Licences by country
What each store asks for per market, how the attestation console turns your licences into the app's country lists, and why an empty table serves nobody.
The two tests
Apple 3.1.5(iii) — an app may facilitate cryptocurrency transactions "only in countries or regions where the app has appropriate licensing and permissions to provide a cryptocurrency exchange." Every storefront you leave enabled is a claim that you are licensed there.
Google Play has enforced its crypto exchange and wallet policy since 29 October 2025. Play asks for the licence per country, through the Financial features declaration, and narrows or removes an app whose targeting outruns its evidence.
Neither test is about your build. They are about your markets.
Roughly what is asked for where
Check the current policy text before you rely on any of this; lists change and this one is a shape, not a citation.
| Market | Typically asked for |
|---|---|
| United States | FinCEN MSB registration and a money transmitter licence in each state served. State-by-state, not federal-only. |
| European Union | MiCA authorisation as a Crypto-Asset Service Provider, passported to the member states you serve. |
| United Kingdom | FCA registration under the Money Laundering Regulations. |
| Bahrain | CBB crypto-asset services licence. |
| Canada | FINTRAC registration as an MSB; provincial requirements on top. |
| Hong Kong | SFC VATP licence. |
| Indonesia | Bappebti / OJK registration. |
| Israel | Capital Markets Authority licence. |
| Japan | FSA registration as a Crypto Asset Exchange Service Provider. |
| Philippines | BSP Virtual Asset Service Provider licence. |
| South Africa | FSCA Crypto Asset Service Provider licence. |
| South Korea | FIU VASP registration. |
| Thailand | SEC digital asset business licence. |
| United Arab Emirates | VARA (Dubai) or the relevant free-zone authority. |
Recording them: the attestation console
Admin → System → Attestations. One row per (module, country): the entity that holds the licence, the regulator, the licence number and the expiry.
Three things follow from that table:
- A regulated module reaches only residents of a country in it. Residence comes from approved KYC, falling back to the profile — deliberately not from an IP address, which a VPN changes.
- An empty table reaches nobody. Default-deny is the point, and it is the expensive direction: a fresh install shows customers fewer modules until you fill this in.
- Expiry is enforced the day it lapses. No grace period.
The console also emits your Apple storefront list and your Play country targeting list from the same rows, so the three cannot drift apart. Use them when you configure availability in App Store Connect and Play Console — see Country targeting.
The module that needs more than a licence
Futures and token offerings are also caught by Apple 3.1.5(iv), which asks what kind of institution you are rather than where you are licensed. See Before you buy.