# ProvisionQL: a Quick Look plugin for .ipa, .xcarchive and .mobileprovision files

> ProvisionQL is a macOS Quick Look extension and file inspector for Apple app archives and provisioning profiles. It is a narrow tool for people who read entitlements, certificates and device lists, not a signing or build utility.

**ealeksandrov/ProvisionQL** — Quick Look plugin for mobile apps and provisioning profiles

- Repository: https://github.com/ealeksandrov/ProvisionQL
- Stars: 2,462 · Forks: 162
- Language: Swift
- License: MIT
- Published: 2026-09-28 · Updated: 2026-09-28 · Language: en
- Canonical page: https://hysenlabs.com/projects/ealeksandrov-provisionql

## What ProvisionQL inspects that Finder will not

A provisioning profile is a binary plist wrapped in a CMS signature. Finder shows it as an opaque file with no useful metadata, and the same is true of an .ipa or an .xcarchive. Answering a routine question such as which entitlements an archived build carries, whether a profile is a development or distribution profile, or which devices are listed in it usually means decoding the profile by hand and reading the result in a text editor.

ProvisionQL collapses that into a preview. The README lists the file types it handles: .ipa, .tipa (TrollStore IPA), .xcarchive including macOS archive layouts, .appex, .mobileprovision and .provisionprofile. For app archives the documentation says the preview shows bundle metadata, the icon, entitlements, the embedded provisioning profile and diagnostics. For profiles it lists type, platform, signature status, certificates, devices, entitlements and validation diagnostics.

The intended audience is narrow and specific: developers, QA engineers and support staff working on Apple platforms who already have the file on a Mac and want to read it without a terminal. It is a viewer. It does not sign, resign, install or modify anything, and the README never suggests otherwise.

## How the Quick Look extension and the in-app inspector divide the work

The repository is split into two targets plus shared code. ProvisionQLCore holds the parsing logic, ProvisionQL is the app, and Thumbnail is the thumbnail extension. The README's development section points at ProvisionQLCore as a Swift package with its own test suite, which is the part you would exercise if you wanted to trust the parsing.

There are two entry points into that core. The first is Finder Quick Look: select a supported file, press Space, and the extension renders the preview or the thumbnail. The second is the app itself, which the README describes as an in-app file inspector for drag-and-drop and Open With workflows. That second path matters because Quick Look extensions can be disabled or fail to register, and the standalone app gives you a place to drop a file when the Finder preview does not appear.

Error handling is deliberately placed inside the preview. The README lists in-preview error reporting for malformed profiles and archives as a feature, so a truncated or corrupted profile should surface a message in the preview pane rather than an empty window. That is the right call for a viewer: the failure you most often hit is a file that is not what its extension claims.

## Installing ProvisionQL from the DMG and enabling the extension

There is no package manager formula or Homebrew cask in the README. Installation is a signed app dragged out of a disk image, which is why the first launch matters.

Download the latest ProvisionQL.dmg from the Releases page, open it, and drag ProvisionQL.app into /Applications. The README gives those four steps: download the DMG, open it and drag the app to /Applications, launch the app once, and enable the Quick Look extensions in System Settings > Login Items & Extensions if previews do not appear.

To check the result, select a .mobileprovision file in Finder and press Space. You should get a preview showing the profile type, platform and certificate list rather than the generic document icon. If the icon is still generic, the extension is not enabled, not the file that is wrong. The app's toolbar has an Extensions button that opens the System Settings pane directly.

If you are building from source rather than installing the release, the README says to open ProvisionQL.xcodeproj in Xcode 26 or newer and lists these commands:

```sh
swift test --package-path ProvisionQLCore
mise run lint
mise run format
```

## Where ProvisionQL stops: no signing, no Linux, macOS 15 required

The platform badge in the README reads macOS 15 or newer. That is a real constraint, not a formality: on an older Mac the app will not run, and there is no documented fallback. If your team standardises on an older macOS release, this tool is simply unavailable to you.

