# Should you pay for the Apple Developer Program?

> Free Apple developer account vs the $99 Apple Developer Program: what each lets you do, what changes when you pay, and why it helps outside the App Store too.

Author: [Flavio Copes](https://flaviocopes.com/about/) | Published: 2026-10-04 | Topics: [Swift](https://flaviocopes.com/tags/swift/) | Canonical: https://flaviocopes.com/apple-developer-free-vs-paid/

Until now I shipped my Mac apps without paying Apple. [NoteRepo](https://flaviocopes.com/noterepo/), [Soundscape](https://flaviocopes.com/soundscape/) and five more are free and open source on GitHub, and none of them was signed with a Developer ID.

It worked. But every one of their READMEs had the same paragraph: macOS says it "could not verify" the app "is free of malware", and you go to System Settings to click **Open Anyway**.

Then I wanted an iPhone app for NoteRepo that syncs with iCloud, which is impossible without the paid program. So I looked at everything the membership changes, including for apps that never touch the App Store, and paid the $99. NoteRepo 2.2 was the first of my apps signed and notarized with it, and the other six followed the same day.

## Two kinds of Apple developer accounts

The **free account** is any Apple ID that accepted the Apple Developer Agreement on [developer.apple.com](https://developer.apple.com). Apple's [membership comparison](https://developer.apple.com/support/compare-memberships/) lists what it includes: beta releases of Xcode and the OSes, testing on your own devices with Xcode, the developer forums, and Feedback Assistant.

The **Apple Developer Program** costs $99 a year, or the local equivalent. On top of the free features, it adds the Certificates, Identifiers & Profiles section of your account, notarization for Mac apps, App Store Connect, TestFlight, Xcode Cloud and code-level support from Apple engineers.

You can enroll as an individual or as an organization. I described the steps in [How to join the Apple Developer Program](https://flaviocopes.com/apple-developer-program/).

Nonprofits, accredited schools and government entities can ask for a [fee waiver](https://developer.apple.com/support/membership-fee-waiver/). Individuals and one-person businesses can't.

## What you can do for free

Xcode and Swift are free, and you can build and run any app on your own Mac. You can also ship that app to other people outside the App Store.

Apple silicon Macs refuse to run native code without a signature, but an **ad-hoc signature** counts. It's a signature with no identity behind it, and it costs nothing. Up to version 2.1, NoteRepo's build script signed the app with this line:

```sh
codesign --force --deep --sign - build/NoteRepo.app
```

The `-` after `--sign` means ad-hoc. Then you zip the app, attach it to a GitHub release, and people download it.

You can also put your own app on your own iPhone. Sign in to Xcode with your Apple ID, pick your "Personal Team" in the target's Signing & Capabilities, connect the phone and press ⌘R. The app stops opening after 7 days, until you run it from Xcode again, and you can have at most 3 apps installed this way.

### Where the free account stops

Apple publishes which capabilities each kind of account gets, for [macOS](https://developer.apple.com/help/account/reference/supported-capabilities-macos) and for [iOS](https://developer.apple.com/help/account/reference/supported-capabilities-ios). The free column is short. On the Mac it has App Groups, App Sandbox, hardened runtime, keychain sharing and Maps, and that's it.

So no iCloud, no push notifications, no Apple Pay, no Sign in with Apple, no In-App Purchase. And on iOS there's no App Store and no TestFlight, so nobody else can install your iPhone app at all.

## What your users feel when you don't pay

On the Mac, the free account is enough to ship, but the people who download your app pay for it.

### The first launch

Your browser marks every downloaded file with a quarantine flag. When you open a quarantined app, Gatekeeper checks it, and an app that isn't notarized gets the "could not verify" message, with no button to open it.

Up to macOS Sonoma, you could Control-click the app and pick **Open**. [Since macOS Sequoia](https://developer.apple.com/news/?id=saqachfa) that shortcut is gone. Now you try to open the app, dismiss the dialog, go to **System Settings → Privacy & Security**, click **Open Anyway** (the button stays there for about an hour), and type your password.

Or you remove the quarantine flag in Terminal:

```sh
xattr -dr com.apple.quarantine /Applications/NoteRepo.app
```

For a developer this is a minute of annoyance. For anyone else, the dialog says "malware", and Apple's own [support page](https://support.apple.com/guide/mac-help/open-an-app-by-overriding-security-settings-mh40617/mac) about overriding it opens with "Overriding security settings to open an app is the most common way that a Mac gets infected with malware".

### macOS forgets your app after every update

macOS remembers apps by their **designated requirement**, the rule a signature uses to say "this is me". You can see it with `codesign`:

```sh
codesign -d -r- build/NoteRepo.app
```

For an ad-hoc signed app, the identity is the hash of that exact build. Here's NoteRepo 2.1, the last ad-hoc version. It's a universal app, so there's one hash for Apple silicon and one for Intel:

```text
# designated => cdhash H"7c3e19b0a81992bd41d9597021a877055ff7428c" or cdhash H"c78a13342cec55b93a5a13589ed52a922a8dbfc1"
```

The next build has different hashes, so to macOS it's a different app. If your app asks for the microphone, screen recording or accessibility, the user grants it again after every update, and keychain items it saved can prompt again too. Apple's [TN3127](https://developer.apple.com/documentation/technotes/tn3127-inside-code-signing-requirements) describes exactly this: "Without a DR, macOS can't track this authorization across versions of your app."

NoteRepo doesn't ask for any permissions, so it doesn't run into this. An app that records the screen would run into it on every release.

