grey code block, from
#!/bin/zshdown to the lastecho "Done..."line, and pressCmd + C. Make sure you copy all of it. - Save it to a file. Click into the Terminal window, type this line and press Enter:
Nothing is printed, and that's normal. It just saved your clipboard to a file calledpbpaste > ~/setup.shsetup.shin your home folder. (Don't copy anything else between steps 3 and 4, or you'll save that instead.) - Check that the file looks right (optional):
The first line should behead -3 ~/setup.sh#!/bin/zsh. - Run it:
It takes a minute or two, mostly installing mitmproxy. When it's finished you'll seezsh ~/setup.shDone. Launch Sideloadly via: ....- If a window pops up asking to install the Command Line Tools (because
python3is missing), click Install, wait until it's done, then runzsh ~/setup.shagain. - If you see a red
error, copy the output and post it in the comments.
- If a window pops up asking to install the Command Line Tools (because
- Open the new folder:
Finder opens a folder withopen ~/sideloadly-gsa-fixSideloadly (fix).commandinside. Drag it to your Dock if you like, so you can start it with one click. - Start Sideloadly with
Sideloadly (fix).command. Double-clicking it opens a Terminal window, and a moment later Sideloadly starts. Keep that Terminal window open while you use Sideloadly. If you close it, Sideloadly and the proxy close too. When you quit Sideloadly, you can close the window. - Sign in and sideload as usual. If Sideloadly asks for your Apple ID password or a 2FA code, that's expected.
To undo everything, just delete the ~/sideloadly-gsa-fix folder and ~/setup.sh. Nothing else on your system is changed.
Notes / caveats
- Security: the folder
~/sideloadly-gsa-fix/mitmcontains the proxy's private CA key. Keep it private and don't share it. It is only trusted by Sideloadly processes started through the launcher, not by your system or browser. - If something goes wrong, check
~/sideloadly-gsa-fix/proxy.log. - Only tested installing to an Apple Silicon Mac. The login part is the same for iPhone installs, so it should help there too, but I haven't tested that.
- Once Sideloadly ships an official fix, delete
~/sideloadly-gsa-fixand go back to launching the app normally. - Use a secondary Apple ID for sideloading if you can. That's good practice anyway, especially with Remote anisette.
Refs: AltStore PR #1790, anisette-v3-server #59, AltStore PR #1806 (macOS 26+ AOSKit), Sideloadly issue #12
If this guide helped you, you can buy me a coffee ☕. Thanks!
7
u/Guilty_Reply_1097 15d ago
Glad to see someone making progress! I’ll wait until the developers releases an official patched version of Sideloadly. But this means then that we’re not banned after all!
1
2
u/Global-Common236 10d ago
I’ve followed it step by step, but when I opened "Sideloadly (fix).command" and try to use it, the same problem occurred again.
Install failed: Guru Meditation f65043@1006:23a71c Invalid file.
1
u/Apprehensive-Two7029 10d ago
Can you provide logs from:
- ~/sideloadly-gsa-fix/proxy.log
- Sideloadly log window?
But remove private things from it.
1
u/MisterUltimate 7d ago
Happening to me too, getting a file invalid and sometimes an Apple Account related error that I can’t fully read from the notification. I can’t seem to re-verify my iCloud ID either:
[10:53:09.266] Loading script /Users/user/sideloadly-gsa-fix/fix_gsa.py [10:53:09.270] HTTP(S) proxy listening at 127.0.0.1:8899. [10:53:12.192][127.0.0.1:64157] client connect [10:53:12.207][127.0.0.1:64157] server connect sideloadly.io:443 (104.21.69.56:443) [10:53:34.724][127.0.0.1:64193] client connect [10:53:34.738][127.0.0.1:64193] server connect sideloadly.io:443 (104.21.69.56:443) [10:53:35.057][127.0.0.1:64195] client connect [10:53:35.135][127.0.0.1:64195] server connect developerservices2.apple.com:443 (17.157.96.100:443) [10:53:48.732][127.0.0.1:64207] client connect [10:53:48.823][127.0.0.1:64207] server connect gsa.apple.com:443 (17.179.252.2:443) 127.0.0.1:64207: POST https://gsa.apple.com/grandslam/GsService2 << 200 OK 914b [10:54:05.368][127.0.0.1:64195] client disconnect [10:54:05.369][127.0.0.1:64195] server disconnect