Key takeaways
- Apple's 2026 action against Replit blocked updates of the Replit iOS app itself – not apps built with Replit, as a reply in Replit's own forum pointed out.
- Replit separates development and production: secrets, databases, Clerk users and sign-in providers. A review account created in development doesn't exist in the published app.
- Autoscale deployments scale to zero, so a first request can take a few seconds – use a Reserved VM or a native loading state so App Review never sees a blank app.
- Treat every Publish as a release: no Agent-built features go live while a build is in review, and new functionality ships with a new build and specific review notes.
Our recommended solution
Rebuild your wrapper with WebViewGold – a real app, not just a website in a frame
WebViewGold turns your website into native iOS and Android apps with push notifications, a native offline screen, deep links, a QR scanner and more – the building blocks App Store reviewers look for. Built by our own team, and we submit WebViewGold apps all the time.
What the rejection typically looks like
Guideline 5.6 - Developer Code of Conduct
We've identified a pattern of unusual behavior with the app that is commonly associated with fraudulent activity. Specifically, the app contains features that appear to have been intentionally hidden during the review process.
Paraphrased example – the exact wording in your message may differ.
Replit app rejected under Guideline 5.6 – and why it isn't a Replit ban
A Replit app rejected under Guideline 5.6 was flagged under Apple's Developer Code of Conduct, not because of the tool behind it. App Review concluded that something about the app's behavior looked deceptive – most often features the reviewer couldn't reach or that changed after review. In Replit projects, that traces back to deployments, environments, sign-in and fast Agent edits, and all of it is fixable.
Many Replit builders first suspect a ban, and the timing explains why. In March 2026, Apple blocked App Store updates of vibe-coding tool apps, Replit's among them, citing Guideline 2.5.2 and its developer license terms (9to5Mac). The concern was the tool app running generated apps inside itself. On May 15, 2026, Replit CEO Amjad Masad said the company had "worked things out with Apple" and shipped its iOS app's first update in four months (9to5Mac).
When a user in Replit's forum read the March news as a ban on Replit-built apps, the reply was blunt: "They aren't blocking apps made in Replit, they've stopped Replit from being able to update the Replit app." (Replit forum, April 2026). Your rejection is about your app.
The letters developers posted in 2026 speak of "a pattern of unusual behavior" and features that "appear to have been intentionally hidden during the review process", usually without naming them. Apple says it pairs human review with machine learning that can "flag potentially problematic changes in app updates" (Apple Newsroom). For the cross-builder picture, read our pillar on 5.6 rejections of AI-built apps.
Native Expo app or wrapped web app: where the 5.6 risk sits
| Replit mobile app (Expo, React Native) | Replit web app inside a native wrapper | |
|---|---|---|
| How it reaches Apple | Publishing tab, Replit's Launch flow, TestFlight – from your Apple Developer account | Your own native shell that loads the published deployment |
| What changes without a new build | Everything the app fetches from your Replit server: API routes, data, server-side logic | The entire interface and its logic – with every Publish |
| What needs a new build | Native changes such as icons or permissions | Native modules and shell settings |
| Typical 5.6 trigger | Server responses that unlock screens the reviewer never saw | A dev URL, a private deployment, cold starts, features published mid-review |
Both routes depend on the same thing: the server you publish on Replit. That is where most 5.6 trouble starts, so the rest of this article focuses on it.
Rejected or stuck? Talk to an App Specialist – for free.
Book a free consultation call: we look at your rejection or setup, explain the fastest way forward and tell you honestly whether you need us. Prefer to hand it off? Book our AI-powered + human-powered service and we take care of it.
Replit habits that read as hidden features
- Pointing the app at a development URL. Development URLs on
replit.devare, in Replit's words, "only live while you actively work on a Replit App", and they can change each time you reopen the project. A wrapper or review note that uses one shows the reviewer a dead page or your in-progress build with Replit's educational banner – never the app your users get. - Two environments, one assumption. Replit keeps development and production secrets in separate stores, the published app reads the production database, and Clerk Auth gives each environment its own user store: "Accounts that sign up in the Development environment do not exist in the Production environment". The demo account you tested with may not exist for the reviewer.
- Sign-in providers enabled in one place only. Development and production also keep separate provider lists, so a Google or Apple button that works in your preview can be missing in the published app.
- A private or password-protected deployment. Published apps can be public, password protected or private, and visitors without access to a private one are "prompted to sign in through Replit". A reviewer facing a Replit login wall sees none of your features.
