Apple Wallet PKPass Inspector & Debugger
Drop a .pkpass or pass.json to inspect it automatically in your browser. Validate schema, hashes, assets, signature structure, colors, and barcodes; rebuild an unsigned package for trusted signing or use the explicit REST API in CI/CD.
Visual approximation for debugging. Layout can differ by Wallet version and device; confirm the final signed pass in Apple Wallet.
| File | Manifest Hash | Actual Hash | Integrity Status |
|---|
Why iOS Silently Drops .pkpass Files
When creating digital passes, iOS rarely shows descriptive error popups - it silently fails to open the pass. Here are the top failure reasons caught by this inspector:
manifest.json SHA-1 Desync
Modifying dates, colors, or barcode messages in pass.json without recomputing its SHA-1 checksum in manifest.json causes iOS to reject the archive immediately as corrupt or tampered.
Floating Dates Missing Timezones
iOS strictly requires all expirationDate and relevantDate strings to follow full ISO 8601 formatting with an explicit timezone offset (e.g. 2026-08-23T14:30:00+02:00 or Z). Floating dates without timezones are rejected.
Missing Required Assets & Retina Icons
Apple Wallet requires icon.png and icon@2x.png (58x58 px) for lock screen notifications. Missing icon files or incorrect aspect ratios will prevent the pass from installing.
Barcode Format & Encoding Errors
Using unsupported encoding headers or invalid format constants causes iOS barcode rendering failures. Standard encoding should always be utf-8 or iso-8859-1.
Frequently Asked Questions
What is inside an Apple Wallet .pkpass file?
A .pkpass file is a standard ZIP archive containing pass.json (field layouts, colors, dates, barcodes), manifest.json (SHA-1 checksum dictionary of all files), signature (PKCS#7 signature from Apple Developer), and PNG image assets (icon, logo, strip, thumbnail).
Can I test and preview .pkpass files on Android, Windows, or Linux?
Yes. The browser previews pass fields, colors, barcodes, and supported package images locally. It is a debugging preview, not a pixel-identical Apple Wallet rendering; confirm the final signed pass on an iPhone.
How does 'Rebuild Unsigned .pkpass' work?
Rebuild recalculates each file's SHA-1 checksum, regenerates manifest.json, removes any now-invalid old signature, and downloads an unsigned package. You must sign that package with an Apple Pass Type ID certificate before installing it.
Is my ticket or boarding pass uploaded to your server?
The browser workspace processes dropped files locally and does not upload them. The separate cURL and REST API examples explicitly send their request payload to StackHal for server-side processing; use those only when that behavior is appropriate.