← All posts

Why we don't sign apps for you

When silicondevkit.com builds your app, it signs it ad hoc so it runs on a Mac. We do not sign it with a Developer ID certificate, and we do not notarize it. That is a deliberate choice.

A signature is an identity

A Developer ID signature tells macOS and the person downloading the app who published it. If we signed your apps with our certificate, every app would say it came from us, and we would be vouching for code we did not write. If you sign it with yours, it says it came from you, which is true.

Your keys stay with you

To sign or notarize on your behalf in a way that carries your name, a service has to hold your certificate's private key and your Apple API credentials. Those are valuable. We would rather not store them, and you should not have to trust a web service with them. When you sign locally, they never leave your Keychain.

What this means in practice

Trade-offs

This puts a small amount of work on you. You need a Mac and a paid Apple Developer account to distribute widely, and you run one script. For apps you only use yourself, none of this is needed.

If we ever offer signing with your own credentials, we will say so here, and it will be opt-in.