Publishing · Last verified 30 July 2026
Give Vunda access to your store accounts
You do not generate or send Vunda any keys. Once your app records exist, you invite two Vunda identities into your own App Store Connect and Google Play accounts - Apple as an Admin, Google scoped to just the app you created. There is no Google Cloud project for you to create, and you can remove our access at any time.
Your app is published under your own Apple and Google developer accounts, not Vunda's. So that we can build and upload it for you, you give us access to those accounts - by inviting us into them. You do not generate a key, and you do not send us a file.
There is nothing for you to create and email. No API key, no
.p8file, no JSON key, and no Google Cloud project. You invite two Vunda identities into your own accounts, we do our work inside them, and you can remove that access yourself at any time.
Create your app records before you do this
Do this only once both app records exist. The Publish page lists them in that order too: Create your App Store Connect record and Create your Google Play record first, then Give Vunda access to your stores. The two records are tracked as separate lines because having made one and not the other is the normal half-way state, and each records its own evidence.
The reason is on the Google side. A Play Console grant is either account-wide or limited to particular apps, and Google is explicit that "App permissions only apply to the selected app" - but the app has to exist before you can select it. Creating your Play record first is what turns this into a grant on one app rather than on your whole developer account. (Source: Add developer account users and manage permissions.)
Nothing stops you creating the records first. Vunda shows your iOS bundle ID and Android package name on the Publish page as copyable values, so you do not need us inside the account to get either record made. On the Apple side, register the bundle id under Certificates, Identifiers and Profiles in your Apple Developer account before you add the app in App Store Connect - App Store Connect only lets you pick an id that already exists. See Create your App Store Connect app record and Create your Google Play app record.
What you will need
- Your app record already created in each store (see the two guides linked above).
- Your Apple Developer Program account, signed in with a role that can invite users in App Store Connect (usually the Account Holder or an Admin).
- Your Google Play Console account, signed in as the account owner or an admin who can add users.
- The two Vunda identities to invite. They are shown on the Publish page in your Shopify admin, in the
Invite Vunda to your store accountsstep - labelledInvite this userfor Apple andGrant access to this service accountfor Google. Each one has a Copy button. Always use the addresses shown there - we will never ask you to invite a different one, and there is nothing to send back to us.
Step 1: invite Vunda in App Store Connect (Apple)
This step happens inside App Store Connect, not in Vunda, so the exact screens are owned by Apple. Verify against their current guide before you rely on it.
On the Publish page, copy the address labelled Invite this user. Then, in App Store Connect, open Users and Access and choose the add button. The New User form asks for more than an email, so here is what to put in each field (fields as shown on a live App Store Connect console on 2026-07-30):
- First Name / Last Name: these are just the label your team sees in the user list.
VundaandPublishingwork fine. - Email: the address you copied. It must match exactly.
- Roles: tick Admin only. Do not add Finance, Sales, Developer, App Manager, Customer Support, or Marketing.
- Additional Resources: tick Access to Certificates, Identifiers & Profiles if it is still selectable once Admin is chosen. Leave Access to Reports, the two cloud-managed certificate options, Create Apps, and Generate Individual API Keys unticked - none of them are needed for your builds.
Continuing shows a second page, App Access, which lists every app in your account and notes that Admin roles have access to all apps. That is Apple's model, not a choice you make on the form - it is the account-wide access the next section explains - so there is nothing to select there. Continue and send the invitation. Apple emails it to us, and once we accept it we can finish setting up your build from inside your account. (Sources: App Store Connect help, Roles and access.)
That access is what lets us create your App Store Connect API key - the credential that uploads your iOS builds - inside your own account, under your own team. You never create it, and you never send it to anyone. If you later remove our access, that key stops working, which is exactly the point.
Why Apple asks for Admin when Google does not
We scope our Google Play access to a single app, so it is fair to ask why Apple gets an account-wide role. The short answer is that Apple does not offer a narrower option that can still do the job, and the Publish page says so plainly: Apple requires Admin here: only Account Holder and Admin can create the team API key our build service needs, and Apple does not allow that key or signing-certificate access to be limited to a single app.
The longer answer, if you want to check it yourself:
- Generating API keys is an Account Holder and Admin permission in Apple's role matrix, not something a lower role can do. (Source: Roles and access.)
- There are two kinds of App Store Connect API key. A team key has "Access to all apps, with varying levels of access based on selected roles"; an individual key carries the "Access and roles of the associated user". (Source: fastlane - App Store Connect API.)
- Individual keys "aren't able to use Provisioning endpoints", and it is "highly recommended to create a Team Key, as it is required for any provisioning-related API access". Provisioning is exactly what our build service uses to register your bundle id and issue your certificates and profiles, so an app-scoped App Manager with an individual key would fail at credential setup. (Source: fastlane - App Store Connect API.) That does not make registering the bundle id yourself optional or pointless: doing it yourself is the faster path, because App Store Connect only offers you ids that already exist, so leaving it to us means your app record waits until we reach your credential setup.
- Access to Certificates, Identifiers and Profiles is granted per user in Users and Access, not per app, so signing access is account-wide for any role that has it. (Source: Roles and access.)
