Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
rorkai avatar

Asc Notarization

  • 2k installs
  • 934 repo stars
  • Updated July 21, 2026
  • rorkai/app-store-connect-cli-skills

This is a copy of asc-notarization by rudrankriyam - installs and ranking accrue to the original listing.

asc-notarization is a release skill that archives, exports, signs, and notarizes macOS apps with xcodebuild and asc for developers distributing outside the Mac App Store with Developer ID certificates.

About

asc-notarization is a skill for preparing macOS apps for distribution outside the Mac App Store using xcodebuild and the asc CLI. The workflow verifies a Developer ID Application certificate in the local keychain, archives the Xcode macOS target, exports a signed build, and submits it for Apple notarization. Preconditions include Xcode with command line tools, asc auth via asc auth login or ASC_* environment variables, and a macOS-capable Xcode project. Developers invoke asc-notarization when they need Developer ID signing and Apple notarization rather than App Store Connect upload flows.

  • Automates xcodebuild archive and export for macOS apps
  • Handles Developer ID signing and Apple notarization workflow
  • Includes preflight verification of signing identities
  • Provides troubleshooting for trust settings and certificate issues
  • Works with ASC auth via login or environment variables

Asc Notarization by the numbers

  • 2,001 all-time installs (skills.sh)
  • +215 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
npx skills add https://github.com/rorkai/app-store-connect-cli-skills --skill asc-notarization

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs2k
repo stars934
Security audit1 / 3 scanners passed
Last updatedJuly 21, 2026
Repositoryrorkai/app-store-connect-cli-skills

How do you notarize a macOS app for distribution?

Archive, export, sign, and notarize macOS apps for distribution outside the App Store using Xcode and Apple services.

Who is it for?

macOS developers shipping apps outside the Mac App Store who need automated Developer ID signing and Apple notarization via asc and xcodebuild.

Skip if: iOS App Store submission-only workflows or teams without a Developer ID Application certificate installed locally.

When should I use this skill?

The user needs to archive, export, sign, or notarize a macOS app with xcodebuild and asc for non-App Store distribution.

What you get

Archived macOS build, exported signed .app or .pkg, and Apple notarization ticket ready for distribution.

  • signed macOS app export
  • Apple notarization submission

Files

SKILL.mdMarkdownGitHub ↗

macOS Notarization

Use this skill when you need to notarize a macOS app for distribution outside the App Store.

Preconditions

  • Xcode installed and command line tools configured.
  • Auth is configured (asc auth login or ASC_* env vars).
  • A Developer ID Application certificate in the local keychain.
  • The app's Xcode project builds for macOS.

Preflight: Verify Signing Identity

Before archiving, confirm a valid Developer ID Application identity exists:

security find-identity -v -p codesigning | grep "Developer ID Application"

If no identity is found, create one at https://developer.apple.com/account/resources/certificates/add (the App Store Connect API does not support creating Developer ID certificates).

Fix Broken Trust Settings

If codesign or xcodebuild fails with "Invalid trust settings" or "errSecInternalComponent", the certificate may have custom trust overrides that break the chain:

# Check for custom trust settings
security dump-trust-settings 2>&1 | grep -A1 "Developer ID"

# If overrides exist, export the cert and remove them
security find-certificate -c "Developer ID Application" -p ~/Library/Keychains/login.keychain-db > /tmp/devid-cert.pem
security remove-trusted-cert /tmp/devid-cert.pem

Verify Certificate Chain

After fixing trust settings, verify the chain is intact:

codesign --deep --force --options runtime --sign "Developer ID Application: YOUR NAME (TEAM_ID)" /path/to/any.app 2>&1

The signing must show the chain: Developer ID Application → Developer ID Certification Authority → Apple Root CA.

Step 1: Archive

xcodebuild archive \
  -scheme "YourMacScheme" \
  -configuration Release \
  -archivePath /tmp/YourApp.xcarchive \
  -destination "generic/platform=macOS"

Step 2: Export with Developer ID

Create an ExportOptions plist for Developer ID distribution:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>method</key>
    <string>developer-id</string>
    <key>signingStyle</key>
    <string>automatic</string>
    <key>teamID</key>
    <string>YOUR_TEAM_ID</string>
</dict>
</plist>

Export the archive:

xcodebuild -exportArchive \
  -archivePath /tmp/YourApp.xcarchive \
  -exportPath /tmp/YourAppExport \
  -exportOptionsPlist ExportOptions.plist

This produces a .app bundle signed with Developer ID Application and a secure timestamp.

