Skip to content
hideouts

Type to search every app and research write-up.

iOS Developer Toolkit (Swift)

iOSmacOSReleasedAuthorized use onlyNo shellPhysical-device testing in progress

The iPhone and iPad workbench, rebuilt as a native Mac app.

A native SwiftUI app and command-line tool for iPhones, iPads, and simulators: device details, readiness checks, live logs, location simulation, app installs, encrypted backups, packet capture, and hashed evidence cases, through macOS’s own device services.

Categories:Developer toolsForensics & evidenceDiagnostics

Topics:developer-toolsiosios-forensicsmacospacket-capture

Also available: iOS Developer Toolkit (Python). The original Python app, built on pymobiledevice3.

v1.0.0Requires macOS 14 or later, Apple silicon or Intel, Xcode for simulators and some developer featuresChangelogSource

Ad-hoc signed · not notarized · GitHub build attestation

SHA-256 checksums
  • iOS-Developer-Toolkit-Swift-1.0.0-macOS-universal.zip

    ec3662f1b7f3d2865522e390ac7a5b28b8928b0058bd422c3ee570963def6354

Check a download with shasum -a 256 iOS-Developer-Toolkit-Swift-1.0.0-macOS-universal.zip and compare the result. Full verification guide

Screenshots

Select an image to view full size

  • Overview

    Overview

  • Readiness Check

    Readiness Check

  • Device

    Device

  • Live Logs

    Live Logs

  • Location Lab

    Location Lab

  • Actions

    Actions

  • Apps

    Apps

  • Backup

    Backup

Downloads · v1.0.0

Release notes

Verify after downloading: shasum -a 256 iOS-Developer-Toolkit-Swift-1.0.0-macOS-universal.zip · How to verify a download

On this page

A native macOS app for working with iPhones, iPads, and simulators — device information, live logs, location simulation, app installs, backups, packet capture, readiness checks, and documented evidence collection.

Overview

iOS Developer Toolkit is written in Swift and SwiftUI. It talks to devices through macOS's own device service (usbmuxd and lockdown), Xcode's CoreDevice service (devicectl), simctl, and Instruments. It needs no Python, no Homebrew packages, and no administrator rights.

Scope. This is a tool for devices you own or are authorized to examine. It does not jailbreak iOS, bypass a passcode, disable the sandbox, defeat code signing, decrypt protected traffic, or provide unrestricted file-system access.

AreaWhat you get
DevicesAutomatic discovery of USB and Wi-Fi–synced devices (event-driven, no polling), Xcode-paired network devices, and simulators — shown in separate Physical Devices and Simulators sections.
Plain-language device detailsName, model, hardware identifier, UDID, iOS version and build, architecture, connection, trust, Developer Mode, and developer-service status, each with an explanation. Identifying values stay hidden until you choose to show them.
Readiness CheckA read-only check of every prerequisite (Xcode, the macOS device service, connection, trust, Developer Mode, Xcode's device service, developer services, Instruments, lock state, logging and backup services, Safari Web Inspector) with a next step for anything not ready.
Live LogsUnified Logging and classic syslog streamed from physical devices, and the simulator's unified log; plus two collected sources: an OSLog archive (the device's saved log history for a time window, kept as a .logarchive for Console) and DVT logging (os_log recorded through Instruments, kept as a .trace). Every byte is spooled and hashed; the view can be paused and filtered (literal or regex) without affecting capture. Mark findings, then export the raw capture, filtered lines, or an evidence bundle.
Location LabSet a coordinate (offline world map, map-link parsing, nudges, saved places), move along a route at constant speed, or replay a GPX track. Always clearable; every change is logged.
FirmwareApple's firmware (IPSW) for the connected model with whether Apple still signs it; download with resume and SHA-1 verification; a local IPSW library; recovery and DFU mode; and Update (keeps data) or Restore (erases) with the bundled idevicerestore, after a check that changes nothing.
AppsSearch and sort installed apps (with sizes over USB), launch, and remove with confirmation.
Install AppInspect an .ipa on the Mac first — contents, provisioning profile, and code signature verified with Security.framework — then install it on a device, or install an .app on a simulator.
ActionsOver 40 guided actions (diagnostics, battery, IORegistry, provisioning and configuration profiles, crash reports, screenshots, sysdiagnose, Instruments recordings, packet capture, Bluetooth capture, Safari and web view tabs, network discovery, launch, open URL, simulated location, restart, simulator controls), each showing its risk, what it needs, and exactly how it runs. An Advanced Mode runs devicectl subcommands bound to the selected device.
BackupEncrypted local backups with the same protocol Finder uses, full or incremental, with progress. Turn on backup encryption with a new password (never stored or logged).
Evidence CaptureA documented case folder with snapshots, optional timed streams (Unified Logs, syslog, packet capture), a screenshot, and crash reports, plus a manifest and SHA-256 hashes. Failed steps are recorded as coverage gaps.
Packet captureDevice-side network packets written as a standard .pcap file for Wireshark or tcpdump, as an action or as part of Evidence Capture.
External toolsOptional handoffs to separately installed MVT, UFADE, and idb Companion, validated by path and SHA-256.
Session ActivityEverything run in this session, with exportable manifests (output hashes, never raw output).
Tool ReferenceThe exact help text of the installed devicectl, simctl, and xctrace, and a Toolchain Check that confirms every command the app relies on exists in your Xcode.

