Install Dopamine
Sideloading = installing an .ipa without the App Store, by re-signing
it with a code-signing identity the device trusts. A free Apple Account signs
for 7 days (re-install when it expires); TrollStore
signs permanently but only exists on older exploitable versions (roughly iOS
14.0 - 16.6.1), so on iOS 17 you’ll use one of the free-Apple-Account tools below.
Prerequisites: you’ve confirmed your device qualifies (Step 0 on the iOS overview) and downloaded the right file (
.ipaor.tipa, see Download Dopamine).
Pick ONE installer, then expand its box below and follow it top to bottom. Each box is fully self-contained (its own Step 0 β last step) - you only need the one you pick.
| Use this | If you⦠| Needs a computer? |
|---|---|---|
| Sideloadly | just want the simplest one-shot install | Yes (Mac/PC), only at install time |
| AltStore | want the signature auto-refreshed | Yes, running on the same Wi-Fi |
| SideStore | want no computer after first setup | Only for first pairing |
| TrollStore | already have it (β€ iOS 16.6.1) β permanent, no 7-day expiry | No |
Provisioning profile / cert (zsign / applesign) | already have (or can make) a dev cert and want a headless/scriptable path | Yes (CLI) |
Sideloadly - simplest one-shot (Mac/PC)
Needs a Mac/PC only at install time (sideloadly.io).
- Confirm the device qualifies (Step 0 on the overview): a recent iPhone must be on iOS β€ 17.3.1. If not, stop - Dopamine can’t jailbreak it.
- Have
Dopamine.ipaon the computer (from Download Dopamine). - Make a throwaway Apple Account at account.apple.com - do not use your real one.
- On the computer, download + install Sideloadly, then open it.
- Connect the iPhone by USB. Sideloadly shows it at the top; on the phone tap Trust This Computer if asked.
- Drag
Dopamine.ipaonto the Sideloadly window (or click the app-file box and select it). - In Apple account, enter your throwaway Apple Account, then click Start; enter the password (and an app-specific password if 2FA prompts).
- Wait for Sideloadly to report Done - Dopamine is now on the Home screen.
- On the phone: Settings β General β VPN & Device Management β tap your Apple-Account developer app β Trust.
- Open Dopamine to confirm it launches, then go to Run the jailbreak.
- When the 7-day signature expires, just repeat steps 4-8 to re-install.
AltStore / AltServer - auto-refreshing (computer on same Wi-Fi)
Auto-refreshes the signature (altstore.io); a computer must stay on the same Wi-Fi.
- Confirm the device qualifies (Step 0 on the overview): iOS β€ 17.3.1 on a recent iPhone.
- Have
Dopamine.ipaavailable (from Download Dopamine). - Make a throwaway Apple Account at account.apple.com (not your real one).
- On the computer, install AltServer and run it (macOS Mail plug-in or the standalone app).
- Connect the phone by USB; tap Trust This Computer on the phone if asked.
- From AltServer’s menu-bar/tray icon β Install AltStore β pick your device; sign in with the throwaway Apple Account. This puts the AltStore app on the phone.
- On the phone: Settings β General β VPN & Device Management β trust your Apple-Account developer app.
- Get
Dopamine.ipaonto the phone (AirDrop it, or save it into the Files app). - Open AltStore β My Apps β β+β (top-left) β select
Dopamine.ipa. AltStore signs + installs it - Dopamine appears on the Home screen. - Keep AltServer running on the same Wi-Fi so it auto-refreshes the 7-day signature.
- Open Dopamine to confirm it launches, then go to Run the jailbreak.
SideStore - no computer after setup
On-device signature renewal (sidestore.io); a computer is only needed for first pairing.
- Confirm the device qualifies (Step 0 on the overview): iOS β€ 17.3.1 on a recent iPhone.
- Have
Dopamine.ipaready (from Download Dopamine). - Make a throwaway Apple Account at account.apple.com.
- Do SideStore’s one-time pairing from a computer following the official installer on its site (installs SideStore + a pairing file), signing in with the throwaway Apple Account.
- On the phone, when prompted, enable the SideStore VPN/loopback (this is how it re-signs on-device) and trust the profile under Settings β General β VPN & Device Management if asked.
- Get
Dopamine.ipaonto the phone (AirDrop or the Files app). - Open SideStore β My Apps β β+β β select
Dopamine.ipaβ install. - Wait for it to finish - Dopamine is on the Home screen; SideStore renews the signature on-device afterward.
- Open Dopamine to confirm it launches, then go to Run the jailbreak.