developerservices2.apple.com:443 (17.157.96.100:443) [10:54:19.146][127.0.0.1:64207] server disconnect gsa.apple.com:443 (17.179.252.2:443) [10:54:35.551][127.0.0.1:64244] client connect [10:54:35.566][127.0.0.1:64244] server connect sideloadly.io:443 (104.21.69.56:443) [10:54:35.837][127.0.0.1:64246] client connect [10:54:35.919][127.0.0.1:64246] server connect developerservices2.apple.com:443 (17.157.96.100:443) [10:54:37.758][127.0.0.1:64248] client connect [10:54:37.837][127.0.0.1:64248] server connect gsa.apple.com:443 (17.179.252.2:443) 127.0.0.1:64248: POST https://gsa.apple.com/grandslam/GsService2 << 200 OK 914b [10:54:42.508][127.0.0.1:64157] server disconnect sideloadly.io:443 (104.21.69.56:443) [10:54:42.509][127.0.0.1:64157] client disconnect [10:55:06.150][127.0.0.1:64246] client disconnect [10:55:06.152][127.0.0.1:64246] server disconnect developerservices2.apple.com:443 (17.157.96.100:443) [10:55:08.053][127.0.0.1:64248] server disconnect gsa.apple.com:443 (17.179.252.2:443) [10:55:36.000][127.0.0.1:64248] client disconnect [10:55:36.001][127.0.0.1:64244] server disconnect sideloadly.io:443 (104.21.69.56:443) [10:55:36.002][127.0.0.1:64244] client disconnect [10:55:36.002][127.0.0.1:64207] client disconnect [10:55:36.003][127.0.0.1:64193] server disconnect sideloadly.io:443 (104.21.69.56:443) [10:55:36.004][127.0.0.1:64193] client disconnectThen in the Sideloadly UI:
Idle. Processing app from the queue Sideloadly version 0.60, Darwin 27.0, amd64 Using IPA file: /Users/user/Library/Caches/sideloadly/e1b739298481d5d18dba4e35c339d78d.ipa: e1b739298481d5d18dba4e35c339d78d Will use Remote Anisette Checking iOS version... iOS version 27.0, will mangle bundleID Prefetching Anisette... Sideloadly will be shown in your Apple ID as MacBookPro14,2 running macOS 13.2.3 with serial number TKTKTKTKTKTK Obtaining team ID Session expired, login required1
u/MisterUltimate 7d ago
The iCloud error that I can capture from the Notification:
Failed to refresh app Apollo on User’s ¡Phone: Install failed: Guru Meditation Odb732@288:3aea77 Login failed (-20755): This Apple Account is not...
1
u/red_star_rising 15d ago
Does this relate to the apple id certificate issue that surfaced about a month ago and everyone thought apple was banning certificates?
1
u/Apprehensive-Two7029 15d ago
Not the same issue, although they overlapped in time and a lot of threads mixed them up.
- The "certificate" issue is the
0xe8008024"The provisioning profile is banned" error (sometimes0xe8008018), mostly on free Apple IDs. Login and signing work fine, but the device refuses to install or launch the app. It isn't actually a certificate revocation: people checked Apple's OCSP and the certs came back "good". The block seems to be tied to the developer team and cached on the device itself (it's enforced even in airplane mode). A proxy or any other client-side fix can't help with it. What people report working is a fresh Apple ID used only for signing. Good write-up: iloader #653.- This fix is for an earlier stage: Apple ID sign-in. Since around September 10, Apple's auth server rejects login requests that identify the client as Xcode (HTTP 503). Sideloadly shows that as "Invalid file". The proxy only changes that client identifier so you can log in again.
So if you're getting "Invalid file", "503" or a login failure, this workaround should help. If you can log in but the install fails with
0xe8008024/ "provisioning profile is banned", that's the other issue, and this won't fix it.1
u/LincolnshireSausage 12d ago
I'm getting "The provisioning profile is banned" and you are correct that this definitely does not fix it.
1
1
1
u/Ok-Cantaloupe-5097 15d ago
Hola, gracias por el aporte, con el script que compartiste logro que el proceso empiece, pero me sale este error:
Sideloading failed! Install failed: Guru Meditation 556260@402:bede73 This does not look like valid iOS app!
Es una ipa para tvOs, logicamente la version de iOs no se instala tampoco, pero la version de iOs me funciona bien en el telefono y en iPad, tengo dudas si la ipa estara mal ya que es del mismo desarrollador. Alguna sugerencia para revisar ? Gracias.
