This is a reference for all of the entitlements that let you add more functionality to
your app, and links to the forms to request them. You should, of course, read each
carefully and be sure to conform to whatever restrictions are placed on the entitlements.
This is meant as an index to make it a bit simpler to find the link you need.
Notifications & messaging
| Entitlement |
Key |
Platforms |
Request |
| Critical Alerts |
com.apple.developer.usernotifications.critical-alerts |
iOS, iPadOS, macOS, tvOS, watchOS, visionOS, Mac Catalyst |
Request |
| Notification filtering (silence pushes in a service extension) |
com.apple.developer.usernotifications.filtering |
iOS, iPadOS, macOS |
Request |
CarPlay
| Entitlement |
Key |
Platforms |
Request |
| CarPlay — audio, video, communication/messaging, navigation (maps), parking, EV charging, fueling, quick food ordering, driving task, public safety |
com.apple.developer.carplay-audio, -video, -communication, -messaging, -maps, -parking, -charging, -quick-ordering, … |
iOS, iPadOS |
Request |
Note on CarPlay video: it's a separate request from the others. If you also want your
app to appear in cars without video support, you need the CarPlay audio entitlement too.
Screen Time & education
| Entitlement |
Key |
Platforms |
Request |
| Family Controls (Distribution) |
com.apple.developer.family-controls |
iOS, iPadOS, Mac Catalyst, visionOS |
Request |
| Automatic Assessment Configuration |
com.apple.developer.automatic-assessment-configuration |
iOS, iPadOS, macOS |
Request |
Networking
| Entitlement |
Key |
Platforms |
Request |
| Multicast Networking |
com.apple.developer.networking.multicast |
iOS, iPadOS, tvOS, visionOS |
Request |
| Hotspot Helper |
com.apple.developer.networking.hotspothelper |
iOS, iPadOS |
Request |
| Manage Thread Network Credentials (distribution) |
com.apple.developer.networking.manage-thread-network-credentials |
iOS, iPadOS, visionOS |
Request |
macOS system-level
| Entitlement |
Key |
Platforms |
Request |
| Endpoint Security client |
com.apple.developer.endpoint-security.client |
macOS |
Request |
| DriverKit family entitlements (distribution) |
com.apple.developer.driverkit.* |
macOS, iPadOS |
Request |
| System Extension redistribution |
— |
macOS |
Request |
| Persistent Content Capture (VNC screen capture) |
com.apple.developer.persistent-content-capture |
macOS |
Request |
All three of the first entries share one intake form.
Payments & identity
| Entitlement |
Key |
Platforms |
Request |
| Tap to Pay on iPhone |
com.apple.developer.proximity-reader.payment.acceptance |
iOS |
Request |
| ID Verifier (display-only & data transfer) |
com.apple.developer.proximity-reader.identity.display / .read |
iOS, iPadOS |
Request |
| Verify with Wallet (in-app identity presentment) |
com.apple.developer.in-app-identity-presentment |
iOS, iPadOS |
Request |
| FinanceKit |
com.apple.developer.financekit |
iOS, iPadOS, macOS |
Request |
| NFC & SE Platform / HCE (card session, default contactless app) |
com.apple.developer.nfc.hce, .hce.default-contactless-app, .hce.iso7816.select-identifier-prefixes, com.apple.developer.secure-element-credential |
iOS, iPadOS |
Request · Background (EEA) |
| Apple Pay In-App Provisioning (card issuers) |
com.apple.developer.payment-pass-provisioning |
iOS, watchOS |
Request |
| UPI Device Validation (India / NPCI) |
com.apple.developer.upi-device-validation |
iOS, iPadOS |
Request |
Health & safety
| Entitlement |
Key |
Platforms |
Request |
| Fall Detection |
com.apple.developer.health.fall-detection |
iOS, iPadOS, watchOS |
Request |
| Crash Detection (severe vehicular crash events) |
com.apple.developer.severe-vehicular-crash-event |
iOS, iPadOS, watchOS |
Request |
| SensorKit reader |
com.apple.developer.sensorkit.reader.allow |
iOS, iPadOS, visionOS |
Request · Study approval |
Privacy-sensitive device data
| Entitlement |
Key |
Platforms |
Request |
| Contact Notes field |
com.apple.developer.contacts.notes |
iOS, iPadOS, macOS, visionOS |
Request |
| User-Assigned Device Name |
com.apple.developer.device-information.user-assigned-device-name |
iOS, iPadOS, Mac Catalyst, tvOS, visionOS, watchOS |
Request |
| Location Push Service Extension |
com.apple.developer.location.push |
iOS, iPadOS, macOS |
Request |
| Multitasking Camera Access (no longer required as of iOS 18) |
com.apple.developer.avfoundation.multitasking-camera-access |
iPadOS |
Request |
Browsers & default apps
Largely driven by the EU Digital Markets Act and the equivalent Japanese regulation, so
most of these are region-limited.