TrollStore - permanent, no 7-day expiry (β€ iOS 16.6.1 only)
What it is: TrollStore is not a jailbreak - it’s a utility that
permanently signs and installs .tipa apps using a CoreTrust signing bug, so
an app you install through it never expires and needs no computer and no
Apple Account afterward. That’s why it’s the nicest way to install Dopamine.tipa
if your device supports it.
The catch - how you “get” TrollStore: you don’t just download-and-sideload TrollStore itself; you run a small installer app once, which then installs TrollStore onto the device:
- TrollInstallerX - the main installer; you sideload it (via Sideloadly/AltStore, so a computer once), open it, and tap Install TrollStore.
- TrollHelperOTA - a no-computer route on older iOS (β 14.0 - 15.6.1).
Supported iOS: roughly iOS 14.0 - 16.6.1 (arm64 & arm64e). Not supported on 16.7.x (except 16.7 RC) or 17.0.1+ - if you’re on iOS 17, use Sideloadly / AltStore / SideStore above instead. Follow the exact device/version route in the community guide: https://ios.cfw.guide/installing-trollstore/.
Steps:
- Confirm this applies: device on iOS 14.0 - 16.6.1 (see the guide’s table for your exact chip/version). On iOS 17 β use another installer above.
- Get TrollStore onto the device (one time): install TrollInstallerX (sideload it with Sideloadly/AltStore, enable Developer Mode on iOS 16+ if asked, open it, tap Install TrollStore, and pick a persistence-helper app like Tips when prompted) - or use TrollHelperOTA on older iOS. Full per-device steps: https://ios.cfw.guide/installing-trollstore/.
- On the Download Dopamine page, grab
Dopamine.tipa(the TrollStore package), not the.ipa. - Get
Dopamine.tipaonto the phone (AirDrop, or save it into the Files app). - Open TrollStore β β+β β select
Dopamine.tipaβ Install. - Done - the signature is permanent: no Apple Account, no 7-day expiry, no trust step.
- Open Dopamine to confirm it launches, then go to Run the jailbreak.
Provisioning profile / signing cert (CLI)
Sign the .ipa yourself and install it headlessly - no GUI installer. This is the
right route if you have (or can make) an Apple Development signing identity. It
needs two things most guides gloss over: a signing certificate + private key
(the “identity”) and a provisioning profile (.mobileprovision) that includes
your device’s UDID and grants get-task-allow. The steps below show how to
obtain both from scratch, then sign with either signer.
β‘ Quick path (copy/paste) - the known-good sequence
If you already have an Apple Development identity in your keychain (check with
security find-identity -v -p codesigning) and Xcode has downloaded your provisioning profiles, this is the entire working flow, start to finish. Run it from the folder containingDopamine.ipa, with the iPhone plugged in and trusted. The numbered sections below explain each piece if a step needs adjusting.The four things a first-timer gets wrong - and this sequence gets right:
-a(--all) re-signs Dopamine’s nested frameworks (e.g.badRecovery.framework). Without it the install dies with0xe800801c (No code signature found)on a framework. This is mandatory.-b "$BUNDLE_ID"signs the app as the profile’s App ID (e.g.com.dvma), not Dopamine’s owncom.opa334.Dopamine. Skip it and you get0xe8008015 (A valid provisioning profile β¦ was not found).- The profile picker prefers
com.dvmaon your own team and skips signer sample profiles (likecom.testing.testytest/com.nowsecure.testapp) - a wrong pick makes the install go out under a bogus bundle id.- Install
Dopamine-signed.ipa, notDopamine.ipa. The raw download is unsigned β0xe800801c (No code signature found)on the app itself.Full per-step details, alternatives (
zsign+.p12), and every error message follow.
0. Confirm the device qualifies (Step 0 on the overview): iOS β€ 17.3.1
on a recent iPhone (A14+); older chips have wider ranges. Have Dopamine.ipa
(from Download Dopamine).
1. Check what signing identity you already have. A “codesigning identity” is a
certificate plus its private key in your keychain - that’s exactly what a .p12
bundles into one file. List them:
The 40-character hex string before the quotes is your IDENTITY_SHA1 - it’s what
the signer needs (applesign -i β¦). Capture it into a variable so you never have to
copy it by hand:
- Got an
Apple Development: β¦line? You already have a usable identity - skip to step 3 (profile). Paid Apple Developer certs last 1 year; free Apple Account certs last 7 days (you re-sign weekly). - Nothing listed? Create one for free in Xcode β Settings β Accounts β add your Apple Account β Manage Certificates β β+β β Apple Development. That drops the cert + private key into your login keychain.