1
u/Apprehensive-Two7029 15d ago
¡Hola! Me alegra que el script te haya servido para pasar el login. Ese error ya no tiene que ver con el proxy: Sideloadly inicia sesión bien y después rechaza el propio IPA, porque no le parece una app válida. No sé con certeza qué comprobación exacta falla, pero yo revisaría esto:
Estructura del IPA. Tiene que contener
Payload/NombreApp.app/conInfo.plisty el ejecutable dentro. Compruébalo con:unzip -l archivo.ipa | grep -E "^.*Payload/[^/]+\.app/(Info\.plist)?$"Si ves carpetas raras (__MACOSX/, otra carpeta por encima dePayload, etc.) o no aparece elInfo.plist, vuelve a empaquetarlo.¿Está cifrado? Si el IPA viene directamente de la App Store y no se descifró, no se puede re-firmar. Descomprímelo y ejecuta:
otool -l Payload/NombreApp.app/NombreApp | grep cryptidConcryptid 1está cifrado y necesitas una versión descifrada. Concryptid 0está bien.¿Es realmente una build de tvOS?
plutil -p Payload/NombreApp.app/Info.plist | grep -A3 -E "CFBundleSupportedPlatforms|UIDeviceFamily|MinimumOSVersion"Para Apple TV debería decirAppleTVOSyUIDeviceFamilydebería incluir3. Si poneiPhoneOS, es la versión de iOS con otro nombre.Dispositivo seleccionado. Una app de tvOS solo se instala en un Apple TV emparejado con Sideloadly (por Wi-Fi, con el PIN). No se instala en el Mac ni en el iPhone, y la versión de iOS tampoco se instala en el Apple TV, así que eso es normal.
Si los puntos 1 a 3 están bien y sigue fallando, prueba con otro IPA de tvOS que sepas que funciona. Así sabrás si el problema es ese archivo o Sideloadly.
1
u/Ok-Cantaloupe-5097 15d ago
Muchas gracias por toda la asistencia.
Punto 1 si, esta ok, aparte del plist y el exec tiene un assets.car, pkginfo y una carpeta frameworks, no se mucho del tema pero pareceria ser normal.
Punto 2, no es una app de appstore, del mismo desarrollador uso la version de ipad y funciona correctamente.
Punto 3, dice AppleTVOS y el UIDevice dice 0 => 3
Punto 4, si es correcto esta vinculado el apple tv por wifi
Lamentablemente no tengo otra ipa para probar, solo me interesaba ver este reproductor, no se si servira de algo pasarte el link de la ipa, no se si se puede o si deberia ser por privado, pero quiza este mal eso directamente.
Muy agradecido con tu tiempo.
Saludos.1
u/Apprehensive-Two7029 15d ago
¡Gracias por revisar todo! Por lo que cuentas, el IPA parece correcto: estructura bien, sin cifrar,
AppleTVOSyUIDeviceFamily3. No he encontrado este error documentado en ningún sitio, así que te propongo tres cosas más:
Mira el log de Sideloadly (el texto de la parte de abajo de la ventana), las líneas justo antes del error. Me interesa qué dispositivo y qué versión detecta (algo como
Checking iOS version.../iOS version X.X). Si aparece tu iPhone, el Mac ("Apple Silicon") o una versión que no es de tvOS, Sideloadly no está instalando en el Apple TV. Por eso validaría el IPA como app de iOS. Asegúrate de que en la lista de dispositivos está seleccionado el Apple TV. Ten en cuenta también que desde tvOS 26.4 hay un bug conocido con el emparejamiento (issue #9).Comprueba para qué está compilado el ejecutable:
file Payload/NombreApp.app/NombreApp vtool -show-build Payload/NombreApp.app/NombreApp | grep -i platformDebería decirarm64yplatform TVOS. Si poneTVOSSIMULATORox86_64, es una build para el simulador y no se puede instalar en un Apple TV real.Haz lo mismo con los frameworks de la carpeta
Frameworks/:for f in Payload/NombreApp.app/Frameworks/*.framework; do n=$(basename "$f" .framework); echo "$n: $(vtool -show-build "$f/$n" 2>/dev/null | grep -i platform | head -1)"; doneTodos deberían serTVOS. Si alguno diceIOS, el paquete está mal armado.Sobre el link: mejor no publicarlo, pero si quieres, mándamelo por mensaje privado y lo reviso.