| Entitlement |
Key |
Platforms |
Request |
| Default Browser (+ browser app-installation) |
com.apple.developer.web-browser, com.apple.developer.browser.app-installation |
iOS, iPadOS, macOS |
Request |
| Alternative Browser Engine (host + embedded) |
com.apple.developer.web-browser-engine.host/.networking/.rendering/.webcontent, com.apple.developer.embedded-web-browser-engine |
iOS, iPadOS (EU & Japan) |
Request · Background |
| Alternative app marketplace / app installation |
com.apple.developer.marketplace.app-installation |
iOS, iPadOS (EU) |
Request · Background |
| Passkeys in a macOS browser |
com.apple.developer.web-browser.public-key-credential |
macOS, Mac Catalyst |
Request |
| Browser universal-links read/write |
com.apple.developer.associated-domains.applinks.read-write |
macOS |
Request |
| Default Mail Client |
com.apple.developer.mail-client |
iOS, iPadOS, visionOS |
Request |
Device management & enterprise
| Entitlement |
Key |
Platforms |
Request |
| Automated Device Enrollment — add devices |
com.apple.developer.automated-device-enrollment.add-devices |
iOS, iPadOS |
Request |
| Enrollment SSO |
com.apple.developer.enrollment-sso-capable |
iOS, iPadOS, macOS |
Request |
| Enterprise APIs for visionOS |
ten separate keys — see below |
visionOS |
Request |
Enterprise APIs for visionOS
Ten distinct capabilities, each with its own key, all behind the same request form.
| Capability | Key | Platforms | Request |
| Main camera access |
com.apple.developer.arkit.main-camera-access.allow |
visionOS |
Request |
| Camera region |
com.apple.developer.arkit.camera-region.allow |
| Shared coordinate space |
com.apple.developer.arkit.shared-coordinate-space.allow |
| Spatial barcode & QR scanning |
com.apple.developer.arkit.barcode-detection.allow |
| Object-tracking parameter adjustment |
com.apple.developer.arkit.object-tracking-parameter-adjustment.allow |
| Visual fidelity monitoring |
com.apple.developer.arkit.visual-fidelity.allow |
| Passthrough in screen capture |
com.apple.developer.screen-capture.include-passthrough |
| App-protected content |
com.apple.developer.protected-content |
| Increased performance headroom |
com.apple.developer.app-compute-category |
| Window follow mode |
com.apple.developer.window-body-follow |
visionOS enterprise APIs are organization- and enterprise-account only, and they
require an Apple-issued license file shipped inside your app bundle. The entitlement
alone isn't enough.
Carrier
| Entitlement |
Key |
Platforms |
Request |
| eSIM access (CoreTelephony fine-grained) |
com.apple.commcenter.fine-grained |
iOS, iPadOS |
Request |
| Carrier refresh token (subscriber info) |
com.apple.commcenter.fine-grained |
iOS, iPadOS |
Request |
Media & commerce
| Entitlement |
Key |
Platforms |
Request |
| Video Partner Program (Apple TV app + Universal Search, single sign-on) |
com.apple.smoot.subscriptionservice, com.apple.developer.video-subscriber-single-sign-on |
iOS, iPadOS, tvOS, macOS |
Request |
| StoreKit External Link Account |
com.apple.developer.storekit.external-link.account |
iOS, iPadOS, macOS, tvOS, visionOS, watchOS |
Request |
| StoreKit External Purchase / External Purchase Link |
com.apple.developer.storekit.external-purchase, .external-purchase-link, .external-purchase-link-streaming, .custom-purchase-link.allowed-regions |
iOS, iPadOS, macOS, tvOS, visionOS, watchOS, Mac Catalyst |
Request |
| Advanced Commerce API |
— (App Store Connect access) |
all |
Request · Docs |
| Real-time Retention Messaging API |
— (App Store Connect access) |
all |
Request · Docs |
Both StoreKit external-purchase entitlements use the same intake form, but qualification
criteria differ by region.
