Symptom
A backend keyed by MAC address works with Android and Linux gateways, but the iOS app can't find the matching device. Or the "same" device shows up with a different ID on every iPhone.
Why
- Core Bluetooth gives apps a system-generated UUID (
CBPeer.identifier), not the Bluetooth address. - That UUID is assigned on each iPhone/Mac. Two phones see two different IDs for the same peripheral. It is useful for reconnecting from the same phone (
retrievePeripherals(withIdentifiers:)), nothing more. - Separately, devices using privacy (resolvable private addresses) change their address periodically anyway, so MAC-based identity also breaks on other platforms.
Fix: carry your own identity
Choose one:
- Manufacturer-specific data in advertising. Include a short device ID (or a hash of it) after your company ID. Visible to scanners without connecting. Mind the 31-byte legacy advertising limit.
- A read-only GATT characteristic with the serial number or device UUID. Requires a connection, keeps advertising small.
- Standard Device Information Service (serial number string) if you already expose DIS.
For provisioning flows, show the ID printed on the device (QR code) and match it against the advertised ID instead of asking users to pick a MAC from a list.
Treat anything identifying in advertising as public: don't advertise secrets, and consider rotating or encrypting IDs if tracking is a concern.