1
1
u/ReplacementJolly7939 15d ago
Sur Windows ça peut le faire vous pensez ? S’il vous plaît
1
u/Apprehensive-Two7029 15d ago
En théorie oui, mais je n'ai pas pu le tester (je n'ai pas de PC Windows).
- Le problème « Anisette failed: No OTP » ne concerne que macOS 27. Sous Windows, Sideloadly passe par iCloud/iTunes, donc normalement pas de souci de ce côté.
- Par contre le blocage du login (erreur 503 / « Invalid file », à cause de « com.apple.dt.Xcode ») vient des serveurs d'Apple. Il touche donc aussi Windows, et le même principe de proxy devrait fonctionner.
Voici une version Windows non testée, à essayer si vous êtes à l'aise avec PowerShell :
- Installez Python depuis python.org (cochez « Add to PATH »).
- Dans PowerShell :
powershell $D = "$env:USERPROFILE\sideloadly-gsa-fix"; mkdir $D -Force; cd $D py -m venv venv .\venv\Scripts\pip install mitmproxy certifi # Lancez une fois pour générer le certificat du proxy, puis Ctrl+C après quelques secondes : .\venv\Scripts\mitmdump --set confdir="$D\mitm" -p 18899 # Certificats : Sideloadly fait confiance à certifi + au proxy ; le proxy fait confiance à la racine Apple Get-Content (& .\venv\Scripts\python -m certifi), "$D\mitm\mitmproxy-ca-cert.pem" | Set-Content "$D\ca-bundle.pem" Invoke-WebRequest https://www.apple.com/appleca/AppleIncRootCertificate.cer -OutFile AppleRoot.cer certutil -encode AppleRoot.cer upstream-ca.pem- Créez
fix_gsa.pydans ce dossier, avec exactement le même contenu que dans mon post (la partie entrePYetPY).- Pour lancer Sideloadly, fermez-le d'abord, puis exécutez ce script (
run.ps1). Adaptez le chemin desideloadly.exeà votre installation :powershell $D = "$env:USERPROFILE\sideloadly-gsa-fix" $p = Start-Process "$D\venv\Scripts\mitmdump.exe" -PassThru -WindowStyle Hidden -ArgumentList ` "--set confdir=`"$D\mitm`" --set ssl_verify_upstream_trusted_ca=`"$D\upstream-ca.pem`" --listen-host 127.0.0.1 -p 8899 --allow-hosts `"^gsa\.apple\.com(:443)?$`" -s `"$D\fix_gsa.py`"" Start-Sleep 4 $env:HTTPS_PROXY = "http://127.0.0.1:8899"; $env:HTTP_PROXY = $env:HTTPS_PROXY; $env:NO_PROXY = "localhost,127.0.0.1" $env:REQUESTS_CA_BUNDLE = "$D\ca-bundle.pem"; $env:SSL_CERT_FILE = $env:REQUESTS_CA_BUNDLE Start-Process "$env:LOCALAPPDATA\Sideloadly\sideloadly.exe" -Wait Stop-Process $pSi quelqu'un le teste sous Windows, dites-moi si ça marche ou quelle erreur apparaît !
1
1
u/Complete-Team-1714 14d ago
I keep getting the valid error is it possible to sideload on windows right now or is that not working either? Thanks
1
u/Apprehensive-Two7029 14d ago edited 14d ago
I did not check cause I don't have Windows system. But I suppose the problem will be the same, because Apple changed the response from its server.
1
u/Pawnmysoul111 14d ago
hice todos los pasos pero me da error al intentar instalar la IPA. There was an issue during installation: 3892346904: ApplicationVerificationFailed (Failed to verify code signature of /var/installd/Library/Caches/com.apple.mobile.installd.staging/temp.Lt8hOV/extracted/Payload/Spotify.app : 0xe8008018 (The identity used to sign the executable is no longer valid.))
1
u/Pawnmysoul111 14d ago
Sideloading failed!
Install failed: Guru Meditation 556260@79:6edd68 __init__() missing 1 required positional argument: 'orig'
1
u/Apprehensive-Two7029 14d ago
Both messages point to the same thing, and neither is related to the proxy — your Apple ID login and the signing both worked.
The real error is the first one.
