How to publish a Python app to the Microsoft Store

Python doesn't have a Store packager of its own, so you do it in two parts. First you freeze the app into a folder with an .exe using PyInstaller, Nuitka or Briefcase. Then you turn that into an MSIX, either by adding a manifest and running MakeAppx or by converting an installer with the MSIX Packaging Tool. You reserve the name and make the first submission in Partner Center, and after that StoreFast can publish each new .msix for you.

Freeze the app with PyInstaller in one-folder mode, add an AppxManifest.xml and pack it with MakeAppx. Make the first submission in Partner Center, then send each new .msix to StoreFast from the dashboard, CI or a coding agent.

  • PyInstaller and Nuitka make a Windows .exe and its files, but neither one's docs mention MSIX or the Store.
  • Briefcase builds an MSI by default, which you can submit as an MSI listing or convert to an MSIX.
  • An MSIX needs a manifest with the identity Partner Center gives you, and one MakeAppx command.
  • You don't need a trusted certificate for an MSIX, because Microsoft re-signs Store packages.

Which tools should you use?

ToolWhat it builds on WindowsHow you get to the Store
PyInstallerA folder with your .exe (default) or a single .exePack the folder into an MSIX with MakeAppx
NuitkaPython compiled to C, as a standalone folder or a single filePack the folder into an MSIX with MakeAppx
BriefcaseAn MSI made with WiX (default) or a ZIPSubmit the MSI, or convert it with the MSIX Packaging Tool

MSIX is the route this guide covers, since Microsoft signs and hosts the package and the Store handles updates. If you'd rather list Briefcase's MSI as it is, you host it at a versioned HTTPS URL and sign it yourself. The EXE or MSI vs MSIX guide compares the two.

Freeze the app

With PyInstaller, build on Windows in one-folder mode, which is the default. --windowed stops a console window from opening for a GUI app, and the result lands in dist.

pyinstaller --windowed --name MyApp --icon app.ico main.py
# dist\MyApp\MyApp.exe and the files it needs

PyInstaller also has --onefile, but its docs say a one-file app unpacks itself into a temporary folder at every launch and starts a little slower. Inside an MSIX that buys you nothing, so keep the folder.

Nuitka compiles your Python to C. Its --mode=standalone option makes a folder that runs without a Python install, and you pack that folder the same way. With Briefcase, briefcase package windows builds an MSI, and the next section covers what to do with it.

Before you package, go through Microsoft's preparation checklist. Packaged apps can't require elevation, and writing to the install folder isn't supported. A frozen app that keeps settings or logs next to its .exe has to move them to the user's app data folder.

How to publish the first version

  1. 1

    Reserve the name

    In Partner Center, click New product, choose MSIX or PWA app and reserve your app's name. Then open Product identity under Product management and copy Package/Identity/Name, Package/Identity/Publisher and PublisherDisplayName.

  2. 2

    Write the manifest

    Copy your dist\MyApp folder to a staging folder, put your logos in an images folder inside it and add an AppxManifest.xml based on Microsoft's manual packaging template. Executable points at the .exe PyInstaller or Nuitka built.

    <?xml version="1.0" encoding="utf-8"?>
    <Package
      xmlns="http://schemas.microsoft.com/appx/manifest/foundation/windows10"
      xmlns:uap="http://schemas.microsoft.com/appx/manifest/uap/windows10"
      xmlns:uap10="http://schemas.microsoft.com/appx/manifest/uap/windows10/10"
      xmlns:rescap="http://schemas.microsoft.com/appx/manifest/foundation/windows10/restrictedcapabilities">
      <Identity Name="(Package/Identity/Name from Partner Center)"
                Publisher="(Package/Identity/Publisher from Partner Center)"
                Version="1.2.0.0" ProcessorArchitecture="x64" />
      <Properties>
        <DisplayName>My App</DisplayName>
        <PublisherDisplayName>(PublisherDisplayName from Partner Center)</PublisherDisplayName>
        <Logo>images\StoreLogo.png</Logo>
      </Properties>
      <Resources>
        <Resource Language="en-us" />
      </Resources>
      <Dependencies>
        <TargetDeviceFamily Name="Windows.Desktop" MinVersion="10.0.19041.0" MaxVersionTested="10.0.26100.0" />
      </Dependencies>
      <Capabilities>
        <rescap:Capability Name="runFullTrust" />
      </Capabilities>
      <Applications>
        <Application Id="MyApp" Executable="MyApp.exe"
          uap10:RuntimeBehavior="packagedClassicApp" uap10:TrustLevel="mediumIL">
          <uap:VisualElements DisplayName="My App" Description="My App"
            Square150x150Logo="images\Square150x150Logo.png"
            Square44x44Logo="images\Square44x44Logo.png" BackgroundColor="#464646" />
        </Application>
      </Applications>
    </Package>

    The identity values are case-sensitive, and spaces and punctuation have to match Partner Center too. If they don't, the upload fails with an identity error, which the package identity guide covers. The fourth number of the version is reserved for the Store and stays 0, the first can't be 0, and none can go above 65535.

    The uap10 attributes need Windows 10 version 2004 (build 19041) or later, which is why MinVersion is 10.0.19041.0. A full-trust desktop app like a frozen Python app declares runFullTrust.