2. (Optional) Export the identity to a portable .p12. You only need this if you’ll
sign with zsign, move the identity to another machine/CI, or just prefer a file.
There are three ways to produce one:
Keychain Access (the normal macOS way). Keychain Access β login β My Certificates β expand your βApple Development: β¦β row (confirm a private key is nested under it - no key = can’t sign) β right-click β **Export β**save as
dvma-dev.p12, set a password. This must be done in the GUI: macOS blocks non-interactive private-key export by design, so there’s no fully-headless equivalent. (If you’d rather avoid the.p12entirely, use the applesign variant below, which signs straight from the keychain by identity hash.)security export(CLI, only if the key’s ACL already allows export):openssl(only if you already have separate PEM cert + key files, e.g. from CI):
3. Get a provisioning profile that includes your device. The signature is only valid if a profile lists your device’s UDID and authorizes the app’s entitlements. Two ways:
Let Xcode mint it (easiest - also registers the UDID). Point
xcodebuildat any Xcode project with automatic signing and your team, targeting the connected device. Xcode registers the UDID and writes anembedded.mobileprovisioninto the built.app:The build itself doesn’t need to finish - the
embedded.mobileprovisionappears as soon as Xcode resolves signing (early in the build), so you can stop it once the file exists.Or download one from developer.apple.com (register the device’s UDID under Devices first, create a Development profile including it, download the
.mobileprovision).Or download the ones Xcode already made for you (GUI, no build). If Xcode has ever signed a project for your team, it has profiles ready to fetch: Xcode β Settings β Accounts β select your Apple Account + team β Download Manual Profiles. They land in one of:
There are usually several - pick a plain app-level Development profile (e.g.
iOS Team Provisioning Profile: com.dvma) that hasget-task-allow: trueand includes your device; skip any*.xctrunner/*RunnerUITests*profile (those are test-runner profiles, not for a normal app). List and identify them:That
PROFis what you hand the signer via-m "$PROF". How this picks the right one - positively, not by blocklisting names: it keeps only profiles that are on your team ($TEAM, read from your signing cert), list this device, are debuggable (get-task-allow), and target a concrete app id (no*wildcard, no*.xctrunnertest-runner). Among those it prefers the app id you actually control (PREFER_APP, defaultcom.dvma) - so a signer’s bundled sample profile (e.g. applesign’scom.nowsecure.testapp) is simply never preferred, without hardcoding its name. OverridePREFER_APP=<your.bundle.id>if your profiles use a different one.BUNDLE_IDmatters: a profile authorizes ONE App ID (e.g.TEAMID.com.dvma), but Dopamine’s own bundle id iscom.opa334.Dopamine- a mismatch makes iOS reject the install with0xe8008015 (A valid provisioning profile β¦ was not found). So you must rewrite Dopamine’s bundle id to match the profile during signing (the-b "$BUNDLE_ID"in step 4). IfSELECTED PROF=is empty, no usable profile lists this device - register the UDID (Xcode with the device connected, then Download Manual Profiles) and re-run the loop.Sanity-check the chosen profile contains your device +
get-task-allow(decodes inline - no temp file):
4. Sign the .ipa. Pick one signer. Both re-sign the app with your identity and
clone the profile’s entitlements onto it (that’s the -c / entitlements step -
required so iOS accepts the app):
zsign(uses the.p12from step 2):applesign(signs straight from the keychain - no.p12needed):Trouble installing or running
applesign? Two common snags:npm install -gfails with an auth/ENEEDAUTH/could not locateerror even though applesign is public - your~/.npmrcpoints at a private registry (corporate Artifactory, etc.), so npm tries to auth against it. Force the public registry for just this install:zsh: command not found: applesignafter a successful-ginstall. With nvm/corepack the globalbinoften isn’t on yourPATH(ls "$(npm prefix -g)/bin"shows onlynode/npm/npx, noapplesign). Don’t fight the PATH - just run it throughnpx, which resolves+runs it regardless:(
npxwill offer to fetchapplesign@latestthe first time - accept it.) Do not trynode applesign β¦- that looks for a local file, not the installed CLI, and fails withCannot find module 'β¦/applesign'.
