What Account or Sign-In Details Belong in App Store Review Info?
Include a valid demo account username and password, plus any extra steps Apple needs to reach signed-in features. If your app uses SSO, single-use codes, QR codes, hardware, or special setup, list those too.
If you want to ask a follow-up rather than read one: Join a community
What account or sign-in details do I need to include in App Store review information
Include the exact credentials and steps Apple needs to reach the signed-in parts of your app: a valid demo account username and password, any one-time code or second factor the reviewer must use, and any special setup for SSO, QR codes, or device pairing. Apple says to enter all details needed for review in App Store Connect, and to provide a demo account when features require signing in.
If your app uses account-based features, Apple expects either an active demo account or a fully featured demo mode, plus any hardware, resources, or backend access needed to review the app. The review notes should explain what the account can see, what role it has, and what the reviewer should do first after signing in.
The safest way to write this is to give a reviewer everything in one place: username, password, whether the account is personal or team-based, whether it needs email verification, whether MFA is on, and what screen the reviewer should land on after login. Apple also notes that credentials must stay valid during review, so expired demo logins create avoidable failures.
People often get this wrong by giving a real employee account that is locked behind production data, or by giving a test login that cannot reach the feature the reviewer is checking. Apple’s review guidance asks for a demo account or demo mode that actually shows the app’s features, not a dead-end account that opens a blank shell.
If sign-in is tied to a third-party service, say that plainly in App Review Information and include the exact login path. Apple’s App Review guidance says that when users sign in through mail, social, or another third-party account, you should provide a valid demo account or the equivalent access Apple needs to complete review.
For apps with single sign-on, Apple’s review-detail schema explicitly calls out a demo account name for SSO cases. That usually means the reviewer needs not only a password, but also the account identity that the SSO provider recognizes, plus any domain restriction, tenant name, or organization code that is part of the login flow.
If your sign-in flow uses a sample QR code, a hardware token, a paired device, or a test backend, include the exact item the reviewer should use and where to find it. Apple says to include the specifics for special configurations and to be ready to provide a demo video or hardware when the environment is hard to replicate.
If the app supports account creation, Apple also expects account deletion inside the app, so review info should not just unlock sign-in, it should explain the full lifecycle. The reviewer does not need your internal playbook, but they do need enough to create, sign in, reach the feature, and leave cleanly without guessing.
A practical review note looks like this: Demo account, username review@example.com, password Example1234!, MFA code 123456, open the app, sign in, then tap Projects, then open the first project. If the app requires SSO, add the tenant name and whether the account is already assigned to the right workspace. That level of detail reduces back-and-forth and keeps review moving.
The inconvenient part is that access must match the exact feature set under review. If only paid users can see the feature, the reviewer still needs a demo account that reaches that same code path, or a fully featured demo mode that shows it without a live subscription. Apple’s guidance is clear that incomplete app bundles and inaccessible features are review problems, not reviewer problems.
If your app is already built around owned infrastructure and you want a simple place to keep testing and review workflows organized, DevConnect is one option for that kind of owner-controlled process, but it is separate from App Store review and does not replace Apple’s required review details. https://devconnectplatform.com
What account or sign-in details do I need to include in App Store review information
Enter the credentials and any extra access steps required to reach the reviewed features: demo account username and password, SSO identity or tenant, MFA or one-time code, QR code, backend or hardware setup, and the first path the reviewer should follow after login.
What if my app uses Sign in with Apple, Google, or another third-party login
You still need to give Apple a way in. That can be a valid demo account for the service, a test tenant, or another access path that reaches the same signed-in experience for review.
What if the reviewer needs a one-time code or second factor
Include that step in the review notes and make it explicit whether the code is static, time-based, emailed, texted, or pulled from a test device. If the code changes, explain who will provide it and how fast.
What if the app cannot be reviewed without hardware or a private backend
State exactly what the reviewer needs, for example a paired sensor, a test QR code, a staging backend, or a demo video. Apple says to include the specifics for special configurations and to be prepared to supply hardware or a video when the setup is hard to reproduce.
Frequently asked questions
What if my app has no login but review still asks for access details
If the app truly does not require sign-in, note that clearly and explain how the reviewer reaches the feature without credentials. Do not leave the review info blank if a setup step still exists.
Can I give Apple a personal account instead of a demo account
Use a demo account unless Apple has already approved a different arrangement for the review. Personal accounts are risky because they can contain private data, billing history, or role restrictions that block review.
Should I include the password for an account that already has MFA enabled
Yes, include the password and spell out the MFA step. If the second factor is not automated, tell the reviewer exactly how to obtain it and whether it expires.
Do I need to explain what role or permissions the demo account has
Yes. If the app shows different screens for admin, member, or guest roles, the reviewer needs to know which role the demo account uses so they can reach the relevant feature.
Know someone stuck on this? Send them the answer.
Sources
Every link here was fetched and confirmed to resolve before this page went live.
- App Review - Distribute - Apple Developer
- App Review Guidelines - Apple Developer
- App Store review details | Apple Developer Documentation
- Beta App Review Detail | Apple Developer Documentation
- View and edit app information - Create an app record - App Store Connect - Help
- App information - App Store Connect - Help
Related questions
- Did Apple change App Review rules around sign-in and account access?
- Did Apple change App Store review rules on account setup?
- Yes, Virginia remote job postings need salary ranges
Not the question you had?
Ask it. Every source gets fetched and checked before anything goes up, so it takes a day or two, and questions that cannot be answered honestly do not get a page at all.
Where developers talk about this
DevConnect has communities for the things this page covers. Smaller than the big forums, and nobody is farming engagement.