So the asymmetry is Apple's, not a shortcut of ours. You can still remove the access whenever you want, and doing so stops the key working immediately.
One Apple rule worth knowing
Apple limits who can generate app signing credentials, and the limit depends on whether your Apple Developer account is an individual or an organization account. From Expo, whose build service we use: "On individual Apple Developer accounts, only the Account Holder role can generate app signing credentials. On an organization Apple Developer account, the Account Holder and Admin roles can always generate app signing credentials, and the App Manager role can generate credentials when a user with this role has Access to Certificates, Identifiers, and Profiles enabled." (Source: Expo - Apple Developer Program roles and permissions.)
In practice: on an organization account, inviting us as an Admin is enough. On an individual account it is not, because only your Account Holder can generate the signing credentials. We will tell you if we hit that. It is a short step for you, not a rebuild.
Step 2: invite Vunda in Google Play Console (Android), scoped to your app
This step happens inside Google Play Console, not in Vunda, so the exact screens are owned by Google. Verify against their current guide before you rely on it.
On the Publish page, copy the address labelled Grant access to this service account. This is the Google Play service account in your publish checklist. Then, in Google Play Console, open Users and permissions and choose Invite new user. Here is what to do with each part of the invite form (fields as shown on a live Play Console on 2026-07-30):
- Email address: the address you copied. Google shows a warning about checking the identity of new users before inviting them - that warning is expected and correct, and this identity is Vunda's.
- Access expiry: leave
Set access expiry dateoff. An expiry would silently break your future releases on the day it lapses. - Permissions: stay on the App permissions tab and use Add an app to select your Vunda app. Do not use Account permissions.
- App access: on the app's permissions screen Google requires one base access level. Choose
View app information (read-only)- the smallest one, and all the visibility our uploads need. Never Admin: Google's own description says app Admins can invite and remove users on your developer account. - Under Releases, tick
Release apps to testing tracksandManage testing tracks and edit tester lists. Google's own descriptions of both end the same way: they do not allow publishing apps to production. Leave everything else unticked, includingRelease to production, financial data, store presence, and user feedback.
Play Console splits the grant across two tabs, and the one you choose is the whole point of this step. Google's guidance is to use the App permissions tab "to select permissions to apply to specific apps", and the Account permissions tab "to select permissions to apply to all apps in your developer account". Google revises these labels from time to time; if the form in front of you words them differently, pick the permissions that release to testing tracks, and nothing that releases to production. (Source: Add developer account users and manage permissions.)
Granted that way, our service account can put builds into your Vunda app and nothing else. It cannot see or touch your other apps, and it never has account-level permissions.
You do not need Google Cloud at all
This is the part merchants most often brace themselves for, and it is not yours to do. In the Publish page's own words: It is a Vunda-owned service account, so you need no Google Cloud project of your own.
- You do not create a Google Cloud project.
- You do not create a service account.
- You do not download, store, or send a JSON key.
You invite an address in Play Console, the same way you would add a colleague. Everything on the Google Cloud side is ours, and it stays ours. (Source: Expo - submit to Google Play.)
Step 3: confirm each platform, then watch it clear
After completing each console, press that platform's confirm button on the Publish page. Your confirmation records the handoff; it is not the verification itself. As the page's What happens next note explains, Vunda then accepts the Apple invitation, verifies both grants, and prepares your signing and upload credentials - usually within one business day - and nothing is built or published until that verification passes. If a check fails, the step reopens on the page with what to fix.
The Publish page tracks this inside the first step, so you do not have to guess whether the invites landed.
Give Vunda access to your storesstays marked as your action until Vunda has confirmed both invites, then it shows Done.Build identifiers generatedconfirms that Vunda derived your iOS bundle ID and Android package name from the linked Shopify store. It does not mean Vunda has access to Apple or Google.Create your App Store Connect recordbecomes Recorded when you enter your numeric Apple ID in the App identity section. That stores the number for the future upload; it is not an Apple verification.Create your Google Play recordbecomes Recorded when you tell us. There is no Google equivalent of the Apple ID for us to read before the first upload, so press theI have created my Google Play appbutton next to your Android package name once the record exists. We will not upload your Android build until you do.
The page distinguishes system facts (Done), saved details or confirmations (Recorded), and actions still owed (You), so it does not turn an assertion into a verified external state.
Once both invites are accepted, the rest of the store-account setup is on us.
You stay in control
- We never publish under our own accounts. Your app is listed by your business, in your accounts, and the store relationships and payouts are yours.
- You can remove our access whenever you want: Users and Access in App Store Connect, Users and permissions in Google Play Console. You do not need to ask us, and there is no key to rotate.
- If you do remove our access, tell us. Your next publish will fail until it is restored, and we would rather fix that before a release than during one.
If you were asked for keys before
An earlier version of this guide asked you to generate an App Store Connect API key and a Google Play service account key yourself and hand them to Vunda. That is no longer how it works, and there is nothing new for you to create. If you already sent us keys they keep working; the invite model replaces them from here on.
Next: with both records made and our access granted, enter your numeric Apple ID in the App identity section on the Publish page (see Configure your app identity), then follow Publish your app to the App Store and Google Play.