Notarize your app
Make your app open on other people’s Macs without the “Apple could not verify” warning, using your own Mac and Apple Developer account.
Just want to open your own app? See Signing and first launch.
What notarization is
Apps from SiliconDevKit are ad-hoc signed and not notarized. They run fine on the Mac you build them for, but when you send one to someone else, macOS shows "Apple could not verify this app is free of malware" and they have to approve it by hand in System Settings.
Notarization removes that warning. You sign the app with your own Apple Developer ID certificate and send it to Apple, which scans it automatically and returns a ticket. An app with that ticket opens normally on any Apple silicon Mac.
SiliconDevKit does not do this step for you yet. It has to use your certificate, so it happens on your own Mac. Your certificate and Apple credentials never leave your Keychain.
What you need
- A Mac with Xcode (or just the Command Line Tools:
xcode-select --install). - A paid Apple Developer Program membership, $99 per year. A free Apple ID cannot notarize.
- About 20 minutes the first time, and about 5 minutes for every app after that.
Step by step
1. Get a Developer ID Application certificate
The easiest way is in Xcode: Xcode → Settings → Accounts, select your team, click Manage Certificates…, click + and choose Developer ID Application.
Check that it is installed:
security find-identity -v -p codesigning
You should see a line like Developer ID Application: Your Name (ABCDE12345). The ten characters in brackets are your Team ID. Copy the whole name in quotes, you need it below.
2. Make an app-specific password
Go to account.apple.com, open Sign-In and Security → App-Specific Passwords and create one called "notarytool". Apple shows it once. Do not use your normal Apple ID password.
3. Save your notary login in the Keychain (once)
xcrun notarytool store-credentials "AC_PASSWORD" \
--apple-id "you@example.com" \
--team-id "ABCDE12345" \
--password "xxxx-xxxx-xxxx-xxxx"
This stores a profile named AC_PASSWORD so you never type the password again.
4. Unzip your app and sign it
Download your app from SiliconDevKit and open it in a folder. Then, in Terminal in that folder:
codesign --force --deep --options runtime --timestamp \
--sign "Developer ID Application: Your Name (ABCDE12345)" YourApp.app
codesign --verify --deep --strict --verbose=2 YourApp.app
--options runtime turns on the hardened runtime, which Apple requires. --timestamp is also required. The second command should end with "valid on disk".
5. Send it to Apple
ditto -c -k --keepParent YourApp.app YourApp-notarize.zip
xcrun notarytool submit YourApp-notarize.zip --keychain-profile "AC_PASSWORD" --wait
This usually takes one to five minutes. You want to see status: Accepted.
6. Staple the ticket
xcrun stapler staple YourApp.app
xcrun stapler validate YourApp.app
Stapling attaches the ticket to the app so it also opens when the Mac is offline.
7. Package it for sharing
Zip it (the quick way):
ditto -c -k --keepParent YourApp.app YourApp.zip
Or make a disk image people drag to Applications. A disk image you notarize yourself should be signed and notarized too:
mkdir dmg && cp -R YourApp.app dmg/ && ln -s /Applications dmg/Applications
hdiutil create -volname "YourApp" -srcfolder dmg -ov -format UDZO YourApp.dmg
codesign --sign "Developer ID Application: Your Name (ABCDE12345)" --timestamp YourApp.dmg
xcrun notarytool submit YourApp.dmg --keychain-profile "AC_PASSWORD" --wait
xcrun stapler staple YourApp.dmg
(The .dmg files we give you are deliberately unsigned. macOS refuses a disk image that is signed ad hoc and not notarized, but opens an unsigned one. Once you sign with a Developer ID and notarize, signing the disk image is correct.)
8. Test it like a user
Send the file to another Mac (AirDrop, or download it from a link in a browser) and open it. Or check on your own Mac:
spctl --assess --type execute --verbose YourApp.app
You want accepted and source=Notarized Developer ID.
The shortcut
sign.sh does steps 4 to 6 for you: it finds your Developer ID certificate, signs, submits, waits and staples. Download it into the folder with your app and run:
chmod +x sign.sh && ./sign.sh
Choose 1. (Choose 2 if you only want to run the app on your own Mac without an Apple account.) Read the script before you run it; it is short. The full text is in Sign and notarize your app in 3 steps.
If it fails
status: Invalid. Ask Apple why:xcrun notarytool log <submission-id> --keychain-profile "AC_PASSWORD". The submission ID is printed when you submit.- "The signature does not include a secure timestamp" or "hardened runtime is not enabled". You left out
--timestampor--options runtimein step 4. Sign again. - "No Developer ID Application certificate". The certificate is not in your login Keychain, or it is the wrong kind. Make sure it says Developer ID Application, not Apple Development.
- Notarization stays "In Progress" for a long time. Apple is sometimes slow. Check with
xcrun notarytool history --keychain-profile "AC_PASSWORD". - You changed the app afterwards (including by sending a follow-up in SiliconDevKit). Every new version is a new app: repeat steps 4 to 7.
Good to know
- This does not put your app on the Mac App Store. That needs different certificates and a sandbox. See Submitting a Mac app to the Mac App Store from the terminal.
- Our apps are built for Apple silicon only, so they will not run on Intel Macs even when notarized.
- Why we do not sign for you: Why we don't sign your apps.