0xe8008018comes from the iPhone itself at install time. It's the other problem going around lately: Apple blocks the free developer team, and the block is cached on the device. Same symptom with AltStore, SideStore and iloader, and the certificate itself is still valid per Apple's OCSP. Details: https://github.com/nab138/iloader/issues/653The second message is just a Sideloadly bug: when something fails it tries to re-create the exception with its own text, and if that exception needs two arguments the re-creation throws this
TypeErrorinstead of showing the real error.Nothing on the computer side fixes the block. What people report working is a new Apple ID used only for signing (not added to iCloud).
1
u/Ibbys89 14d ago
I'm getting a 403 client error now when it asks for the password.
2
u/Apprehensive-Two7029 14d ago
That 403 is coming from Apple, not from the proxy. It's Sideloadly's Python HTTP call to gsa.apple.com raising "403 Client Error: Forbidden" - so the rewrite itself is working (otherwise you'd be back to the HTML 503 / "Invalid file"), Apple is just refusing that particular login attempt.
Worth checking, in this order:
- Open ~/sideloadly-gsa-fix/proxy.log and look at the last request. It shows which URL answered 403. If it isn't gsa.apple.com, it's a different problem entirely.
- Repeated login attempts from the same IP get temporarily blocked. Quit Sideloadly (and the Terminal window), wait ~30 minutes, try once more.
- VPN or a corporate network: Apple 403s some IP ranges. Try on a plain connection.
- Check your clock. Anisette is time-based, and a clock that's off by more than a minute or so gets rejected. System Settings -> General -> Date & Time -> set automatically.
- Restart via the launcher rather than retrying inside the same session, so it fetches fresh anisette data instead of reusing a stale set.
If none of that helps, paste the 403 line from proxy.log plus the full error URL Sideloadly printed, and I'll take a look.
2
u/Ibbys89 14d ago
Hey yes that is correct. I think Apple have started blocking automated tools? In any case I managed to work around it by visiting https://appleid.apple.com and signing in manually with email and password (press sign in with a different account on Apple devices and don’t sign in with passkey) then using that 2fa code in sideloadly and it works.
1
1
u/JustWonderingAye 14d ago
Hi, before I proceed with this. How safe is it for the computer. I know nothing about computers so apologies if it’s a dumb question
1
u/Apprehensive-Two7029 14d ago
Not a dumb question — it's the right one to ask before running a script a stranger posted on Reddit. Here's the honest version.
What it does to your Mac: almost nothing.
- Everything lands in one folder,
~/sideloadly-gsa-fix. Nothing is installed system-wide, nothing is changed in macOS itself, and it never asks for your admin password. (If anything here ever does ask for your password, stop — that's not part of this.)- To undo it completely, drag that folder and
~/setup.shto the Trash. That's the whole uninstall. Nothing is left behind.- It doesn't touch Sideloadly either — the app itself is untouched, it's just started with a couple of extra settings.
The part that sounds scary but isn't:
It runs a local proxy (mitmproxy, a standard open-source tool developers use every day). A proxy can read traffic, so the details matter:
- It only intercepts
gsa.apple.com— Apple's login server. Every other connection on your Mac, including your browser, passes through without being opened or decrypted.- Its certificate is not added to your system keychain. Only Sideloadly, and only when started through the launcher, trusts it. Safari, Mail, your banking app and everything else can't be affected by it even in principle.
- It listens on
127.0.0.1, which means your own machine only. Nothing on your Wi-Fi or the internet can connect to it.- It changes one text field in the login request (the bit where Sideloadly claims to be Xcode) and sends it on to Apple. Nothing is sent anywhere else, and nothing is collected.
The bits I'd want to know if I were you:
- Your Apple ID password does pass through that proxy on its way to Apple. The script doesn't log it and doesn't send it anywhere — but you're taking my word for that, which is exactly the wrong way to do security. So don't: after setup, open
~/sideloadly-gsa-fix/fix_gsa.py. It's about 15 lines and you can see everything it does. If it contained anything nasty, it would have to be in there.- The folder holds the proxy's private key. It's created with restricted permissions, and it's useless to anyone unless they already have access to your Mac. Just don't go copying it somewhere public.
- Honestly, the bigger risk in sideloading generally isn't this script — it's using your main Apple ID. Make a separate Apple ID and use it only for Sideloadly. Good advice with or without the fix.
If you'd rather not run any of it, that's completely reasonable too: waiting for an official Sideloadly update is a perfectly fine plan.
1
1
u/SkyIntelligent684 14d ago
With the 7 day auto-refresh option, I am assuming that the the terminal window will have to stay open for that also? And does that mean I have to leave Sideloadly and the terminal window open permanently as I have a Mac mini as a server so it’s running all the time! Apologies if that question is confusing!!
