ScopeBlindFreePass Isolated qualification
Physical-device proof · protection stays off

Prove the device-bound free-trial path—without touching production.

This isolated run checks that one signed iPhone or iPad can produce valid App Attest and DeviceCheck evidence for the exact FreePass release. It cannot allow, block, deploy, or charge anything.

Protection held Rollout 0% Billing $0 No access grant
What passing proves

A real Apple device can hold and present the private trial credential.

FreePass checks a one-time signed challenge, App Attest possession, and Apple’s two-bit DeviceCheck promotion memory. Only a run-scoped receipt comes back; no device identity or raw Apple token is shown here.

  1. 1
    Open the qualification buildUse the signed reference app on a physical iPhone or iPad.
  2. 2
    Run device qualificationThe app creates and submits one expiring proof.
  3. 3
    Save the receiptA passing receipt is evidence—not production approval.
The important boundary

Qualification is not activation.

No customer traffic reaches this site. No normal FreePass issue, decision, billing, workspace, or protected-action API exists here. Moving to canary or full protection requires a separate reviewed production deployment and explicit owner approval.