4 ms·
Sign in with Apple" broke after update–losing data for a third of users
We run ASO.dev, a tool helping developers manage their App Store metadata and visibility. On May 3, 2025, we faced a critical issue: “Sign in with Apple” stopped working properly for all users, resulting in the complete loss of access for one-third of our users—specifically, those using Apple’s private relay emails.
What exactly happened?
• Apple began returning a completely new userIdentifier for existing Apple IDs, without users initiating any changes.
This effectively made user authentication impossible, as we can no longer match users to their existing data.
• The email field now always returns null. Although this behavior is typical for subsequent sign-ins, it’s irrelevant in this case because the userIdentifier itself changed, leaving no way to identify existing accounts.
• Previously issued relay emails (@privaterelay.appleid.com) no longer accept emails—we verified this with bounce tests.
• Users also report that our app has disappeared from their Apple ID’s authorized apps list.
Important context:
• We migrated our Apple Developer account from Individual to Organization about a year ago.
• Everything worked perfectly until the May 3, 2025 update.
• The incident occurred precisely on the day Apple released updates to the Developer Console (Accounts, Profiles, etc.). We strongly believe these internal changes at Apple triggered the issue.
Consequences:
• Every user received a new userIdentifier, meaning our system sees returning users as entirely new, breaking the link to their historical data.
• One-third of our users, who registered via Apple’s private relay email, are now completely unreachable:
• We can’t contact them (emails bounce).
• We can’t restore their access (new IDs don’t match old accounts).
• We have sent three support requests to Apple via email—no reply or acknowledgment yet, with no escalation path or live chat available.
⸻
We were fortunate because ASO.dev also supports an alternative sign-in method (email with a one-time login code). Without this alternative, we would’ve permanently lost access for every user who originally signed in with Apple.
⸻
We’re openly sharing this story to:
• Warn developers who rely solely on Apple Sign-In and relay email addresses.
• Connect with others who’ve faced similar issues—let’s share experiences.
• Draw Apple’s attention to this critical problem—currently, there is no documented solution and no available support.
Never rely solely on Apple ID authentication.
Always implement a fallback method, as even major ecosystems can fail unpredictably.
- deleted 1y ago[deleted]
- zainhoda 1y agoOof… coincidentally my task for today is to implement Sign in with Apple. If you were starting over what would you do differently?
- toomuchtodo 1y agoNot OP, but customer identity is a component of my work. Ask users for a recovery email and/or phone number to bootstrap identity if sign in with goes sideways.
- gorniv 1y agoDefinitely save the email in your database — even if it’s a private relay address. Also, send a welcome email right after signup, so users can see which email was used and ideally encourage them to update it to a regular one or add an alternative login method (like passwordless email sign-in or OAuth). If we were starting over, we’d make that update flow more prominent from day one. Apple’s “Hide My Email” sounds harmless until it silently breaks everything later.
- j45 1y agoIs it still the case that offering Apple ID is mandatory on the iOS store? Forcing users to use certain identity providers while uninformed as a sole point of failure is a challenge. Apple (or other providers) already have the user with an ID, having the app do the bidding of propagating it's use further is a different issue. If it was optional, and a convenience/preference that could be added, that would be a different thing.