The demo screenshots use the built-in Demo Mode (a clearly labelled simulated iPhone) or a real iOS simulator. They contain no real device data.

Readiness CheckDevice details (simulator)
Readiness CheckDevice
Live Logs (simulator)Location Lab
Live LogsLocation Lab
ActionsApps
ActionsApps
BackupEvidence Capture
BackupEvidence Capture

More: Install App · External Tools · Scope & Safety

macOSmacOS 14 Sonoma or later.
MacApple silicon or Intel (universal binary). Tested on Apple silicon.
DevicesiPhone and iPad (iOS/iPadOS). Developer-service features on physical devices need iOS 17 or later through Xcode's device service; iOS 16 and earlier are supported for identity, logs, backups, diagnostics, and apps.
SimulatorsAny iOS simulator installed with Xcode.
ConnectionA data-capable USB cable, or Wi-Fi sync / Xcode network pairing after first pairing over USB.
XcodeOptional — see below.

Many features use only macOS's built-in device service and work on a Mac without Xcode. Features that use Xcode's developer tools need Xcode installed (open it once to finish setup):

Works without XcodeNeeds Xcode
Device discovery (USB and Wi-Fi sync), identity, trust, Developer Mode statusSimulators (everything in the Simulators section)
Live Logs from physical devices (Unified and classic syslog)Location simulation on iOS 17 and later
Packet capture; Bluetooth capture (with Apple's logging profile); Safari and web view tab listing (with Web Inspector on); checking the developer image, and mounting it over USB from an image Xcode installed or a folder you choose (Developer images)Xcode's device service (devicectl) route for the developer image
Encrypted backups and encryption setupScreenshots, launch app, open URL, stop a process
Diagnostics, battery, IORegistry, MobileGestalt, running processes, configuration profilesLock state, displays
Installed apps (with sizes), removing apps, installing .ipa packagesSysdiagnose and Instruments recordings
Provisioning profiles, crash reports, Media folder listingRestart device, Advanced Mode (devicectl), Tool Reference
IPA inspection, Evidence Capture (without the Xcode-only steps)Readiness rows for Xcode's device service and Instruments

The Command Line Tools alone are not enough for the Xcode column: devicectl, simctl, and xctrace ship with Xcode.app.

  1. Download iOS-Developer-Toolkit-Swift-VERSION-macOS-universal.zip and SHA256SUMS.txt from the latest release.

  2. Verify the download:

    Terminal
    shasum -a 256 -c SHA256SUMS.txt --ignore-missing

    Optionally verify GitHub's build attestation:

    Terminal
    gh attestation verify iOS-Developer-Toolkit-Swift-VERSION-macOS-universal.zip --repo hideouts-io/iOS-Developer-Toolkit-Swift
  3. Unzip it and move iOS Developer Toolkit (Swift).app to /Applications.

