Open-source project
claration/impactor avatar
claration/impactor

Impactor: a Rust sideloader that talks to Apple's servers for you

Cross-platform & feature rich iOS/iPadOS/tvOS sideloading application. Formerly known as PlumeImpactor.

3,371 stars217 forksRustMIT

At a glance

What is it?
Impactor (formerly PlumeImpactor) is a cross-platform iOS/iPadOS/tvOS sideloading app written in Rust. It replicates parts of Xcode's signing flow so you can install IPAs with a free Apple ID, and it is the wrong tool if you expected a Cydia Impactor replacement.
Who is it for?
Adopt Impactor if you sideload IPAs on macOS, Linux or Windows and want certificate creation, provisioning and signing handled in one GUI, or if you need a pairing file for SideStore, LiveContainer or StikDebug. Do not adopt it if you need a sideload that survives longer than seven days, if you cannot install usbmuxd on Linux or iTunes on Windows, or if you were looking for Cydia Impactor, which is a different, unrelated program.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem Impactor solves, and who it is actually for

Installing an IPA on an iPhone without a paid Apple Developer account means doing what Xcode does: registering the device with Apple, asking for a certificate, registering an App ID, fetching a provisioning profile, and signing the binary before it can be pushed over USB. Impactor exists to do that sequence in one application rather than in Xcode. The README describes the goal directly: it tries to "replicate what Xcode would do but in our own application", using your Apple Account as the developer identity.

The audience is narrow and specific. It is people who already have an IPA to install, either one they built, one obtained through ipatool, or one that needs a tweak injected before installation. It is also for people who want the pairing file that lets SideStore, LiveContainer, StikDebug, Antrag or Protokolle talk to the device directly. The README lists eleven such apps, from Reynard Browser to Ksign.

What it is not: this is not Cydia Impactor, despite the shared name. Cydia Impactor is an older, separate tool, and several of the questions people search for around this name belong to that project or to a Transformers character. If you came here for the classic Cydia Impactor workflow, nothing in this repository describes it.

How the signing pipeline works, step by step

The README walks through the order of operations. First Impactor registers the iDevice with Apple's servers. Then it creates a certificate, which the README says lasts 365 days, and stores the key locally. That storage detail matters more than it looks: the README states that you must copy the keys to other machines, otherwise Impactor will create a new certificate there.

Next it registers the app being sideloaded and provisions it with entitlements gathered from the binary. The README calls the entitlement handling "almost proper" and notes that plugins can be registered, and that entitlements such as increased-memory-limit can be requested for emulators. Then it downloads the certificate and provisioning profile it just created. Finally it modifies the app, which can mean tweak injection, renaming, or other changes, and signs it with apple-codesign-rs before installing through idevice.

The free-account limits are stated plainly: seven days and a capped number of apps and components. That is an Apple policy constraint, not an Impactor bug, and no amount of re-signing removes it. The workspace in Cargo.toml shows the split: plume_core, plume_gestalt, plume_store and plume_utils are the crates, with apps/plumeimpactor and apps/plumesign as the two binaries. The Makefile builds both and, on macOS, can wrap the result in Impactor.app.

Installing Impactor on macOS, Linux and Windows

The README points at the releases page for the latest build and says the app is also available on Flatpak and Homebrew. On macOS the documented Homebrew command is a single line.

bash
brew install --cask impactor

After that, `impactor` should be available as an installed application. On Linux the README links the Flathub listing for dev.khcrysalis.PlumeImpactor, and the Makefile confirms that identifier is the Flatpak app ID. Two platform prerequisites are called out. Linux needs usbmuxd installed, which the README says most popular distributions already ship, and Windows needs iTunes downloaded so Impactor can use the drivers for talking to Apple devices.

The Linux footnote also warns about a real failure mode: on some distributions the udev rules let usbmuxd stop running once no device is connected, so Impactor will not detect a device plugged in later. The suggested workaround is to plug the phone in first and then restart the app. Some distributions, Bazzite is named, may need `sudo update-crypto-policies` before usbmuxd detects the device again.

For a first real use, connect the device, open the Utilities page, and install one of the supported pairing-file apps. The README describes exactly that path: retrieve the pairing file either by sideloading the supported app of your choice, or by going to Utilities while a device is connected and pressing install. Pairing files are device specific and become invalid after a re-trust, an update or a reset.

Linux is supported, with an honest caveat about auto-refresh

Cross-platform is claimed, and the repository backs it up with a flake.nix, a Flatpak manifest target and a Makefile that branches on uname. The caveat is that Linux does not get the same experience as macOS and Windows. The README states that auto-refresh will not work the same way because usbmuxd lacks WiFi connectivity, so Impactor only attempts it automatically when a device is plugged in. The README also says a proper solution is being looked for, which is a rare admission that the current behaviour is a stopgap.

That is a design trade-off worth naming. Plugging in a cable to refresh a seven-day signature is exactly the friction people sideload to avoid, and on Linux it is currently unavoidable. If your workflow depends on wireless refresh, macOS or Windows is the better host for this tool.