- Cold starts. Autoscale, the default deployment type, scales to zero when idle, and Replit notes that "the first request after scaling to zero can take a few seconds". A wrapper that shows nothing meanwhile looks broken – or empty.
- Secrets as feature switches. A flag in the deployment secrets plus a republish changes what the app does without a new build or review – the dormant features Guideline 2.3.1(a) forbids.
- Agent edits after approval. One prompt to Agent 4 can restructure screens or add a feature, and one Publish ships it to every app user. Store screenshots polished by AI until they show more than the app delivers belong in the same category.
- Replit branding where yours should be. Replit Auth signs users in with Replit accounts on a Replit-branded page, Clerk with Replit-managed OAuth credentials shows Replit branding on the provider's consent screen, and Starter-plan apps carry a "Made with Replit" badge with a referral link. Guideline 5.6.2 asks you to represent yourself and your offerings accurately – make it obvious whose app this is.
Audit your Replit project before you answer Apple
| Where in Replit | Check | Fix |
|---|---|---|
| Publishing – deployment settings | Deployment type, access setting (public, password, private), production secrets | Public access, a Reserved VM or a native loading state, no feature-switch secrets |
| Publishing – History | Deployments between your submission and the rejection | List them in your reply; roll back unreviewed features |
| Users & Auth – Users, Production toggle | Does the review account exist in production, with a verified email? | Create it on the published app and add realistic data |
| Users & Auth – Configure – SSO providers, Production | Which providers are enabled; Replit-managed or custom credentials | The same providers you show in the app, with your own OAuth credentials |
| Wrapper configuration and review notes | A replit.dev address or a replit.app subdomain that may change | Your custom domain, connected before you submit |
| Git pane and Agent history | What Agent changed since the reviewed build | Revert it, or ship it with a new build and describe it |
Replit warns that a remixed app may receive a different .replit.app subdomain – one more reason to put a custom domain in front of anything App Review sees. Our article on fixing 5.6 in WebView apps adds a screen-by-screen walkthrough.
The fastest fix for most WebView rejections
WebViewGold: native features for your web app
Instead of building native features from scratch, start from WebViewGold. You get ready-made Xcode and Android Studio projects for your website, with native modules you switch on in the configuration:
- Push notificationsOneSignal or Firebase, for real, personal events
- Native offline screenNo browser error pages when the connection drops
- Native splash screenApp-like start instead of a loading web page
- Deep linksLinks open the right screen inside the app
- QR & barcode scannerDevice features the website alone can't offer
- In-app purchasesNative purchase flows where the store requires them
No tool guarantees an approval: Apple still judges what your app offers. Use the native features in your main user journey – our App Specialists review your WebViewGold app before it goes to the App Store.
Stabilize what the reviewer sees, then resubmit
- Give App Review one stable address. Connect your custom domain, keep access public and consider a Reserved VM, which Replit describes as a dedicated server that "never sleeps". If you stay on Autoscale, make sure the app shows a native loading state instead of a white screen.
- Create the review account in production. Email and password through Clerk, signed up on the published app, email verified, sample data added and paid features unlocked. Don't make Google the only way in: Replit's own docs warn that "Google sign-in does not work in embedded browsers or in-app webviews."
- Freeze features during review. Ask Agent for fixes only – Replit's own prompt examples include the line "Do not add new features" – and publish no new functionality until a build that describes it is approved.
- Remove switches. Delete secrets that turn features on and off for app users, or ship the feature switched on for everyone with the build that introduces it.
- Make the app unmistakably yours. Clerk with your own OAuth credentials, your name and icon on the sign-in screen, no Starter badge, and a seller name that matches the business behind the app.
- Write specific Notes for Review. Every feature, where it lives and how to reach it with the demo account – Guideline 2.3.1(a) says generic descriptions will be rejected.
Wrapping a Replit web app so App Review sees a stable, native app
WebViewGold, the website-to-app solution built by our team, names Replit among the builders it supports: anything that runs in Safari or Chrome becomes a native Xcode project. Point Config.swift at your custom domain, and the modules cover the 5.6 weak spots of a thin wrapper:
- Cold starts: the native loading indicator and splash screen bridge the seconds an idle deployment needs, and the offline screen with its Reconnect button catches real outages.
- Ratings: Apple's native in-app rating dialog replaces web prompts – Guideline 5.6.1 says Apple "will disallow custom review prompts".