  3. 3

    Pack it

    MakeAppx comes with the Windows SDK. Point it at the staging folder and it writes the .msix. You can try the app first by registering the folder, without signing anything.

    # try it from the folder, before packing
    Add-AppxPackage -Register staging\AppxManifest.xml
    
    MakeAppx pack /d staging /p MyApp_1.2.0.0_x64.msix
  4. 4

    Make the first submission

    Start a submission in Partner Center, fill in pricing and availability, properties, age ratings and the Store listing, and upload the .msix on the Packages page. Because the package declares runFullTrust, a restricted capability, Partner Center asks you to explain why the app needs it. Then submit it for certification.

If you start from Briefcase's MSI

The MSIX Packaging Tool repackages an MSI or EXE installer as an MSIX without the source code. It needs Windows 10 version 1809 or later and admin rights, and Microsoft suggests running it on a clean machine or virtual machine because it builds the package from what the install changes.

Choose Application package, point it at the MSI and enter the Name, Publisher and Publisher display name from Partner Center with a version that ends in 0. Run the app once on the Manage first launch tasks page, then save the .msix. You repeat the conversion for each new release, so for regular updates it's less work to pack Briefcase's app folder with MakeAppx as in step 3.

Do you need a certificate?

Not a trusted one. Microsoft's package requirements say the Store replaces the signature on an MSIX with a Microsoft certificate after certification. MakeAppx doesn't sign, and the Store doesn't need you to. If you sign test builds to install them on other machines, a self-signed certificate whose subject matches the Publisher in your manifest is enough.

How to publish updates with StoreFast

Once the first version is live, connect your Partner Center account to StoreFast and your app shows up on the dashboard. For each release, freeze the app again, raise the version in AppxManifest.xml, pack one .msix and send it in one of these ways.

  • Drop it on your app's page in StoreFast. It reads the package name and version on your computer, translates What's new into every listing language and submits the update.
  • Add the StoreFast GitHub Action, legendaryspy/storefast-publish@v1, after your build step. The GitHub Actions guide covers the secrets and the workflow.
  • Call the REST API from any other CI system.
  • Ask a coding agent connected to the StoreFast MCP server. It shows you the update and waits for your yes before it submits.
- name: Freeze and pack
  shell: pwsh
  run: |
    pip install -r requirements.txt pyinstaller
    pyinstaller --windowed --name MyApp --icon app.ico main.py
    Copy-Item -Recurse dist\MyApp staging
    Copy-Item -Recurse packaging\* staging   # AppxManifest.xml and images
    MakeAppx pack /d staging /p MyApp_x64.msix

- name: Publish to the Microsoft Store
  uses: legendaryspy/storefast-publish@v1
  with:
    api-key: ${{ secrets.STOREFAST_API_KEY }}
    app: 9PJWF4W8V4WG
    package: MyApp_x64.msix

StoreFast takes a single .msix and doesn't accept .msixupload or .msixbundle files yet. The .msix you send replaces the packages in the last submission. The MSIX update guide covers version rules and the upload errors Partner Center gives, and the Tauri guide walks through the same MakeAppx route for another kind of app.

Who it's for

StoreFast is a good fit if

  • Your Python app is in the Store as an MSIX and you ship updates often.
  • Your listing has several languages and you want What's new in all of them.
  • You release from GitHub Actions, another CI system or a coding agent.

Look elsewhere if

  • Your app isn't in the Store yet. Make the first submission in Partner Center.
  • You list Briefcase's MSI as it is. StoreFast publishes MSIX packages only for now.
  • You need several architectures in every update. StoreFast sends one .msix for now.

Questions

Can PyInstaller build an MSIX?
No. PyInstaller makes a folder with an .exe in it, or a single .exe, in its dist folder. To get an MSIX, you add a package manifest to that folder and pack it with MakeAppx from the Windows SDK.
Does Briefcase make MSIX packages for the Microsoft Store?
Its Windows docs don't mention MSIX or the Store. briefcase package windows builds an MSI installer with the WiX Toolset by default, or a ZIP with -p zip. You can submit that MSI as an MSI listing, convert it to an MSIX with the MSIX Packaging Tool, or pack Briefcase's app folder with MakeAppx yourself.
Should I use one-folder or one-file mode?
One-folder, which is PyInstaller's default. The MSIX already gives users one app to install, so a single .exe doesn't buy you anything, and PyInstaller says one-file apps start a little slower because they unpack themselves into a temporary folder each time.
Do I need a code signing certificate?
Not a trusted one for an MSIX. Microsoft re-signs MSIX packages with its own certificate after certification. If you submit an MSI or EXE installer instead, you sign it yourself with a certificate from a CA in the Microsoft Trusted Root Program.
Can StoreFast publish my Python app?
Yes, if you ship it as an MSIX, from the second release on, as one .msix per update. You make the first submission in Partner Center, then publish updates from the dashboard, the GitHub Action, the API or a coding agent. EXE and MSI listings aren't supported yet.

Publish your app's next update

Make your first submission in Partner Center, connect it to StoreFast and drop the next .msix on the page. Try it free for 7 days, no card needed.

Sources

Facts about Microsoft's tools were checked against these pages on October 5, 2026.