### Homebrew won't list it

Since September 1, 2026, the official Homebrew cask repository disables casks for apps that fail Gatekeeper checks (see Homebrew's [deprecation rules](https://docs.brew.sh/Deprecating-Disabling-and-Removing)). In practice that means apps that aren't signed with a Developer ID and notarized. You can still publish your own tap, but `brew install --cask` from the main repository is off the table.

## What changes when you pay

### Mac apps open like any other app

The membership gives you a **Developer ID** certificate. You sign the app with it, send it to Apple's notary service, which scans it automatically, and attach the ticket Apple sends back.

[Notarization](https://developer.apple.com/documentation/security/notarizing-macos-software-before-distribution) has a few requirements: a Developer ID certificate, the hardened runtime, a secure timestamp, and no `get-task-allow` debugging entitlement. Xcode handles all of it when you export with Developer ID, and my free [Ship macOS Apps course](https://flaviocopes.com/courses/ship-macos-apps/) walks through the whole process. With a build script, it looks like this:

```sh
codesign --force --options runtime --timestamp \
  --sign "Developer ID Application: Flavio Copes (DGFKNTAG99)" build/NoteRepo.app
ditto -c -k --keepParent build/NoteRepo.app NoteRepo.zip
xcrun notarytool submit NoteRepo.zip --keychain-profile notary --wait
xcrun stapler staple build/NoteRepo.app
```

These are the steps NoteRepo's [`scripts/notarize.sh`](https://github.com/flaviocopes/noterepo/blob/main/scripts/notarize.sh) runs for every release. `DGFKNTAG99` is my team ID. `notary` is a credentials profile you save once with `xcrun notarytool store-credentials`, so the password never sits in the script. After stapling, you zip the app again and publish that zip.

Your users now get the normal dialog for apps from the internet, the one that asks if you're sure and has an **Open** button.

### iCloud and push, even outside the store

The capability tables have a separate column for apps signed with Developer ID, and it's long. It includes iCloud (CloudKit, iCloud Documents and key-value storage), push notifications, Apple Pay, associated domains, network extensions and system extensions.

What Developer ID apps can't use: In-App Purchase, Game Center, Sign in with Apple, WeatherKit, HomeKit, and a few other store-only features.

### A stable identity

With Developer ID, the designated requirement says "any build with this bundle ID, signed by this team". This is NoteRepo 2.2's:

```text
designated => identifier "com.flaviocopes.noterepo" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = DGFKNTAG99
```

The bundle ID and the team ID are the same in every build, so updates keep the same identity, and permissions and keychain access carry over.

### Homebrew, TestFlight and the App Store

Your app can be a regular Homebrew cask. You can run betas through TestFlight, on the Mac too. And you can publish on the Mac App Store if you want to, where Apple handles payments and updates. The trade there is App Review, a required sandbox, and a commission on sales: 15% under the [Small Business Program](https://developer.apple.com/app-store/small-business-program/), for developers with up to $1 million in yearly proceeds, and 30% above that.

### iPhone apps

This is where the membership stops being optional. iPhone apps reach other people through the App Store, through TestFlight (up to 10,000 testers, each build lasts 90 days), or as Ad Hoc installs on up to 100 iPhones you register by hand each membership year. And apps you install on your own phone from Xcode keep working for a year instead of 7 days.

## The downsides of paying

The first one is obvious: $99 every year, for as long as you want to keep shipping.

Every release gets a notarization step. For NoteRepo 2.2, the upload and Apple's scan took less than a minute, but it's one more thing in the release script that can fail. The hardened runtime that notarization requires can also break apps that load unsigned plug-ins or generate code at runtime, until you add the right entitlements.

If you stop paying, your [App Store apps become unavailable](https://developer.apple.com/help/account/access/resolving-access-issues/) in every storefront, although copies already installed keep working. TestFlight and the notary service stop too. Developer ID apps fare better: [users can keep downloading and running](https://developer.apple.com/support/developer-id/) the versions you already notarized, you just can't notarize new ones.

Apple can also revoke a Developer ID certificate, and then every app signed with it stops launching, including copies people already installed.

Finally, your name goes on it. As an individual, the App Store shows your legal name as the seller. If you sell in the EU App Store as a trader, the Digital Services Act requires Apple to [show an address, a phone number and an email](https://developer.apple.com/help/app-store-connect/manage-compliance-information/manage-european-union-digital-services-act-trader-requirements) on your product page. An individual can use a P.O. box for the address.

## Outside the store, the membership still pays off

My Mac apps are staying on GitHub, with their own updater that checks the latest release once a day. I don't plan to put them on the Mac App Store.

The membership still changes things for them. They open without the malware warning now, and they can use iCloud and push notifications, keep their permissions across updates, and go into Homebrew. What I give up by staying out of the store is In-App Purchase, Game Center, Sign in with Apple, and the store's discovery, payments and automatic updates.

| | Free account | Apple Developer Program |
| --- | --- | --- |
| Ship a Mac app outside the store | Yes, ad-hoc signed | Yes, notarized |
| First launch for users | "Could not verify" warning | Normal "Open" dialog |
| Permissions after an update | Asked again | Kept |
| iCloud and push notifications | No | Yes, even outside the store |
| Official Homebrew cask | No | Yes |
| Your own iPhone | 7 days, then reinstall | A year |
| Other people's iPhones | No | App Store, TestFlight, Ad Hoc |
| Cost | Free | $99 a year |

The free account is enough when you're learning, building tools for yourself, or shipping free apps to developers who know where **Open Anyway** is. That was my case until now.

Pay when you want an iPhone app, when you need iCloud or push notifications, when your users aren't developers, or when you sell the app. For me it was the iPhone app with iCloud sync.
