fix: report the client as akd, not Xcode, to stop Apple refusing sign-in with 503 - #271
Merged
Merged
Conversation
Since early September 2026 every sign-in fails with `Error response for GSA request: 503`.
Apple's edge refuses any POST to `gsa.apple.com/grandslam/GsService2` whose
`X-MMe-Client-Info` names `com.apple.dt.Xcode`, before any credential is examined -- it
answers a 190-byte HTML page from `Server: Apple` in about 0.2s instead of a GSA plist.
`com.apple.akd` is the daemon that performs this request on macOS and is answered normally.
Reproducible without an account:
curl -so /dev/null -w '%{http_code}\n' -X POST --data-binary t \
-H 'X-MMe-Client-Info: <MacBookPro18,3> <Mac OS X;13.4.1;22F8> <com.apple.AOSKit/282 (com.apple.dt.Xcode/3594.4.19)>' \
https://gsa.apple.com/grandslam/GsService2 # 503
curl -so /dev/null -w '%{http_code}\n' -X POST --data-binary t \
-H 'X-MMe-Client-Info: <MacBookPro18,3> <Mac OS X;13.4.1;22F8> <com.apple.AuthKit/1 (com.apple.akd/1.0)>' \
https://gsa.apple.com/grandslam/GsService2 # 401, i.e. it reached the service
And with this library's own request shape, real anisette data, one variable changed:
akd returns HTTP 200 with a GSA plist, Xcode returns HTTP 503 with the edge page.
Only the app token matters -- bumping the Xcode version does not help, and the user agent,
the hardware and OS portion of the header, and which edge IP is used make no difference.
That isolation is AltStore's, in altstoreio/AltStore#1790, shipped in AltServer 1.7.6.
The same block took out SideStore, Macless Haystack, OpenBubbles and OpenTagViewer;
Dadoum/anisette-v3-server#60 is the same one-token change.
Closes malmeloo#268.
This was referenced Sep 13, 2026
Exporter: UnhandledProtocolError: Error response for GSA request: 503
parawanderer/OpenTagViewer#181
Closed
Owner
|
Thanks, adjusting the anisette client info is definitely the right approach. The additional client info itself still identifies as Xcode for e.g. 2FA, but that doesn't appear to be causing any issues. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #268 (and #269).
Problem
Every sign-in fails with
Error response for GSA request: 503.Apple's edge refuses any POST to
gsa.apple.com/grandslam/GsService2whoseX-MMe-Client-Infonamescom.apple.dt.Xcode, before any credential is examined — it answers a 190-byte HTML page fromServer: Applein about 0.2s rather than a GSA plist.com.apple.akdis the daemon that actually performs this request on macOS, and is answered normally.Reproducing it, without an account
And with this library's own request shape and real anisette data, one variable changed:
X-MMe-Client-Infoapp tokencom.apple.dt.Xcode/3594.4.19com.apple.akd/1.0Credit
The isolation is AltStore's, in altstoreio/AltStore#1790, shipped in AltServer 1.7.6. They established that only the app token matters — bumping the Xcode version does not help, and the user agent, the hardware/OS portion of the header, and which edge IP is used make no difference. Dadoum/anisette-v3-server#60 is the same one-token change. The same block took out SideStore, Macless Haystack and OpenBubbles.
Testing
Verified end to end against a real Apple ID: sign-in that had failed with 503 for days now completes. Done on a fork of this library where the GSA call site composes the header separately; on
mainthat call site readsself._anisette.client, which this changes.One thing worth checking if you patch further:
clientis also used byget_headers(with_client_info=True), so this changes that too. That appears correct — akd is the truthful claim for these requests — but you will know better than I do whether any endpoint expects the Xcode identity specifically.