Submitting a Mac app to the Mac App Store from the terminal
Listing an app on the official Mac App Store has different technical and policy requirements than distributing it directly on the web.
Web distribution uses Developer ID Application certificates and notarytool. For the Mac App Store, Apple requires:
- Mandatory App Sandbox (configured via an
.entitlementsfile). - Mac App Distribution / Installer certificates (not Developer ID).
- A packaged signed installer (
.pkg) uploaded to App Store Connect.
You can do the entire submission locally from the terminal, without opening Xcode.
Before you start
An app built for direct download usually isn't ready for the Mac App Store as is. Check that your bundle has:
- An app icon. App Store Connect rejects builds without one.
LSApplicationCategoryTypeinInfo.plist(for examplepublic.app-category.productivity), so Apple knows where to list the app.CFBundleVersionandCFBundleShortVersionString. Every upload needs a build number higher than the last one.- An embedded provisioning profile. Create a Mac App Store profile for your app's bundle ID in the Apple Developer portal, download it, and copy it into the bundle as
MyApp.app/Contents/embedded.provisionprofilebefore you sign. - A unique bundle identifier registered to your developer account, and a matching app record in App Store Connect.
You also need a paid Apple Developer Program membership.
Step 1: Create an App Sandbox entitlements file
All Mac App Store apps must run in Apple's sandbox. Create a file named MyApp.entitlements:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>com.apple.security.app-sandbox</key>
<true/>
<key>com.apple.security.network.client</key>
<true/>
</dict>
</plist>
Step 2: Sign the app and package it into a .pkg
You need two certificates from your Apple Developer account installed in Keychain:
Apple Distribution(or3rd Party Mac Developer Application)Mac Installer Distribution(or3rd Party Mac Developer Installer)
Then run two commands:
# 1. Sign the .app bundle with the sandbox entitlements
codesign --deep --force --options runtime \
--entitlements MyApp.entitlements \
--sign "Apple Distribution: Your Name (TEAMID)" \
MyApp.app
# 2. Package the app into an App Store installer package
productbuild --component MyApp.app /Applications \
--sign "Mac Installer Distribution: Your Name (TEAMID)" \
MyApp.pkg
Step 3: Upload to App Store Connect
Upload the .pkg using Apple's built-in altool or the official Transporter app:
xcrun altool --upload-app -f MyApp.pkg \
--type macos \
--apiKey "YOUR_KEY_ID" \
--apiIssuer "YOUR_ISSUER_UUID"
Alternatively, drag and drop MyApp.pkg directly into the free Transporter app from the Mac App Store.
Step 4: Submit in App Store Connect
Once Apple finishes processing the upload:
- Log in to appstoreconnect.apple.com.
- Click My Apps > + (New App) > select macOS.
- Attach the uploaded build.
- Fill in the standard metadata: screenshots, description, age rating, and privacy disclosures.
- Click Submit for Review.
Which route should you choose?
- Web distribution: the best default. No sandbox constraints, no Apple Review, and you can share or sell the app immediately through Gumroad, Stripe, or a direct download.
- Mac App Store: the right choice when you want Apple's storefront and are willing to accept the sandbox and the review process.