Apple's FairPlay Streaming (FPS) protects HLS playback on iOS, tvOS, and Safari. This guide walks through obtaining an FPS certificate from Apple and handing the resulting credentials to StreamShark so we can wire up license delivery for your content.
Note. FairPlay is Apple's own DRM system and is required for hardware-backed protection on Apple devices. Because Apple issues these certificates directly to the content owner, this is a one-time setup that only you can complete on your developer account.
What you'll need to provide
Once Apple has issued your FairPlay materials, your StreamShark onboarding contact will ask for four things. Keep them together and treat them as secrets. Anyone holding this set can issue playback licenses for your content.
- The FairPlay certificate, as a
.deror.cerfile - The matching private key, as a
.pemfile - The passphrase you set on that private key
- Your Application Secret Key (ASK), the string Apple shows once during setup
Which FairPlay certificate type do I need?
Apple's Developer portal can issue two kinds of FairPlay Streaming credentials, and only one works with our DRM provider.
Please select SDK 4.x, which produces a single certificate file (fairplay.cer, roughly 1.2 KB) generated from a 1024-bit RSA key, along with an Application Secret Key (ASK) shown once on screen.
Important. Do not select SDK 26. That option asks for two certificate signing requests (1024-bit and 2048-bit) and returns fps_certificate.bin and provisioning_data.bin, which we are unable to accept. If you have already generated an SDK 26 credential, please stop and contact us before generating anything further, as Apple permanently limits each developer account to two FairPlay certificates and provides no way to delete them.
Step 1: Request the FPS Deployment Package from Apple
Everything starts inside your Apple Developer account. If your organization doesn't have one yet, enroll at the Apple Developer enrollment page before continuing.
- Sign in to your Apple Developer account.
- Open the FairPlay Streaming page and follow the link to request the Deployment Package.
- Complete Apple's application form describing your content and how it will be distributed.
- After Apple reviews and approves the request, they release a package that includes the FPS Credential Creation Guide. Approval isn't instant, so start this step early in your project.
Note. The form asks whether you've built and tested your own Key Server Module (KSM). Since StreamShark operates the license server on your behalf, answer that you're using a third-party DRM service whose Key Server Module is already built and validated.
Important. Be thorough about your company, the content, and your rights to distribute it. Vague applications tend to sit in review far longer and are more likely to be turned down.
Step 2: Create your private key and certificate request
Next, generate a private key and a Certificate Signing Request (CSR). You'll upload the CSR to Apple in the following step. These commands use OpenSSL, so make sure it's installed on the machine you're working from.
Generate the private key. You'll be prompted to set a passphrase. Choose one and record it, as you'll need it again shortly and StreamShark will need it later:
openssl genrsa -aes256 -out privatekey.pem 1024
Important. Keep the passphrase under 32 characters and avoid special characters, or later tooling may reject it.
Now create the CSR. Adjust the values in -subj to match your own organization before running it:
openssl req -new -sha1 -key privatekey.pem -out certreq.csr \ -subj "/CN=YourAppName/OU=YourTeam/O=YourCompany/C=AU"
When prompted, enter the private key passphrase you just set. You'll be left with two files: privatekey.pem and certreq.csr.
Step 3: Generate the certificate in the Apple Developer Portal
- Sign in to the Apple Developer Portal and open Certificates, Identifiers & Profiles.
- Under Certificates, select the add (+) control to create a new certificate.
- Choose FairPlay Streaming Certificate and select the SDK 4.x option, then select Continue. Do not select SDK 26. See Which FairPlay certificate type do I need?
- Select Choose File and upload the
certreq.csryou generated with OpenSSL, then Continue. - Apple now shows your Application Secret Key (ASK). Copy it and store it somewhere safe immediately. It's displayed only once, and a leaked ASK can't be used to protect your content anymore.
- Paste the ASK into the field provided and select Continue.
- Confirm you've saved the ASK, then select Generate.
- Return to Certificates, open your new FairPlay Streaming Certificate, and select Download to save the certificate file (for example,
fairplay.cer).
Important. The ASK appears exactly once. If you move on without copying it, you'll have to revoke the certificate and start the process again.
Send your credentials to StreamShark
With all four items in hand, the certificate file, the private key, its passphrase, and the ASK, reach out to your StreamShark account manager to complete FairPlay setup. We'll load them into your license configuration and confirm playback across your Apple targets.
Please share these credentials through a secure channel rather than plain email. Your StreamShark contact can provide an encrypted upload link on request.
Once configured, FairPlay licenses are delivered automatically alongside your HLS streams, with Widevine and PlayReady handled in parallel for non-Apple devices. See Enabling EzDRM for Live Events, Live Scheduler and videos for how to turn DRM on for your content.