# Apple & Google wallet

The Wallet Crew generates passes for Apple Wallet and Google Wallet on behalf of Brand. Apple and Google enforce strict issuer identity, signing, and data-handling rules. This setup is critical for compliance and security. Brand must use Brand-owned Apple and Google issuer accounts and credentials.

Brand sets up and controls the accounts and credentials needed to issue passes (certificates, keys, issuer IDs, and approvals). The Wallet Crew uses Brand-provided values to sign and manage passes securely. This keeps Brand as the issuer of record and reduces credential risk. The Wallet Crew acts as the technical provider.

In practice, Brand Legal & IT teams manage the “issuer side” configuration. This includes account ownership, issuer identifiers, signing credentials, and provider approvals. Brand can rotate or revoke credentials at any time. The Wallet Crew should not be the long-term owner of issuer credentials.

{% hint style="warning" %}
This configuration keeps Brand in control of issuer identity and pass data. It also increases security by avoiding third-party ownership of signing keys and provider accounts, and by enabling Brand-managed rotation and revocation.
{% endhint %}

Brand security teams can review the platform security model in [Wallet card security](https://docs.thewalletcrew.io/configure/wallet/wallet-card-security).

### What happens during the onboarding process

* Brand completes the required Apple and Google setup under Brand accounts.
* Brand shares the required identifiers and credentials in the admin console.
* The Wallet Crew verifies the setup matches Apple and Google requirements.
* The Wallet Crew confirms readiness for pass generation and testing.

### More information

Use the platform-specific setup guides below

* Apple: create and manage certificates and push keys : [Apple Wallet certificates](https://docs.thewalletcrew.io/configure/wallet/apple-and-google-wallet/apple-wallet-certificates)
* Google: set up the issuer account and required credentials : [Google Wallet account](https://docs.thewalletcrew.io/configure/wallet/apple-and-google-wallet/google-wallet-account)

### FAQ

<details>

<summary><strong>Can a brand go live with only Apple Wallet or only Google Wallet?</strong></summary>

**No**. Brand needs to configure both Apple Wallet and Google Wallet before going live, so the program covers both iOS and Android users from day one.

</details>

<details>

<summary><strong>Can The Wallet Crew configure Apple/Google for a brand (delegated access)?</strong></summary>

**Yes**. Brand can grants temporary admin access in the provider portals, and delegate The Wallet Crew to do the configuration and removes admin access after validation. Brand remains the owner of the accounts and credentials.

</details>

<details>

<summary><strong>How long does setup take?</strong></summary>

It depends on organization size and whether Brand already owns Apple and Google accounts. Configuration takes around **15 minutes to 1 hour** per wallet provider.

</details>

<details>

<summary><strong>Can a brand rotate or revoke credentials? What happens to existing passes?</strong></summary>

**Yes**. Brand can rotate or revoke credentials at any time. If credentials are revoked, issuance and updates can stop until they are replaced, and installed passes may stop updating.

</details>

<details>

<summary><strong>Should Brand configure both staging and production?</strong></summary>

**No**. Brand can configure only one environment to start. The Wallet Crew can replicate configuration changes on demand.

</details>

<details>

<summary><strong>Does Brand need all information before starting the project?</strong></summary>

**No**. The Wallet Crew can provide test credentials to configure and set up the platform while the Brand team completes the configuration.

These credentials **can’t be used in production**. They are for testing only.

</details>