- Sign-in: Sign in with Apple pages are detected and handled automatically. Google sign-in has to leave the WebView: add
ASWebAuthenticationSessionor Google's Sign-In SDK to the Xcode project, or offer email and password plus Apple in the app and keep Google on the web. - Native value: push via OneSignal, Firebase or Pushwoosh, Face ID, a QR scanner and native navigation make the app more than a frame.
Use the custom user agent only to adapt layout, never to show reviewers something different. No tool can promise an approval, and a WebViewGold app still needs the production fixes above. If you'd rather rebuild natively with Replit's Expo flow, our guide to converting Replit to iOS compares both routes, and Replit to Android covers Google Play. Where web content ends and forbidden code loading begins is explained in Guideline 2.5.2 for WebView apps.
How to reply – and the mistakes that make it worse
Reply to App Review in App Store Connect; replies hold up to 4,000 characters and attachments. Describe what you checked – deployment type and access, production users and providers, secrets, publishing history – what you changed and how to test every feature with the demo account. If the letter names no feature, ask which screen raised the concern. If you believe App Review misread the app, appeal to the App Review Board or request a 30-minute App Review appointment.
Replit's publishing docs suggest pasting reviewer notes into Agent and fixing "the smallest issue that caused it". That works for a missing privacy detail. For a 5.6 flag it falls short: Apple questions consistency, so a clear explanation matters more than a quick patch – and a broad Agent rework right before resubmission produces exactly the kind of change Apple watches for.
- Don't resubmit unchanged or open a second developer account; Apple terminated 193,000 accounts over fraud concerns in 2025.
- Don't publish the "real" version after approval. Apple removed nearly 59,000 apps for bait-and-switch maneuvers in 2025.
- Don't submit from someone else's account. If an agency built your Replit app, publish it in your own developer account – Guideline 4.2.6 expects the content owner to submit.
appsubmitter.io can carry this for you: an App Specialist checks the Replit app with AI-powered pre-submission checks, prepares the review notes and handles the conversation with App Review in your own developer account. Code changes are quoted separately if needed. Book a free consultation call or the iOS service.
Template: how to reply to App Review
Adapt this template to your situation. Keep it factual, short and specific – and only claim what you have actually changed.
Checklist before you resubmit
- The app and the review notes use your custom domain – no replit.dev development URL and no Starter-plan deployment.
- The deployment is public; no Replit sign-in or shared password stands between the reviewer and your app.
- A Reserved VM or a native loading state – such as WebViewGold's loading indicator – prevents blank screens after idle periods.
- The review account exists in the production user store, signs in with email and password and has realistic data.
- Every sign-in provider shown in the app is enabled in production, with your own OAuth credentials.
- Google sign-in never runs inside the WebView, and Sign in with Apple is offered next to it.
- No deployment secret switches features on or off for app users.
- Nothing with new functionality was published between submission and decision.
- The "Made with Replit" badge is gone, and the sign-in screen shows your brand.
- The Notes for Review list every feature with its location and test steps.
Frequently asked questions
Is Apple rejecting apps because they were built with Replit?
Why was my Replit app rejected under Guideline 5.6 if nothing is hidden?
Which Replit deployment type should an App Store app use?
Can I keep using Replit Agent after my app is approved?
Should I use Replit Auth or Clerk for an App Store app?
Can WebViewGold prevent a 5.6 rejection of my Replit app?
Recommended solution
From WebView rejection to approval: WebViewGold + appsubmitter.io
- 1 Build with WebViewGold Turn your website into native iOS and Android projects.
- 2 Add native value Push, offline screen, deep links or scanning in your main flow.
- 3 We submit it Our App Specialists submit and talk to the review team.
WebViewGold is made by our team (jocapps GmbH). It is a tool, not a guarantee – approval decisions are made by Apple and Google.
Sources and further reading
- Apple – App Store Review Guidelines, 5.6 Developer Code of Conduct
- Apple Newsroom – App Store fraud prevention in 2025 (May 20, 2026)
- 9to5Mac – Apple pushing back on vibe coding iPhone apps (March 18, 2026)
- 9to5Mac – Replit ships its first iOS update in four months (May 15, 2026)
- Replit forum – Apple's App Store enforcement and Replit submissions (April 2026)
- Replit Docs – Development URLs
- Replit Docs – Clerk Auth: Development and Production environments
- Replit Docs – Who can access your app
Store policies and third-party products change regularly – always check the current versions. This article is independent advice and not affiliated with or endorsed by Apple, Google or any other company or product mentioned; all trademarks belong to their owners. WebViewGold and appsubmitter.io are made by our team at jocapps GmbH.