Deployment
put it where your team works.
Token Forge has no server, so deploying means building the app and putting it in front of your team: as a static web app on your own HTTPS host, as a macOS app, or through the app stores. Do the rebranding first.
01Before any release
- Rebranding done: your name, bundle ID and icon.
flutter analyzeandflutter testpass.- No real RPC URL in any committed file or build script.
- You created and operated a test token on devnet with this build.
- Decide who may open this build: it has no login (why).
02Web
- Build
The output is influtter build web --releasebuild/web/. Verified with Flutter 3.41.4. - UploadCopy everything in
build/web/to any static host (your web server, an object-storage bucket with a CDN, or a static hosting service). - Serve it over HTTPSThe browser only allows the secure store in a secure context. Over plain HTTP the endpoint you save in Settings lasts for the session only, and the app tells you so.
- Hosting in a sub-folder?Build with Flutter's base-href flag:
flutter build web --release --base-href /forge/
Anyone who can open the URL can use the app and its Settings. The forge holds no key and cannot move funds, but settings and the audit trail are per browser. Put an internal tool behind your own access control if needed. A --dart-define endpoint in a web build is readable by anyone who downloads it.
03macOS
- Add Keychain SharingOpen
macos/Runner.xcworkspacein Xcode, select the Runner target → Signing & Capabilities, choose your Team, and add Keychain Sharing. Without it the keystore write fails and your endpoint does not persist. The package's entitlements files (macos/Runner/*.entitlements) do not include it yet. - Build
The app is created underflutter build macos --releasebuild/macos/Build/Products/Release/. - DistributeSign and notarise with your Apple Developer account (Xcode → Product → Archive) or publish to the Mac App Store.
The macOS build was not run for these docs; the steps follow the project files and DOCS/INSTALL.md (unverified end to end).
04Android
Release builds are signed with the debug key so that flutter run --release works out of the box (android/app/build.gradle.kts). Google Play refuses debug-signed builds.
- Change the application IDSee Rebranding.
- Create an upload key
Keepkeytool -genkey -v -keystore upload.jks -keyalg RSA \ -keysize 2048 -validity 10000 -alias uploadupload.jksand its passwords safe and out of Git. The key you first publish with is the key you are tied to. - Wire it into the release buildReplace
signingConfig = signingConfigs.getByName("debug")with your own signing config, following Flutter's Android deployment guide. - Build the bundle
flutter build appbundle --release
Android and iOS builds were not run for these docs (unverified). Check the store's current policy for token-creation apps before you submit.
05iOS
- Set the bundle ID and teamOpen
ios/Runner.xcworkspace, Runner target → Signing & Capabilities. - Build
flutter build ipa --release - UploadWith Xcode Organizer or Transporter to App Store Connect.
06Going to mainnet
- Add your mainnet endpointSettings → Your RPC endpoints.
- Switch on Allow mainnetSettings → Network.
- Record your venue checksFrom your devnet test, in the venue-check register.
- Use a multisigFor the authorities you keep, and sign every mainnet transaction only after its simulation succeeded (the forge enforces the simulation).