The second limitation is scope. ProvisionQL reads files. It does not create, edit, resign or install them, and nothing in the README describes a command line interface, a scripting hook or a way to export the parsed data. If you need to resign an .ipa in CI, or diff the entitlements of two archives programmatically, this is the wrong tool. You would be back to the platform's own signing and inspection commands, which do produce machine-readable output.

The third is that a Quick Look extension is only as reliable as macOS's extension registration. The README anticipates this with the System Settings step and with the standalone inspector, but it does not document what happens when an extension crashes on a particular file, and it does not describe a log or diagnostic path for that case.

## ProvisionQL against the command line and against Provisioning

The honest alternative for many of these tasks is the shell. macOS ships the security and codesign tools for decoding profiles and reading entitlements, and unzip can pull an embedded profile out of an .ipa. The difference in approach is that the command line gives you parseable output you can pipe into a script, while ProvisionQL gives you a rendered preview with no scripting surface. If your question is a one-off and you are already in a terminal, the shell is faster. If you are triaging a folder of builds and want to eyeball each one, the preview wins.

The README also credits Craig Hockenberry's Provisioning project as the initial basis for ProvisionQL. That lineage matters because it tells you the parsing rules are not new: ProvisionQL is a modern rewrite of an established idea, with the current version adding the separate app inspector, thumbnails and diagnostics. If you have used the older plugin, the file coverage is the thing to compare, since .tipa, .appex and macOS .xcarchive layouts are explicitly listed here.

## Maintenance, upgrade cost and the MIT licence

The last push to the repository was on 2026-08-16, and release 2.0.0 was tagged the same day. The previous stable release, 1.6.4, dates from 2023-08-06, with a 2.0.0-beta.1 in 2025-08-23. That gap is worth noting: this is a project that moves in large jumps rather than small increments, so a bug you report may sit until the next major version.

The upgrade path is manual. There is no documented auto-update mechanism and no Homebrew cask in the README, so upgrading means downloading a new DMG, replacing the app in /Applications, and relaunching it to re-register the extensions. Budget for that step on each machine, and expect to re-check the System Settings toggle after a major version change.

The licence is MIT, which permits commercial and closed-source use and modification, subject to keeping the copyright notice and permission notice. The README also links a separate PRIVACY.md. Since the tool parses provisioning profiles, which contain device UDIDs and certificate identifiers, read that file before deploying it on a shared or managed Mac. Nothing here is legal advice; the licence text in LICENSE.md is the authority.

## Conclusion

ProvisionQL suits iOS, tvOS, watchOS and visionOS developers, QA engineers and support staff who need to read entitlements, certificates or device lists out of an archive or profile on a Mac, and it is the wrong tool if you need to edit, resign or validate a build on Linux or Windows. Before adopting it, confirm you are on macOS 15 or newer, check that the Quick Look extensions are enabled under System Settings > Login Items & Extensions, and open one malformed profile to see how the in-preview error reporting behaves on your machine.

## FAQ

### How do I install ProvisionQL on macOS?

Download the latest ProvisionQL.dmg from the Releases page, open it, drag ProvisionQL.app to /Applications, and launch the app once. If Finder previews do not appear afterwards, enable the Quick Look extensions in System Settings > Login Items & Extensions.

### Which file types can ProvisionQL preview?

The README lists .ipa, .tipa (TrollStore IPA), .xcarchive including macOS archive layouts, .appex, .mobileprovision and .provisionprofile.

### What macOS version does ProvisionQL need?

The README's platform badge states macOS 15 or newer. There is no documented fallback for older releases.

### Can ProvisionQL sign or resign an app?

No. The README describes it as a file inspector and Quick Look extension that shows metadata, entitlements, profiles and diagnostics. Signing, resigning and installation are not listed as features.

## Sources

- [ealeksandrov/ProvisionQL on GitHub](https://github.com/ealeksandrov/ProvisionQL)
- [Issues](https://github.com/ealeksandrov/ProvisionQL/issues)
- [License: MIT](https://github.com/ealeksandrov/ProvisionQL/blob/main/LICENSE)
- [README](https://github.com/ealeksandrov/ProvisionQL/blob/main/README.md)
- [Releases](https://github.com/ealeksandrov/ProvisionQL/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ealeksandrov-provisionql
