The team that kept CodePush alive after Microsoft retired it has shipped its replacement: a complete self-hosted OTA platform with a dashboard, CDN-scale delivery, binary diffs, and fingerprint compatibility check.
Codemagic, the mobile CI/CD company, has released Codemagic Patch, a self-hosted over-the-air (OTA) update platform for React Native.
In case you don't know what OTA updates are, they let you ship JavaScript updates to users' devices without waiting for app-store reviews.
After Microsoft retired App Center and CodePush in March 2025, Codemagic maintained a CodePush fork for 18 months and served billions of updates through it.
That experience convinced the team that CodePush needed a full rewrite:
- Each device sent daily requests to the server, so new architecture was needed to shift that to the CDN.
- Only file-level diffs were enabled, whereas switching to binary diffs could mean much smaller downloads.
- Fingerprinting was missing, so checks were needed to stop incompatible updates from being released.
- Dashboards were limited, with opportunities to give much better release control and monitoring.
- The CLI was pretty clunky, while a more interactive approach would help with both setup and releases.
"We decided it was time for an overhaul," wrote Codemagic's Zach Goldie in the launch announcement.
Patch is that overhaul, rewritten from scratch and available on GitHub.
👉 Codemagic Patch
What Ships in CodeMagic Patch
Codemagic Patch consists of an update server with a release worker, a React Native SDK with an Expo config plugin, the cmpatch command-line tool, and a web dashboard.
The default deployment runs on a single Docker host, with PostgreSQL holding control-plane data and MinIO or any S3-compatible storage holding release artefacts.
A local evaluation stack runs the same server, worker, database, storage and dashboard through Docker Compose, and requires Docker with Compose v2 and Node.js 22 or newer.
The dashboard is the piece self-hosting teams have historically gone without.
Teams manage apps and their Staging and Production deployments, and inspect each release's target binary version, native fingerprint, rollout percentage, package signature, processing status, and adoption metrics.
From the same screen, teams can promote, disable, or roll back releases.
Update Checks without the Server
Most over-the-air update tools work the same way.
Each device makes a daily request to a server to check for updates.
For small apps, this is fine, but at scale it becomes a problem.
Thousands of devices hammering a single endpoint every day burns bandwidth, strains infrastructure, and adds latency to the update check itself.
Patch takes a different approach.
When a release is published, the CLI bundles the JavaScript, hashes the native project into a fingerprint, resolves the target binary version, and uploads the release. The release worker then writes small static manifest files to object storage.
Devices fetch those manifests directly from storage, or from a CDN placed in front of it, and decide locally what to download. The manifest path encodes the deployment key, the binary version, and the hash of the bundle a device is currently running, so Patch can return the correct full bundle or, where one exists, a binary diff computed against that exact version.
If the manifest file exists, a newer bundle is available.
If it returns a 404, the device is already current.
Every device on the same deployment, binary version and bundle asks for the same path, so one device warms the cache and the rest are served by the CDN rather than the server.
The result is that update checks, the highest-volume operation any OTA system performs, are answered by static files at the edge.

At 1,000 Requests per Second
Codemagic supplied a load test comparing Patch's manifest delivery through Cloudflare R2 against HotUpdater's default Cloudflare setup, a Cloudflare Worker and a D1 database on the check path.
In a fixed test at 1,000 requests per second, the Patch configuration completed all 6,331 requests. The tested HotUpdater configuration completed 564, with the remaining 5,767 queued.
The benchmark was created and run by Codemagic, it is not independent, and it measures one specific HotUpdater configuration. HotUpdater is plugin-based and can also store its metadata as JSON in S3 served through CloudFront.
The test demonstrates something narrower but still meaningful.
That answering update checks from static files at the edge scales in a way a per-request compute path does not.
Rollouts, Rollback, and Guardrails
Releases can be rolled out gradually, starting at a chosen percentage of users and expanding as adoption metrics come in.
Native fingerprinting guards against the classic OTA failure of shipping a JavaScript bundle to an incompatible binary: every release records a hash of the native project and a target binary version, and devices receive updates only if they match both.
When sync() runs, it marks the current bundle as healthy. If a newly installed bundle crashes before reaching that point, the SDK automatically restores the previous known-good bundle on the next launch.
Pricing
Codemagic Patch is free to self-host up to one million monthly active users.
Above that, licensing is banded: $990 per million users per year up to 50 million, $750 per million between 50 and 100 million, and $500 per million above that, with each slice billed at its band's rate.
Commercial licenses include a dedicated Slack channel with the Codemagic team, and Codemagic can host Patch on a company's behalf on request.
Comparing OTA pricing means comparing a license, a subscription, and a repository.
The first table separates what each product is selling; the second puts numbers on it.
| Codemagic Patch | HotUpdater | Expo EAS Update | |
|---|---|---|---|
| Who runs the servers | You | You | Expo |
| What it is | Complete stack: server, worker, dashboard, CLI, SDK | Kit: plugins for the storage, database and hosting you pick | Managed update service and CDN |
| What the price buys | A license, once you pass 1M MAU | Nothing, it is MIT | Servers, bandwidth, operations |
| What you still pay for | Your machine, storage, CDN and ops time | Your machine, storage, CDN and ops time | Bandwidth beyond plan limits |
| License | Codemagic server licence, free below 1M MAU | MIT | Proprietary service |
The second shows the annual licence bill at two sizes, at published list prices.
| Monthly active users | Codemagic Patch licence | Expo EAS Update (Production) |
|---|---|---|
| 100,000 | $0 (free up to 1M) | About $5,400 ($199 + 50,000 × $0.005) |
| 1,000,000 | $0 (free up to 1M) | About $45,300 ($199 + graduated overage) |
| 5,000,000 | $3,960 (4M above the free million × $990) | About $163,000 |
The Patch figures are licence cost only.
The server, storage, CDN traffic, and the time to operate them come on top, and they are not zero. At a million users pulling a 5 MiB bundle, that is roughly five terabytes of egress a month, which is free on Cloudflare's edge and about $415 on CloudFront at $0.085 per GB, plus one modest server.
The EAS figures use Expo's published Production plan ($199 per month) plus its graduated overage schedule, which starts at $0.005 per user above 50,000 and declines through bands as volume rises.
These figures don't include bandwidth because it is usually covered: every user beyond the plan allowance adds 40 MiB to the bandwidth quota, which is more than most apps consume. Only users who receive an update in a given month are counted, so real invoices depend on release cadence.
Teams at a million users would typically be quoted Expo's Enterprise plan rather than Production, and MAU definitions differ slightly between vendors, so treat these as list-price comparisons rather than quotes.
Availability
Codemagic Patch is available now.
The source code, documentation, self-host installer, and local evaluation stack are at github.com/codemagic-ci-cd/codemagic-patch.
About Codemagic
Codemagic is a CI/CD platform built for mobile teams, supporting React Native, Flutter, native iOS, and native Android projects. Companies including Toyota, Schneider Electric, and Boston Consulting Group build with Codemagic. Codemagic is operated by Nevercode Ltd.
This press release was published in partnership with Codemagic.