New in the 2026 SDKs
| Entitlement |
Key |
Platforms |
Request |
| Private Cloud Compute |
com.apple.developer.private-cloud-compute |
iOS 27, iPadOS 27, macOS 27, visionOS 27, watchOS 27 |
Request · Overview |
| Foveated Streaming Provider |
com.apple.developer.foveated-streaming-provider |
visionOS 27 |
Request |
Housekeeping
| Purpose |
Request |
| Migrate an already-granted entitlement to a new App ID or team, or surface an entitlement that isn't showing up as a managed capability |
Request |
Restricted, but with no public request form
Apple gates these too, but publishes no self-serve form. Getting them means going through
an Apple representative, a partner program, or a DTS incident.
| Entitlement |
Key |
Platforms |
How to get it |
| VM networking / hypervisor / device access |
com.apple.vm.networking, com.apple.vm.hypervisor, com.apple.vm.device-access |
macOS |
Restricted to developers of virtualization software; contact your Apple representative |
| Critical Messaging (SMS without user interaction) |
com.apple.developer.messages.critical-messaging |
iOS, iPadOS, watchOS |
Restricted; no published form |
| Carrier messaging app (SMS/MMS/RCS via TelephonyMessagingKit) |
com.apple.developer.carrier-messaging-app |
iOS, iPadOS |
Carrier partners only |
| Default calling / dialing / messaging / navigation / translation app |
com.apple.developer.calling-app, .dialing-app, .messaging-app, .navigation-app, .translation-app |
iOS, iPadOS, watchOS |
Managed capability with technical review — request from your App ID's Capability Requests tab |
| Media Device Extension (third-party route picker protocol) |
com.apple.developer.media-device-extension |
iOS 27, iPadOS 27 |
Managed entitlement; mutually exclusive with all other managed entitlements |
| Exposure Notification |
com.apple.developer.exposure-notification |
iOS, iPadOS |
Public health authorities only — see the overview, then go through Apple Developer contact |
| Journaling Suggestions |
com.apple.developer.journal.allow |
iOS, iPadOS |
Restricted |
| Wireless Insights service predictions |
com.apple.developer.wireless-insights.service-predictions |
iOS 26, iPadOS 26 |
Restricted |
If you can't find a form: any managed capability can be requested from
Certificates, Identifiers & Profiles → Identifiers → your App ID →
Capability Requests
tab → Request. That's the catch-all when an entitlement has no dedicated intake.
Not actually gated
These get assumed to need approval and don't. They're plain Xcode capabilities you can
turn on yourself:
- Trust Insights —
com.apple.developer.trustinsights.base (iOS 27 / iPadOS 27). Just add the capability, but note the DPLA §3.3.3(R) usage terms.
- Background GPU access —
com.apple.developer.background-tasks.continued-processing.gpu (iOS 26+)
- Neural Engine background inference —
com.apple.developer.background-tasks.continued-processing.inference (iOS 27 and all 27-generation platforms)
- Extended Virtual Addressing —
com.apple.developer.kernel.extended-virtual-addressing
- Image Playground — no entitlement at all
- Family Controls app & website usage —
com.apple.developer.family-controls.app-and-website-usage (iOS 26.4). Note the base Family Controls distribution entitlement is gated.
- EnergyKit load events, Suggested Actions, Declared Age Range, Accessory Access (USB)
Entitlement gating changes often — Apple adds forms, retires them, and quietly moves
requirements between releases. If you hit a link that's moved or a rule that's changed,
let me know and I'll update this page.