iOS与TestFlight环境下已配置aps-environment权限仍出现ITMS-90078推送通知权限缺失问题求助
Hey there, let’s work through this—you’ve already checked a lot of the common boxes, so let’s dig into the less obvious things that might be blocking your pushes:
1. Confirm Your Build & Firebase Are Targeting the Production APNs Environment
TestFlight builds use the production APNs server, not the sandbox. Even if you have the right certificate, mismatched environments will break pushes:
- Open your
GoogleService-Info.plistand check theAPNS_ENVIRONMENTvalue—it should be set toproduction, notdevelopment. If it’s wrong, re-download the plist from Firebase Console (make sure you’ve selected the production APNS certificate there first). - When archiving for TestFlight, double-check the signing step: in Xcode’s archive distribution flow, ensure you’re using an App Store Distribution profile (not Development) and that the code signing environment is set to production. Sometimes auto-managed profiles can flip to development if you’ve been testing locally, so manually verify this during distribution.
2. Verify Notification Permissions Are Properly Requested & Granted
Just because you’re getting a device token doesn’t mean the user has granted notification permissions. Even if they allowed notifications initially, they might have toggled them off later:
- In your app’s code, make sure you’re explicitly requesting authorization with
UNUserNotificationCenter.current().requestAuthorization(options: [.alert, .badge, .sound])on app launch. - Ask your testers to check Settings > [Your App] > Notifications and confirm that alerts/badges/sounds are enabled, and that "Allow Notifications" is toggled on.
3. Validate Your Production APNS Certificate in Firebase
It’s easy to upload the right certificate but miss a key step in Firebase:
- Go to Firebase Console > Project Settings > Cloud Messaging > Apple app configuration.
- Under "APNs Authentication Key" or "APNs Certificate", ensure your production certificate is uploaded and selected. If you uploaded both development and production, make sure the production one is active (sometimes Firebase defaults to development if you uploaded it first).
- Also, confirm the certificate hasn’t expired—check its validity in Apple Developer > Certificates, Identifiers & Profiles > Certificates.
4. Test Pushes Directly via APNs (Bypass Firebase)
To rule out Firebase as the issue, send a test push directly using the production APNs server. You can use a curl command like this (replace placeholders with your details):
curl -v -d '{"aps":{"alert":"Test Push","sound":"default"}}' \ -H "apns-topic: com.your.bundle.id" \ -H "apns-push-type: alert" \ -H "apns-expiration: 0" \ --http2 \ --cert /path/to/your/production-cert.pem:cert-password \ https://api.push.apple.com/3/device/[TESTER_DEVICE_TOKEN]
If this push doesn’t arrive, the problem is with your APNs setup (certificate, device token, or profile). If it does arrive, then the issue is in Firebase’s configuration.
5. Check Xcode’s Build Settings for Entitlements
Even with auto-managed profiles, sometimes the entitlements file isn’t properly linked:
- In Xcode, go to your target > Build Settings > Code Signing Entitlements. Ensure this points to a valid entitlements file that includes the
aps-environmentkey with valueproduction. - You can also inspect the archived build to confirm the entitlement exists: right-click your archive > Show in Finder > Right-click .xcarchive > Show Package Contents > Products/Applications/[YourApp].app > Show Package Contents > Open
embedded.mobileprovisionin a text editor. Search foraps-environment—it should sayproduction.
6. Ensure Your Tester’s Device Token is for Production
Device tokens are environment-specific: a development token won’t work with production APNs, and vice versa. Since your testers are on TestFlight, their device tokens should be production tokens. Double-check that the tokens stored in your Firebase database were generated from a TestFlight build (not a local development build).
Start with these steps—most TestFlight push issues boil down to environment mismatches or overlooked permission/entitlement details. Let me know if any of these lead you to the fix!
内容的提问来源于stack exchange,提问作者Chris Whipple

