Why we don't sign apps for you
When silicondevkit.com builds your app, it signs it ad hoc so it runs on a Mac. We do not sign it with a Developer ID certificate, and we do not notarize it. That is a deliberate choice.
A signature is an identity
A Developer ID signature tells macOS and the person downloading the app who published it. If we signed your apps with our certificate, every app would say it came from us, and we would be vouching for code we did not write. If you sign it with yours, it says it came from you, which is true.
Your keys stay with you
To sign or notarize on your behalf in a way that carries your name, a service has to hold your certificate's private key and your Apple API credentials. Those are valuable. We would rather not store them, and you should not have to trust a web service with them. When you sign locally, they never leave your Keychain.
What this means in practice
- Your app runs on your Mac right away, because it is ad-hoc signed.
- To share it without macOS warnings, you sign and notarize it on your own Mac. It takes one script and about five minutes. See Sign and notarize your app in 3 steps.
- To list it on the Mac App Store, you use your own App Store certificates. See Submitting a Mac app to the Mac App Store from the terminal.
- We never ask for your Apple ID, certificates or API keys.
Trade-offs
This puts a small amount of work on you. You need a Mac and a paid Apple Developer account to distribute widely, and you run one script. For apps you only use yourself, none of this is needed.
If we ever offer signing with your own credentials, we will say so here, and it will be opt-in.