0xe8008015 (A valid provisioning profile β¦ was not found)? The app’s bundle id doesn’t match the profile’s App ID.-b "$BUNDLE_ID"fixes it - sign the app as the profile’s app id (e.g.com.dvma), not Dopamine’s owncom.opa334.Dopamine. Re-sign with-band reinstall. Also make sure the selection above landed on a real app profile on your team (it prefersPREFER_APP), not a signer’s bundled sample.0xe800801c (No code signature found)on a nested framework (e.g.β¦/Payload/Dopamine.app/Frameworks/badRecovery.framework)? You signed only the main app binary and left its bundled frameworks unsigned - iOS requires every nested Mach-O to be signed. Add-a(--all) so applesign re-signs all nested binaries, and-vto verify before install:(
zsignre-signs nested frameworks by default, so this only bitesapplesignruns that omitted-a.)macOS gotcha (App Management / provenance): if
applesignfails withEPERM β¦ open 'β¦/Payload/Dopamine.app/Dopamine', macOS is blocking your (nvm/Homebrew)nodefrom reading the app’s Mach-O - Apple-signed tools likecodesigncan read it butnode/catcan’t. Fix by granting Full Disk Access to your terminal (System Settings β Privacy & Security β Full Disk Access β add Terminal/iTerm), or just use thezsign+.p12path above (it doesn’t do the offending read). This is common on freshly-downloaded.ipas.
5. Connect the phone by USB and tap Trust This Computer if asked
(idevicepair validate should say SUCCESS).
6. Install the signed IPA - path depends on the iOS major version:
Install
Dopamine-signed.ipa, NOT the rawDopamine.ipa. Installing the unsigned download fails with:That means you skipped step 4 (signing). iOS only runs code signed by an identity + profile it trusts, so you must sign first, then install the
-signedfile. (The earlierWARNING: could not locate iTunesMetadata.plist/SC_Info/β¦sinflines are harmless - those only exist in App Store copies.)
If install instead fails with a device/provisioning error - e.g.
0xe8008015 (A valid provisioning profile for this executable was not found)- the app’s bundle id doesn’t match the profile’s App ID (fix: re-sign with-b "$BUNDLE_ID", step 4), or the profile simply doesn’t list this device’s UDID. For the latter: connect the device, open the Xcode project once (or run thexcodebuild β¦ -allowProvisioningDeviceRegistrationcommand in step 3) to auto-register the UDID, re-download Manual Profiles, and re-sign.
7. Trust the developer profile on the phone (free/personal certs only): Settings β General β VPN & Device Management β tap your developer app β Trust. (Paid Apple Developer / enterprise certs are trusted automatically - skip.) See the Run the jailbreak page for the full trust + Developer-Mode details.
8. Open Dopamine to confirm it launches, then go to Run the jailbreak. (A free Apple-Account signature expires in 7 days - re-run steps 4-7 to renew. A paid dev cert lasts ~1 year.)
Which should I pick? Re-jailbreak rarely β Sideloadly. Want hands-off renewal β AltStore if a computer stays nearby, or SideStore if not. Already TrollStore-capable (β€ iOS 16.6.1) β TrollStore (permanent). Have a profile + cert and like the terminal β Provisioning profile / cert. Dopamine is semi-untethered (re-run after each reboot), but the installed app only needs to survive, so a 7-day resign is usually fine.
Under the hood: why CLI signing is "sign, then install"
Sideloading is really two steps - sign the .ipa with an identity the device
trusts, then install it. The full, tested commands (including how to obtain the
identity and profile) are in the Provisioning profile / signing cert (CLI) box
above; this note just explains the moving parts.
- Sign - needs a signing identity (cert + private key) and a
provisioning profile listing your device UDID. Two signers:
zsign(feed it a.p12) orapplesign(signs straight from the macOS keychain by identity hash - no.p12). Both clone the profile’s entitlements onto the app so iOS accepts it. - Install - fully scriptable, and the tool depends on the iOS major version:
- β€ iOS 16:
ideviceinstaller install Dopamine-signed.ipa(libimobiledevice). - iOS 17.0-17.3.1: developer services route through a root tunnel - run
sudo python3 -m pymobiledevice3 remote tunneldin its own terminal, thenpymobiledevice3 apps install Dopamine-signed.ipa. - A TrollStore
.tipais already permanently signed, so it installs as-is - but TrollStore only exists on β€ 16.6.1, not iOS 17.
- β€ iOS 16:
The one piece that isn’t a clean one-liner: free Apple Account (7-day) signing still relies on AltServer’s Apple-Account-auth + anisette flow, so it’s not a single command. With a real dev cert, the
zsign/applesignβ install path above is the clean headless route; otherwise let Sideloadly/AltStore do the one-time free-account signing and only the install is CLI.