How it works
On Android the key lives in a keystore file (.jks) protected by passwords. With Play App Signing, which new apps on Google Play must use, Google keeps the real app signing key and you sign uploads with a separate upload key; if the upload key is lost or leaked, Google can reset it. Before this, losing the key meant never being able to update the app again, so the keystore and its passwords still belong in a password manager and a backup, never in the code repository.
On iOS, signing uses certificates and provisioning profiles issued through the Apple Developer Program, which state which developer, which app and, for test builds, which devices. Xcode and services such as EAS can create and renew them automatically. It is the mobile counterpart of desktop code signing.
Related terms
More in Mobile apps
Publishing