Tweaks, entitlements and the limits of what gets injected

Tweak support is aimed at advanced users and uses ElleKit for injection. The README lists what can be injected or added: .deb and .dylib files, plus .framework, .bundle and .appex directories. It also mentions replacing Cydia Substrate with ElleKit for 26.0 compatibility, which is a compatibility shim rather than a general-purpose hooking framework.

The entitlement handling is where the README hedges, calling it "almost proper". That phrasing is worth taking at face value. Entitlements are gathered from the binary and requested where possible, but an entitlement Apple will not grant to a free account cannot be conjured by the tool. The increased-memory-limit example is presented as something you can request for emulators, not as something guaranteed.

There is also a signing artefact worth knowing about: Impactor generates a P12 for SideStore and AltStore to use, similar to Altserver, and can export a P12 for LiveContainer. If you already have a working Altserver setup, that overlap means you are not gaining a new capability, just a different host application.

Where Impactor is the wrong choice, and what to use instead

The clearest wrong case is anyone who wants a permanent install. The README is explicit that without a paid developer program you are limited to seven days, so if your requirement is an app that keeps working unattended for months, Impactor is the wrong layer and a paid developer account or a self-hosted refresh service is the right one.

A second wrong case is a machine that cannot meet the prerequisites. On Windows without iTunes, the drivers for device communication are missing. On a Linux distribution where usbmuxd keeps dying, every session starts with a restart dance. Neither is fixable from inside Impactor.

As an alternative, consider Altserver. Impactor's own README compares itself to it on one point: Impactor generates a P12 for SideStore and AltStore "similar to Altserver". The difference in approach is that Altserver is the reference implementation AltStore was built around, while Impactor is a Rust reimplementation of the Xcode signing flow that also produces pairing files for a wider set of apps, including StikDebug and Protokolle. If your setup is already AltStore-shaped, switching gains you the broader pairing-file tooling and loses you nothing on the P12 side. If you only need a pairing file and nothing else, note that Impactor bundles that as a utility rather than as a separate download.

Maintenance, licensing and the cost of staying current

The repository is not archived, and the last push was on 2026-09-22. Releases are frequent: v2.6.3 on 2026-09-11, v2.6.1 on 2026-09-02 and v2.6.0 on 2026-07-02. The workspace version in Cargo.toml is 2.6.3, matching the newest release tag, so the version bump is part of the normal commit flow rather than a separate step.

The release profile in Cargo.toml is tuned aggressively for size: opt-level = "s", lto = true, panic = "abort", strip = "symbols" and split-debuginfo = "packed". The comments claim roughly 25 percent from opt-level, 14 percent from LTO and 50 percent from panic = "abort" combined with panic_immediate_abort. Those are the maintainer's own figures in a source comment, not measured results, and they tell you the project optimises for a small download rather than for peak signing speed.

Upgrade cost is low if you install through Homebrew or Flatpak, since those channels carry the version. If you build from source, the toolchain expectations are current: edition 2024 in the workspace, resolver 3, and a pinned git revision for the idevice dependency. The licence is MIT, which is permissive and imposes no copyleft obligation on your own code. That is a statement about the licence text, not legal advice about your distribution plans.

Editorial conclusion

Adopt Impactor if you sideload IPAs on macOS, Linux or Windows and want certificate creation, provisioning and signing handled in one GUI, or if you need a pairing file for SideStore, LiveContainer or StikDebug. Do not adopt it if you need a sideload that survives longer than seven days, if you cannot install usbmuxd on Linux or iTunes on Windows, or if you were looking for Cydia Impactor, which is a different, unrelated program. Before relying on it, verify that your Apple ID can still register certificates, that your key material is copied to any second machine you sign from, and that your Linux distribution keeps usbmuxd running after a device is unplugged.

Frequently asked questions

How do I install Impactor on macOS?

The README documents a Homebrew cask, so `brew install --cask impactor` installs it. The releases page is listed as the place to get the latest version for your computer, and Flatpak is offered for Linux.

Is Impactor safe to use with my Apple ID?

The README does not address safety or account risk directly. What it does document is that Impactor uses your Apple Account as the developer identity to request certificates and provisioning profiles from Apple, and that it stores the certificate key locally on your machine.

Is Impactor the same thing as Cydia Impactor?

No. This project is Impactor, formerly PlumeImpactor, a Rust sideloading application from the claration/Impactor repository. Cydia Impactor is a different, older tool, and nothing in this README describes it.

How do I install Cydia Impactor on Linux?

The README does not document a Cydia Impactor installation, because that is a different tool. For this project, Linux users are directed to the Flathub listing for dev.khcrysalis.PlumeImpactor and need usbmuxd installed, which the README says most popular distributions already ship.

What is Impactor?

The README describes it as an open-source, cross-platform and feature rich iOS sideloading application supporting macOS, Linux and Windows. It signs and sideloads applications on iOS 9.0+ and Mac using your Apple ID.

Official sources

  1. claration/impactor on GitHub
  2. Issues
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/claration-impactor.svg)](https://hysenlabs.com/projects/claration-impactor)