Verify the Export

codesign -dvvv "/tmp/YourAppExport/YourApp.app" 2>&1 | grep -E "Authority|Timestamp"

Confirm:

  • Authority chain starts with "Developer ID Application"
  • A Timestamp is present

Step 3: Create a ZIP for Notarization

ditto -c -k --keepParent "/tmp/YourAppExport/YourApp.app" "/tmp/YourAppExport/YourApp.zip"

Step 4: Submit for Notarization

Fire-and-forget

asc notarization submit --file "/tmp/YourAppExport/YourApp.zip"

Wait for result

asc notarization submit --file "/tmp/YourAppExport/YourApp.zip" --wait

Custom polling

asc notarization submit --file "/tmp/YourAppExport/YourApp.zip" --wait --poll-interval 30s --timeout 1h

Step 5: Check Results

Status

asc notarization status --id "SUBMISSION_ID" --output table

Developer Log (for failures)

asc notarization log --id "SUBMISSION_ID"

Fetch the log URL to see detailed issues:

curl -sL "LOG_URL" | python3 -m json.tool

List Previous Submissions

asc notarization list --output table
asc notarization list --limit 5 --output table

Step 6: Staple (Optional)

After notarization succeeds, staple the ticket so the app works offline:

xcrun stapler staple "/tmp/YourAppExport/YourApp.app"

For DMG or PKG distribution, staple after creating the container:

# Create DMG
hdiutil create -volname "YourApp" -srcfolder "/tmp/YourAppExport/YourApp.app" -ov -format UDZO "/tmp/YourApp.dmg"
xcrun stapler staple "/tmp/YourApp.dmg"

Supported File Formats

FormatUse Case
.zipSimplest; zip a signed .app bundle
.dmgDisk image for drag-and-drop install
.pkgInstaller package (requires Developer ID Installer certificate)

PKG Notarization

To notarize .pkg files, you need a Developer ID Installer certificate (separate from Developer ID Application). This certificate type is not available through the App Store Connect API — create it at https://developer.apple.com/account/resources/certificates/add.

Sign the package:

productsign --sign "Developer ID Installer: YOUR NAME (TEAM_ID)" unsigned.pkg signed.pkg

Then submit:

asc notarization submit --file signed.pkg --wait

Troubleshooting

"Invalid trust settings" during export

The Developer ID certificate has custom trust overrides. See the Preflight section above to remove them.

"The binary is not signed with a valid Developer ID certificate"

The app was signed with a Development or App Store certificate. Re-export with method: developer-id in ExportOptions.plist.

"The signature does not include a secure timestamp"

Add --timestamp to manual codesign calls, or use xcodebuild -exportArchive which adds timestamps automatically.

Upload timeout for large files

Set a longer upload timeout:

ASC_UPLOAD_TIMEOUT=5m asc notarization submit --file ./LargeApp.zip --wait

Notarization returns "Invalid" but signing looks correct

Fetch the developer log for specific issues:

asc notarization log --id "SUBMISSION_ID"

Common causes: unsigned nested binaries, missing hardened runtime, embedded libraries without timestamps.

Notes

  • The asc notarization commands use the Apple Notary API v2, not xcrun notarytool.
  • Authentication uses the same API key as other asc commands.
  • Files are uploaded directly to Apple's S3 bucket with streaming (no full-file buffering).
  • Files over 5 GB use multipart upload automatically.
  • Always use --help to verify flags: asc notarization submit --help.

Related skills

How it compares

Use asc-notarization for Developer ID distribution and notarization rather than App Store Connect upload skills aimed at Mac App Store releases.

FAQ

What tools does asc-notarization use for macOS distribution?

asc-notarization uses xcodebuild to archive and export macOS apps and the asc CLI for authentication and notarization submission. A Developer ID Application certificate must exist in the local keychain.

What are the preconditions for asc-notarization?

asc-notarization requires Xcode with command line tools, asc auth via asc auth login or ASC_* variables, a Developer ID Application certificate, and an Xcode project that builds for macOS.

Is Asc Notarization safe to install?

skills.sh reports 1 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Release Managementdevopsintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.