  4. Release builds are ad-hoc signed and not notarized, so macOS asks for confirmation the first time. Control-click the app, choose Open, and confirm. If there is no Open button, go to System Settings › Privacy & Security and choose Open Anyway. Do not disable Gatekeeper.

Nothing else needs to be installed. The release also contains idt, the command-line tool, at iOS Developer Toolkit (Swift).app/Contents/MacOS/idt.

See Build from source.

  1. Connect and trust. Connect the iPhone or iPad with a USB cable, unlock it, and tap Trust. Enter the passcode on the device — never in this app.
  2. Choose the target. Use the device menu at the left of the toolbar. Physical devices and simulators are listed separately, and every page shows which one it acts on.
  3. Run the Readiness Check. It tells you exactly what works and what to fix next.
  4. Turn on Developer Mode if needed (iOS 16+): Settings › Privacy & Security › Developer Mode, then restart and confirm. Device › Developer Mode Guide walks through it.
  5. Mount the developer image for screenshots, location simulation, and launching apps: the Developer Image page (in the sidebar, under Device) shows its state; click Mount Developer Image. See Developer images.
  6. Clean up when finished: stop streams and clear simulated locations. Quitting the app clears a location this session simulated.

No device handy? Turn on Device › Demo Mode to explore every workspace with a simulated iPhone.

  • Overview — status of the selected device, a suggested next step, and entry points.
  • Device — identity and status with explanations, a summary of the developer image, Apple developer tool handoffs (open a project in Xcode, open an .xcresult or .trace, list Remote Virtual Interfaces), simulator controls, raw records, and connection diagnostics.
  • Developer Image — the developer image on the selected device (state, details, mount, unmount), how to mount it (automatic, Xcode's device service, or the built-in client), the images on this Mac and folders you add, and what is mounted on the device.
  • Firmware — the device and its mode (normal, recovery, or DFU), Apple's firmware for it and its signing status, downloads, the IPSW library (add, check signing, verify, show in Finder, move to the Trash), and installation.
  • Readiness Check — the read-only prerequisite check, a copyable report, and a local history of tested devices that can be exported as sanitized JSON or Markdown.
  • Apps — installed apps with search, sort, sizes, launch, and confirmed removal.
  • Install App — inspect an .ipa (or choose a simulator .app), see whether the device is in the provisioning profile, then install.
  • Location Lab — coordinates, map, saved places (stored only on this Mac), routes, GPX playback. Location events are appended to ~/Documents/iOS Developer Toolkit (Swift) Location Logs/location-events.jsonl.
  • Live Logs — several concurrent streams; pop out any stream into its own window.
  • Actions — the guided action catalog and Advanced Mode.
  • Backup — encryption status and setup, full or incremental backups.
  • Evidence Capture — optional guided case intake (title, purpose, authorization), collection, and a summary of every step.
  • External Tools — MVT, UFADE, and idb Companion.
  • Session Activity, Tool Reference, Scope & Safety — history, built-in tool help, and the app's boundaries.

Press ⌘K for the command palette, ⌘R to refresh devices, ⇧⌘R to run the Readiness Check, ⌘1–⌘9 to switch workspaces, and ⌥⌘← / ⌥⌘→ for the previous or next workspace. Help › Keyboard Shortcuts (⌘/) lists them all.

RiskExampleConfirmation
Read-onlyBattery snapshot, lock stateRuns immediately
Saves files on this MacScreenshot, crash reports, backupReview sheet; files are never overwritten
Changes the deviceLaunch app, set location, installType RUN plus the last six characters of the device's UDID
High impactRestart device, remove an app, erase a simulatorAlso confirm a current backup and type IRREVERSIBLE plus the same code

Because the code comes from the target's UDID, a confirmation can never apply to a different device. Each operation also captures its target when it starts, and lockdown sessions verify that the device answering is the one you selected.

