You definitely need a secret key to sign your application. The person creating the certificate will have to export the certificate from the key fob (including the private key part) and transfer it to you.
Of course, the best solution would be if you could be added to the team and request your own certificate. But this is only possible for the company account, and not if you are registered as a separate developer.
source share