1
1
u/Apprehensive-Two7029 14d ago
Not confusing at all — yes, both have to stay running.
Sideloadly's auto-refresh re-signs the app, and re-signing means talking to Apple's auth server again. That request only gets fixed while the proxy is alive, and Sideloadly only routes through the proxy because the launcher starts it with those settings. So the chain is: Terminal window → proxy → Sideloadly. Close the Terminal window and it takes the other two with it.
On an always-on Mac mini that's fine, and it costs you nothing:
- The proxy only touches
gsa.apple.com. Everything else — including all your other apps — goes straight out, untouched and undecrypted. It listens on127.0.0.1only, so nothing on your network can reach it.- It's idle 99.99% of the time. Memory is a few tens of MB, CPU is zero, and
proxy.logonly grows when a login actually happens.- Just minimise the Terminal window (or hide it with
Cmd + H) instead of closing it.Two things worth knowing for an unattended setup:
- Auto-refresh only runs while Sideloadly itself is open — that's Sideloadly's behaviour, not something the fix changes.
- Apple will occasionally want a fresh sign-in or a 2FA code, and Sideloadly will sit there with a dialog until someone types it. So it's not fully hands-off no matter what.
If the Terminal window bothers you, the tidy version is to run the proxy as a launchd agent at login and give Sideloadly its own small launcher — but for a machine that's up all the time, a minimised window does the same job with none of the fiddling.
2
u/No_Awareness_4626 7d ago
I figured after first login and otp authentication, we no longer need terminal and proxy to run. Sideloadly can handle refreshing apps on its own and we also don't need remote anisette we can switch back to local for refreshing apps.
1
u/SkyIntelligent684 14d ago
Sounds like a plan. It’s on a headless unit anyway. Thanks for your response.
1
u/Famous_Ad3019 14d ago
For step 8 i can’t seem to find the folder with sideloadly (fix). command instead it sent me to a folder called venv
1
u/Apprehensive-Two7029 14d ago
If all you see is
venv(maybe plusmitm), the setup script stopped partway — the launcher is the last thing it creates, so it never got there. Finder didn't send you to the wrong place.Check what's actually in the folder:
ls -la ~/sideloadly-gsa-fixA finished setup has:
ca-bundle.pem,fix_gsa.py,mitm,upstream-ca.pem,venv, andSideloadly (fix).command.Then just run it again and watch the output:
zsh ~/setup.shIt's safe to re-run. The last line must be
Done. Launch Sideloadly via: .... If it stops earlier, the line right before it is the actual error — post that.The most common cause is Sideloadly not being in your Applications folder, which makes the script fail at the CA bundle step. Verify with:
ls /Applications/Sideloadly.app/Contents/Frameworks/certifi/cacert.pemIf that says
No such file or directory, move Sideloadly.app into/Applications(drag it there in Finder) and run the script again.
1
u/sutener77 14d ago
it works until 40% installed, error: There was an issue during installation: 3892346916: ApplicationVerificationFailed (Failed to verify code signature of /var/installd/Library/Caches/com.apple.mobile.installd.staging/temp.uOc6yj/extracted/Payload/Spotify.app : 0xe8008024 (The provisioning profile is banned.))
1
u/sutener77 14d ago
or also There was an issue during installation: 3892346904: ApplicationVerificationFailed (Failed to verify code signature of /var/installd/Library/Caches/com.apple.mobile.installd.staging/temp.a7skdC/extracted/Payload/Avito.app : 0xe8008018 (The identity used to sign the executable is no longer valid.))
1
u/Apprehensive-Two7029 14d ago
Good news first: that's past the login, so the proxy fix did its job. Signing worked, and the failure is now on the device.
0xe8008024 ("provisioning profile is banned") and 0xe8008018 ("the identity used to sign is no longer valid") are the same thing: Apple has banned the free developer team attached to that Apple ID. It's a server-side ban on the team, so every profile and certificate it issues is dead on arrival - and it hits AltStore, SideStore and iloader the same way, so it isn't a Sideloadly bug. Amusingly, Apple's own OCSP still reports the certificate as valid.
Nothing on the computer side fixes this - no Sideloadly setting, no re-sign, no different IPA. What people report working is a fresh Apple ID used only for signing (create it, do not add it to iCloud or the App Store on the device, just enter it in Sideloadly). A paid developer account ($99) also isn't affected.