Screenshots, location simulation, launching apps, and Instruments need Apple's developer image (Developer Disk Image) mounted on the device. The Developer Image page (sidebar, under Device) checks it automatically and shows one of these states; the Device page shows a summary:

Developer image card

StateMeaning
MountedA compatible image is mounted. Nothing is mounted again.
AvailableA compatible image is on this Mac and can be mounted now (the device already holds Apple's personalization for it, or it is an iOS 16-or-earlier image).
Personalization requiredA compatible image is on this Mac; Apple must sign it for this device first (iOS 17 and later, needs the internet).
MissingNo compatible image is on this Mac.
IncompatibleThe image on this Mac (or the one mounted) does not fit this device or iOS version.
Needs attentionTrust, Developer Mode, unlocking, or a USB connection is needed first.
FailedThe check or the last mount attempt failed; the card shows why and what to do.
Not requiredSimulators and the demo device.

The details list the iOS version and build, model, architecture, chip and board used to choose the image, where it is mounted, and which image on this Mac would be used.

iOS 17 and later use a personalized image. Xcode installs it in /Library/Developer/DeveloperDiskImages/iOS_DDI. Mounting picks the build identity for the device's chip and board and, unless the device already holds a personalization for that image, asks Apple's signing server (gs.apple.com) for one — sending the device's chip, board, and ECID with a one-time nonce, exactly as Xcode does. The confirmation says so before anything is sent.

iOS 16 and earlier use DeveloperDiskImage.dmg and its .signature for the exact iOS major.minor version. Current Xcode versions no longer include them; add a folder that contains them (for example an older Xcode's Platforms/iPhoneOS.platform/DeviceSupport/16.4) with Add Image Folder… on the Developer Image page.

How it mounts (Developer Image › How to mount): Automatic uses Xcode's device service (devicectl) when it can reach the device on iOS 17 and later, and otherwise the built-in client, which talks to the device's image-mounter service over USB and works without Xcode's device service. The app never downloads images from third parties.

The Firmware page (sidebar, under Device) installs iPhone and iPad firmware (IPSW files) the way Finder does, using idevicerestore and irecovery from the libimobiledevice project, bundled with the app as separate programs (see THIRD_PARTY_NOTICES.md).

  • Device and mode. The selected iPhone or iPad, or a device in recovery or DFU mode (found every few seconds while the page is open). Enter Recovery Mode and Exit Recovery Mode, and step-by-step DFU instructions.
  • Apple's firmware. Apple's firmware list (itunes.apple.com/check/version, the one Finder uses) gives the current firmware for the model, with Apple's SHA-1. Check Signing asks Apple's signing server whether it still signs that build — reading only the build manifest from Apple's server, and sending a random device ID, never the device's. Download saves the IPSW to the library, continues an interrupted download where it stopped, and keeps the file only if its SHA-1 matches Apple's.
  • Library. IPSW files in ~/Library/Application Support/iOS Developer Toolkit (Swift)/Firmware. Add your own, check signing, verify (SHA-1 and SHA-256), show in Finder, or move to the Trash.
  • Install. Choose an IPSW and Update (keeps apps and data) or Restore (erases the device). Check Before Installing confirms the firmware is for this model, has the right install type, is signed by Apple, and that the installer finds the device — without changing anything. Update needs the typed RUN confirmation; Restore is high impact. Progress is shown step by step; Stop works until the system starts being written, after which the install always finishes, since stopping then would leave the device unusable. Logs are kept in the library's Logs folder.

During an install, Apple's signing server receives the device's chip, board, and ECID to sign the firmware for it, as with Finder. Firmware that Apple no longer signs cannot be installed. The app does not offer jailbreak-style exploits or downgrades.

idt provides the automation-friendly parts of the app:

Terminal
idt devices --simulators                      # list devices and simulators
idt readiness --udid <UDID>                   # read-only readiness check
idt inspect-ipa App.ipa [--json]              # inspect a package
idt collect --udid <UDID> --output-root ~/Cases --duration 120 --include-unified-logs
idt ddi status --udid <UDID> [--json]         # developer image state (exit 0 mounted, 2 mountable)
idt ddi mount --udid <UDID> --confirm "RUN ABC123" [--mechanism automatic|core-device|native]
idt ddi unmount --udid <UDID> --confirm "RUN ABC123"
idt toolchain                                 # check the installed Xcode

--include-oslog-archive adds the device's saved Unified Log history for the last hour (log collect); --include-dvt-logs records os_log through Instruments (DVT) for the stream duration. --include-oslog, the 0.3.x flag for the DVT OSLog stream, is still accepted and selects DVT logging.

idt collect exits with 0 when complete, 2 when finished with coverage gaps, and 1 when the device could not be identified.

