MMashDiv

App review access

How to give Apple and Google reviewers a working account on your server — a verified email, a KYC level that allows what they will try, licence attestations only if you enforce them, a funded wallet, a usable second factor, and the geo and demo-mode traps.

8 min readUpdated 26 September 2026admin, app-review, app-store, google-play, kyc, attestation, demo-account

The app has nothing to show before sign-in. There is no guest mode and no demo mode: every screen is behind the sign-in form, so a reviewer without working credentials sees that form and nothing else. Apple rejects an app it cannot get into under guideline 2.1(a).

So give the reviewers a real account on your live server, and put its email and password in App Store Connect → App Review Information and in the app access instructions in Play Console. The rest of this page is about making that account work end to end, because a fresh account on a real exchange is refused in several places a reviewer will try.

Apple accepts either working demo credentials or an approved demo mode, and a demo mode has to show the app's full features. A fake that cannot place an order or show a deposit address does not qualify. The app has no demo mode, and real credentials on your own server are the supported path.

Set up the account

  1. Create it the way a customer would. Register in the app, with an email address you control. Sign-up and password reset from the app work when your server's Captcha Provider is Proof of Work (built-in, no keys) (the default) or None — no captcha at all: the app solves the proof-of-work challenge itself. With Turnstile, reCAPTCHA or hCaptcha, the app tells the customer to use the website, so register on your website instead; see Sign-in methods.

  2. Verify the email. While Email Verification Required (verifyEmailStatus) is on, and a missing settings row counts as on, the app refuses an unverified account with User email not verified. Verification email sent. Open the link in the email, or switch on Email Verified on the account under Users → Users (/admin/crm/user).

  3. Approve a KYC application at a level that allows everything the reviewer will try. See KYC below. Put a country on the application; that also settles step 4.

  4. If you enforce licence attestations, give the account a licensed country. Only needed while Enforce Licence Attestations (Mobile App) is on. See Licence attestations below.

  5. Fund it. Credit the account's wallets from the admin so the reviewer can use the money screens without buying crypto. See Adjusting a balance. Keep the amounts small and ordinary; a balance of a million in a review screenshot invites questions.

  6. Give it a second factor the reviewer can use, if your withdrawal policy asks for one. See Two-factor below.

  7. Sign in with it yourself, on a phone, with the build you are submitting. Open Trade, place a small order, open a deposit address and start a withdrawal. Anything that refuses you will refuse the reviewer.

KYC refuses more than it hides

This matters only when KYC Verification (kycStatus) and Enforce KYC Feature Access (kycFeatureEnforcement) are both on, under System → Platform Settings → Features → Verification. Then the account's approved KYC level must list every feature the reviewer will use. It is not enough that the screen opens: the server refuses individual actions with a 403 even inside a screen the account can see.

The reviewer tries KYC feature the level must list
A spot order trade
A spot deposit, or a fiat deposit through one of your own deposit methods deposit_wallet
A withdrawal withdraw_wallet
A transfer between wallets transfer_wallets
Opening a support ticket support_ticket
Staking; withdrawing or claiming from a position invest_staking; withdraw_staking
Creating a P2P offer; opening a P2P trade make_p2p_offer; buy_p2p_offer
Commenting on a blog post comment_blog
A futures order futures_trading
Buying into a token offering purchase_ico
Opening the Store; placing a store order view_ecommerce; order_ecommerce
Registering as a merchant use_gateway

The refusals read KYC verification is required to <action>. or Your verification level does not include this feature (<action>). Complete a higher verification level to continue. A reviewer refused a support ticket this way reports the app as broken. Levels are set in Users → Compliance & Verification → Verification Levels (/admin/crm/kyc/level) and applications approved in KYC Applications (/admin/crm/kyc/application). See KYC.

With either switch off, the levels' feature switches restrict nothing. An approved application is still worth having: it gives the account a country, and a few add-on doors ask for one whenever KYC Verification is on, such as merchant registration when the payment gateway's own KYC setting is on, and a trade against a P2P offer whose maker requires KYC.

Licence attestations

Skip this section if Enforce Licence Attestations (Mobile App) is off, which is the default. The app then serves every feature as the website does, and the attestation table plays no part.