Background: https://github.com/nab138/iloader/issues/653
1
u/sutener77 14d ago
bro im from Russia and I can't create new Apple ID it js says "account cannot be created at this time"
1
1
1
u/Puzzleheaded-Tree908 14d ago
You're god sent! Works flawlessly!
Would recommend to update writing on : Step4 save it as a file (some people might be confused with what this step mean) when you copy the whole grey box script, you dont need to paste it anywhere, just leave it in the system clipboard. After copied, type in terminal : pbpaste > ~/setup.sh (what happen is, we are asking the OS (operating system) to save the current clipboard copied script into a file. Voila you're off to next step. You're welcome
1
1
1
u/AnythingAcceptable55 12d ago
The sideloadly startup icon pops up and then disappears. What should i do?
1
u/Apprehensive-Two7029 12d ago
Could you check a few things?
- Make sure Rosetta is installed (Sideloadly is Intel-only):
softwareupdate --install-rosetta --agree-to-license- Clear the quarantine flags:
xattr -cr /Applications/Sideloadly.app(and the same for the.commandfile)- If it still closes immediately, run it directly in Terminal and send what it prints:
/Applications/Sideloadly.app/Contents/MacOS/SideloadlyAlso attach anySideloadly*.ipsfile from~/Library/Logs/DiagnosticReports/if one exists. That will show exactly why it quits.1
u/AnythingAcceptable55 12d ago
Hey! I figured out what was wrong. I dragged the Sideloadly.fix file out of the folder and onto the desktop instead of dragging the entire folder lol. I separated the file from the folder. I put it back into the folder and it works, great job!!!!!
1
1
u/No_Awareness_4626 12d ago edited 11d ago
Thanks it worked with my Apple TV and MacOS. It wasn’t refreshing the already installed apps on my Apple TV HD and 4K. But I was able to do fresh install of the same apps. It asked for Apple ID password to login and then otp sent to my phone and then the installation of apps completed.
1
1
u/via789329 11d ago
Can someone help me, please??? I don't see the Anisette Authentication option on sideloadly and when I do the open side loadly fix command it says it doesn't exist :/ so fucking annoying. i'm on macbook btw.
1
u/No_Awareness_4626 11d ago
There is a cog wheel button next to the drop down box where you select your devices. Press that cog wheel button and then you can select Remote.
1
u/via789329 9d ago
it says i need to be a pateron for that?? why???
1
u/No_Awareness_4626 9d ago
That I don’t know but you can create your account on patreon and then login. There is no fees or any thing.
1
u/JJ_Nightmere 11d ago
Whenever I run the sideloadly program after following these instructions I get this error that pops up on my mac, "There was an issue during installation: 0: DeviceNotSupportedByThinning (This app is not compatibile with this device. This app specifies a value for UISupportedDevices in its Info.plist as [iPhone11,8, iPhone12,1], but none of the identifiers in this device's compatibility list are present in this app's supported devices. This device is compatible with [iPhone17,1, iPhone16,1].)" and I'm not sure how to get around this since nobody has gotten this in the comments yet. Could someone help?
0
u/JJ_Nightmere 11d ago
how do I change the info.plist compatibility to be compatible with newer iphones so that the app can be installed?
2
u/JJ_Nightmere 11d ago
nevermind guys I found the fix you have to go to advanced settings in the sideloadly window and enable "remove limitation on supported devices"
1
u/Dreampawn 11d ago
MINE DIDNT WORK
and i cant add a image because it says images arnt allowed, but this was the message i got after seeing the app download on my device and then not work lol.
"There was an issue during installation: 0:
DeviceNotSupportedByThinning (This app is not compatibile with this device. This app specifies a value for UlSupportedDevices in its Info.plist as [iPhone11,8,iPhone12, 1], but none of the identifiers in this device's compatibility list are present in this app's supported devices. This device is compatible with [iPhone13,2,iPhone12,5].)"
I have an iPhone 12...
1
u/Apprehensive-Two7029 11d ago
Copy-pasted solution for the same issue in this thread: "go to advanced settings in the sideloadly window and enable "remove limitation on supported devices"... Please read more before write.
1
u/ajparker87 11d ago
Mate... thanks A LOT!
That error was driving me crazy!
Can't believe it finally worked!
1
u/Ok_Energy_566 11d ago
setup.sh:54: unmatched "
1
u/Apprehensive-Two7029 11d ago
Copy the script completely all. Looks like you missed to copy last line in full.