  • Least privilege. No administrator rights and no sudo. The app never reads /var/db/lockdown, never creates pairing records, and never restarts system services. Pairing material is requested from macOS's device service and kept only in memory.
  • Verified connections. Lockdown sessions use TLS with this Mac's pairing certificate, pin the device certificate from the pairing record, and confirm the device's UDID before any request.
  • No shell. External tools run from fixed paths with an argument vector and a minimal environment; nothing is interpreted by a shell. All process launches go through one audited runner with timeouts and cancellation.
  • Untrusted input. Device responses, backup file paths, IPA archives, GPX files, and workspace profiles are validated; path traversal, symbolic links, encrypted or oversized archive entries, and XML entities are rejected.
  • Local only. Nothing is uploaded, with one confirmed exception: mounting a developer image on iOS 17 and later asks Apple's signing server (gs.apple.com) to personalize it, sending the device's chip, board, and ECID with a one-time nonce — as Xcode does. Installing firmware sends the same kind of request, as Finder does; checking whether Apple signs a firmware uses a random device ID. The Firmware page reads Apple's firmware list and downloads IPSWs from Apple. Captures, backups, cases, and reports are written with owner-only permissions. The app's own log records outcomes rather than device content, and marks identifiers as private.
  • Sanitized sharing. iOS Developer Toolkit › Create Support Bundle… and the readiness report exports remove names, identifiers, paths, and addresses. Review them before sharing.
  • Hardened runtime, no App Sandbox: the app must reach the system's device service socket and run Xcode's tools. See SECURITY.md to report a vulnerability.
ProblemTry this
The device does not appearUse a data cable, unlock the device, tap Trust, try another port, and check Connection diagnostics on the Device page. If nothing appears after reconnecting, restart the Mac.
“This device has not trusted this Mac”Unlock the device and reconnect it; tap Trust. If no prompt appears, reset Settings › General › Transfer or Reset › Reset › Reset Location & Privacy.
Developer Mode is missing on the deviceConnect it and open Xcode › Window › Devices and Simulators once.
Developer features say they need XcodeInstall Xcode, open it once, and check Xcode › Settings › Locations › Command Line Tools.
The developer image will not mountRead the Developer Image page: it names the problem (Developer Mode, lock, missing or incompatible image) and the fix. On iOS 17 and later keep the Mac online (Apple personalizes the image); if one route fails, switch How to mount on the Developer Image page.
A backup stops with “must stay unlocked”Unlock the device and keep it awake until the backup finishes.
Firmware will not installRun Check Before Installing on the Firmware page. Apple must still sign the firmware; keep the device connected by USB and the Mac online. If the device is left in recovery mode, install again with Restore. The log is in the library's Logs folder.
An .ipa cannot be installedCheck the inspection: the signature must be valid and the profile must include the device.
Live logs are very busyFilter the view or pause it; capture continues in the background.
Something elseRun the Readiness Check, then create a support bundle and open a discussion.

More detail: docs/troubleshooting.md.

Requirements: macOS 14+, Xcode 16 or later (Swift 6).

