Sign and notarize your app in 3 steps
Apps from silicondevkit.com are ready to run, but they are ad-hoc signed and not notarized. That is fine for trying an app on your own Mac. If you want to share it with other people without scary macOS warnings, you sign and notarize it yourself, on your own Mac, with your own Apple Developer account. This post shows how, in three steps.
Why you see a warning
When you download an app from the web, macOS tags it as quarantined. Gatekeeper then checks whether Apple has seen and approved the app. An app that is signed with a Developer ID certificate and notarized by Apple opens normally. An ad-hoc signed app does not, and macOS shows "Apple cannot check it for malicious software".
You can always open your own app anyway: open System Settings → Privacy & Security, scroll down and click Open Anyway. The rest of this post is for when you want to hand the app to other people.
What you need
- A Mac.
- A paid Apple Developer Program membership ($99 per year).
- A Developer ID Application certificate installed in your Keychain. Create it in the Certificates, Identifiers & Profiles section of the Apple Developer site.
- Notary credentials stored in your Keychain. You only do this once:
xcrun notarytool store-credentials "AC_PASSWORD" \
--apple-id "you@example.com" \
--team-id "YOURTEAMID" \
--password "your-app-specific-password"
Use an app-specific password, not your Apple ID password.
The 3 steps
1. Download and unzip. Unzip the app you downloaded into a folder. Download sign.sh into the same folder.
2. Run the script. In Terminal, in that folder:
chmod +x sign.sh && ./sign.sh
Choose 1 to sign and notarize for sharing. The script finds your Developer ID certificate, signs the app with the hardened runtime, sends it to Apple, waits for the result and staples the ticket to the app. Choose 2 if you only want to run the app on your own Mac. That option clears the quarantine flag and needs no Apple account.
3. Share it. Zip the app and send it, host it, or sell it. It opens without a Gatekeeper warning.
The script
Read it before you run it. It is short, and it only runs codesign, ditto, notarytool and stapler on the app in your folder:
#!/usr/bin/env bash
# sign.sh - sign (and optionally notarize) an app from silicondevkit.com on your own Mac.
# Usage: ./sign.sh [YourApp.app] (run it in the folder that contains the app)
set -euo pipefail
APP="${1:-}"
if [ -z "$APP" ]; then
APP="$(ls -d ./*.app 2>/dev/null | head -n 1 || true)"
APP="${APP#./}"
fi
if [ -z "$APP" ] || [ ! -d "$APP" ]; then
echo "Could not find an .app here. Run this in the folder that contains your app,"
echo "or pass the app: ./sign.sh YourApp.app"
exit 1
fi
echo "App: $APP"
echo
echo " 1) Sign and notarize for sharing (needs a paid Apple Developer account)"
echo " 2) Just run it on this Mac (testing only, no Apple account needed)"
echo
read -r -p "Choose 1 or 2: " choice
if [ "$choice" = "2" ]; then
xattr -cr "$APP"
codesign --force --deep --sign - "$APP"
echo "Done. You can open $APP on this Mac now."
exit 0
fi
CERT="$(security find-identity -v -p codesigning | grep "Developer ID Application" | head -n 1 | awk -F'"' '{print $2}' || true)"
if [ -z "$CERT" ]; then
echo "No \"Developer ID Application\" certificate found in your Keychain."
echo "Create one at developer.apple.com (Certificates, Identifiers & Profiles),"
echo "install it, and run this again. Or choose option 2 to test locally."
exit 1
fi
echo "Signing with: $CERT"
codesign --force --deep --options runtime --timestamp --sign "$CERT" "$APP"
ZIP="${APP%.app}-notarize.zip"
ditto -c -k --keepParent "$APP" "$ZIP"
read -r -p "Notary keychain profile name [AC_PASSWORD]: " PROFILE
PROFILE="${PROFILE:-AC_PASSWORD}"
echo "Submitting to Apple. This usually takes 1-5 minutes..."
xcrun notarytool submit "$ZIP" --keychain-profile "$PROFILE" --wait
rm -f "$ZIP"
xcrun stapler staple "$APP"
spctl --assess --type execute --verbose "$APP" || true
echo "Done. $APP is signed and notarized."
Notes
- Your certificate and notary credentials stay in your own Keychain. silicondevkit.com never sees them. See Why we don't sign apps for you.
- Notarization usually takes one to five minutes.
- To put an app on the Mac App Store instead, you need different certificates and a sandbox. See Submitting a Mac app to the Mac App Store from the terminal.