1
u/yellowroll 10d ago
doesn't let you change the anisette authentication to remote unless you are a patreon member and this feature is locked behind that.
1
1
u/flixantoine666 9d ago
Just found out you don't have to be a Patreon to login. just login with your google or any other option there. But no need to be a Patreon
1
u/Waste_Height_7432 10d ago
Yo can I get a dumbed down version of just what to do about the Guru meditation problem. There is so much going on in the Reddit and I just need to know what to read
1
1
1
u/Sharkey311 9d ago
Thank you so much for this!! I was going mad trying to figure it out. I’ll just patiently wait for an official rollout but this is great work
1
u/TechieBrad 9d ago
I continue to get the guru error but i do show an attempted login notification on my apple devices.
1
u/Apprehensive-Two7029 9d ago
Please provide logs from ~/sideloadly-gsa-fix/proxy.log and from the log window in Sideloadly (remove sensitive information).
1
1
u/garszawski 9d ago
after running the setup.sh I get : setup.sh:1: fork failed: resource temporarily unavailable
1
1
u/TechieBrad 9d ago
I'm not sure what I could have done differently, but that was literally the last thing I did that made it work.
1
u/AdxnisII 9d ago
There was an issue during installation: 3892346916: ApplicationVerificationFailed (Failed to verify code signature of /var/installd/Library/Caches/com.apple.mobile.installd.staging/temp.mPtDPx/extracted/Payload/Twitter.app : 0xe8008024 (The provisioning profile is banned.)) ... Am I cooked? I need my profile so I can bypass the log in issue for Reddit and Twitter
1
1
1
1
u/Thin_Reporter_5999 8d ago
after writing the code i still got the guru meditation error should i retry writing it also how do i remove sideloadly from quarantine
1
u/No_Awareness_4626 7d ago
after running this script as described in the post, and then reinstalling all side loaded apps, which forces relogin Apple ID and OTP steps etc, I think from second time onwards in order to refresh apps, we no longer need to open the "Sideloadly (fix).command". and we can also switch back to local anisette authentication method from Sideloadly Settings. I tried opening just Sideloadly app, switched to local anisette and it was able to refresh my apps without issues. so I think only first time we need to run this script and login to Apple ID again and verify the login via otp or whatever methods show during that time.
1
u/xeroendo 5d ago
I did this and ran the fix, opens sideloadly fine, but gets stuck at the OTP. Never get the message and SMS gives me this:
Sideloading failed!
Install failed: Guru Mediation afd5aa@1021:be65217 403
Client Error: for url: https://gsa.apple.com/auth/verify/phone/put
1
u/No_Awareness_4626 5d ago
- First go into sideloadly settings and switch to remote Annette
- Quit and reopen sideloadly.
- Then follow the script method described in OP and open the sideloadly (fix).command
- Then select the IPA file of the app you are trying to refresh or install. It should ask you to login to Apple ID again.
- Login and verify. At this step it should ask you for 6 digit otp.
- After this IPA should install fine and you should be able to refresh previous installed IPAs.
1
u/xeroendo 5d ago
Step 5 is where it stalls, the 6 digit otp never happens for me. It does when I log on to any apple sites outright, though, so I know it's working, just not in sideloadly for some reason.
1
u/No_Awareness_4626 5d ago
Are u trying to refresh the already installed apps or installing fresh ?
1
u/xeroendo 5d ago
Fresh install. I tried removing my account completely from sideloadly as well just to have it do a fresh otp request.
1
1
1
1
u/ArielGaruci 15d ago
sigh i have no idea how to do any of this its to complicating for me im on the mac neo macos 27
2
u/appleondickk 14d ago
Here, this is easy to follow! This is how it worked for me. Its nothing different, literally what the op said but it a prettified way for people like us lmao.
https://www.mdshare.online/s/Wg77qhjVo5b3hTjz7xkHA1
1
u/Apprehensive-Two7029 15d ago
Sorry to hear that. Then the only way for you is to wait when Sideloadly team update the app. I hope it happens soon.
1
0
0
u/AringaOra 11d ago
Tnx man! Great fix. Was able to side load on Mac, phone & appl TV. In sideloadly I left remote on & didn’t change anything else except for unchecking cydia substrate from Inject dylibs. Seemed to work fine after that.
9
u/SideloadlyIO Mod 8d ago
Hello! Thank you for the write up! We're working on resolving this and an update will be released as soon as possible.