Terminal
git clone https://github.com/hideouts-io/iOS-Developer-Toolkit-Swift.git
cd iOS-Developer-Toolkit

swift test                                    # unit and integration tests
swift build -c release --product idt          # the command-line tool

xcodebuild -project iOSDeveloperToolkit.xcodeproj -scheme iOSDeveloperToolkit \
  -configuration Release -destination 'platform=macOS' build

scripts/build-release.sh                      # universal, ad-hoc-signed release ZIP, SBOM, checksums in build-output/release/

The release includes the firmware helpers, which scripts/build-release.sh builds with scripts/build-restore-helpers.sh from pinned sources. That needs brew install autoconf automake libtool pkg-config cmake. To try the Firmware page from a development build, build the helpers once and point the app at them:

Terminal
scripts/build-restore-helpers.sh
open --env IDT_RESTORE_HELPERS="$PWD/build-output/restore-helpers/out/bin" "iOS Developer Toolkit (Swift).app"

The app icon and logo come from one image, docs/brand/logo-source.png: xcrun swift scripts/generate-icons.swift writes the app icon at every size, the in-app logo, and docs/brand/ (icon-1024.png, iOSDeveloperToolkitSwift.icns, logo-1024.png, logo-512.png, logo.svg, and the repository's social-preview.png).

The Xcode project is generated from project.yml with XcodeGen and committed, so you only need XcodeGen when you change the project structure (xcodegen generate).

Optional test suites:

Terminal
IDT_SIMULATOR_TESTS=1 swift test --filter RealSimulator   # boots a simulator end to end
IDT_NETWORK_TESTS=1 IDT_RESTORE_HELPERS="$PWD/build-output/restore-helpers/out/bin" \
  swift test --filter RealFirmware                        # Apple's firmware list, signing, the helpers
xcodebuild -project iOSDeveloperToolkit.xcodeproj -scheme iOSDeveloperToolkit \
  -destination 'platform=macOS' test                      # UI tests (macOS asks to allow automation)

Documentation screenshots are produced by the app itself:

Terminal
"iOS Developer Toolkit (Swift).app/Contents/MacOS/iOS Developer Toolkit (Swift)" \
  -demo-mode YES -populate-demo YES -window-size 1180x700 -capture-screenshots ~/Desktop/shots

Layout: Sources/ToolkitCore (process runner, errors, logging, secure files), Sources/DeviceKit (usbmuxd, lockdown and its services, CoreDevice, simctl, discovery), Sources/ToolkitFeatures (Location Lab, IPA inspection, logs, actions, readiness, evidence, external tools), Sources/idt (CLI), App/ (SwiftUI app and UI tests), Tests/. See docs/architecture.md.

Version 1.0 is a native rewrite of the Python/PySide6 app (iOS Developer Toolkit, 0.3.x), which depends on pymobiledevice3. See MIGRATION.md for the feature-by-feature mapping. Workspace profiles exported by 0.3.x can be imported in Settings › Profiles; the preview explains how each setting carries over.

Firmware installation (Update, Restore, recovery and DFU mode) has been tested against Apple's servers and with the bundled helpers, but not yet by installing firmware on a device; see MIGRATION.md.

The Python/PySide6 app, iOS Developer Toolkit, is maintained separately in hideouts-io/iOS-Developer-Toolkit, with its releases. It uses pymobiledevice3 and Python; this app needs neither. The two install side by side and keep their data in separate folders, and this app imports workspace profiles exported by the Python app.

  • The native lockdown services (logs, packet capture, backup, diagnostics, app installation over USB, developer-image checking and mounting including Apple personalization) are tested end to end against a protocol-accurate simulated device and against macOS's real device service. Their read-only protocol layer has been checked on one iPhone (iOS 26, Developer Mode off); mounting, location, installation, backup, and the app's pages have not yet been tested on physical iPhones or iPads. Please report results using the physical-device test protocol.
  • Not available in 1.0: the developer-service file listing. Details and alternatives are in MIGRATION.md.
  • Release builds are ad-hoc signed and not notarized.
  • Release builds are universal (Apple silicon and Intel). If the Intel half is run under Rosetta on an Apple silicon Mac, macOS warns that the app includes a component that will not open in macOS 28; the Apple silicon half, which runs by default, is not affected.

iOS Developer Toolkit is released under the MIT License. The bundled world map uses public-domain Natural Earth data. iPhone, iPad, Xcode, and macOS are trademarks of Apple Inc.; this project is not affiliated with Apple.

Related apps