With it on, nine features reach an app user only if their country of residence has a live licence recorded for that feature: spot trading, P2P, staking, token offerings, futures, ecosystem wallets, copy trading, merchant payments and AI Investment. A fresh install has none, so a reviewer signs in to a wallet and a market list with no order ticket behind the Trade tab. The rest of the app works, which makes it read as half-built rather than locked.

  • Record what you actually hold in System → Compliance → Licence Attestations, for each feature you want reviewed. See Licence attestations.
  • Give the account a country the server can read. Residence comes from the account's approved KYC application first and its profile second, never from an IP address or the phone's region. What matters is the country on the account, not where the reviewer is.
  • Do it before you hand over the credentials. The app reads which features exist when it signs in or starts with a saved sign-in, and keeps that answer. A row you add while the reviewer is using the app reaches them only after they sign in again or fully close and reopen the app, and they will not think to.

The app says which of the two problems it hit. "Feature is not offered in your registered country ..." means no licence for that country. "Tell us your country of residence to use Feature ..." means the account has no country, which is a half-provisioned review account, not your licensing.

Two-factor

If Require 2FA to Withdraw or Verify 2FA on Every Withdrawal is on (Security → Withdrawal Security), a withdrawal needs a second factor. The app supports the step-up code: it asks your server for a code on the customer's own channel and sends the resulting token with the withdrawal. An account with no usable factor cannot withdraw, and the app says so. See Withdrawal approval and two-factor policy.

The simplest arrangement for review is an authenticator-app factor whose secret you give in the review notes, so the reviewer generates codes themselves without waiting for an email. Remember that once the account has two-factor on, sign-in asks for a code too, while Two-Factor Authentication is on for the platform. The sign-in code screen also accepts one of the account's recovery codes, behind its Can't get a code? Use a recovery code link, so a recovery code in the review notes is a fallback if the reviewer's codes are refused. Each recovery code works once.

If none of your withdrawal settings asks for two-factor, leave it off on the review account. That is one less thing for the reviewer to get wrong.

Geo restrictions

Reviewers may connect from a country your Geo Restrictions block. A rule that restricts only some activities lets the account sign in and then refuses it the actions you restrict there, such as trading or deposits; a rule that blocks the whole platform refuses sign-in as well. Either reads as broken rather than restricted, even when the account's residence is licensed: geo rules look at where the request comes from, not where the customer lives.

  • The lever is the Always-allowed IP addresses list (geoRestrictionIpAllowlist) under System → Compliance → Geo Policy, which is checked before any country rule. It only helps if you know the reviewer's addresses.
  • Do not give the review account an Admin role to get around it. Administrators are never blocked (geoRestrictionAdminBypass) applies only to /api/admin requests, so it would not let a reviewer trade or deposit anyway, and it would hand a stranger your admin API.

Say in the review notes which countries you restrict and why, so a refusal reads as compliance. See Geo restrictions.

What to write in the review notes

  • What the app is and who operates it, and which markets it serves.
  • The entity and its licence. For a regulated product, name the entity, the regulator and the licence number, the same ones you recorded in the attestation console, so the reviewer finds one story rather than two.
  • Which features are restricted, and where. Say which you deliberately do not offer, so a feature the reviewer cannot reach reads as a market you do not serve rather than a screen that failed.
  • The credentials, and the authenticator secret if the account has one.

Account deletion is real

The app's Delete Account really deletes the account and ends all its sessions. If a reviewer tests it on your review account, you need a new account for the next submission. Deletion is refused while the account has open orders (for example You still have 2 open orders. Cancel them, then delete your account.), and a balance must be withdrawn or deliberately given up first.

Do not use NEXT_PUBLIC_DEMO_STATUS

NEXT_PUBLIC_DEMO_STATUS exists for demo installations, and it is the wrong tool here. While it is set, every public sign-up, by email or Google, is given the Admin role, and those accounts keep it after the flag is unset. On a live exchange that makes every new customer an administrator. A production install logs a warning for each one, but nothing stops it.

What it deliberately does not do

  • No demo or guest mode. Every screen needs a signed-in account.
  • No reviewer bypass. There is no per-account exemption from KYC, attestations or geo rules, and no hidden switch that relaxes them during review.
  • No test server. The reviewer uses your live server, so everything they do is real: orders, deposits, withdrawals and deletion.