
Asc Notarization
- 2.1k installs
- 934 repo stars
- Updated July 21, 2026
- rudrankriyam/app-store-connect-cli-skills
asc-notarization is an agent skill for archiving, signing, and notarizing macOS apps with xcodebuild and asc for Developer ID distribution.
About
asc-notarization guides agents through macOS app notarization for distribution outside the Mac App Store using xcodebuild archive and export plus the asc CLI. Preconditions include Xcode command line tools, asc auth login or ASC env vars, a Developer ID Application certificate in the keychain, and a macOS-targeting Xcode scheme. The workflow covers preflight identity verification with security find-identity, fixing broken trust settings that cause errSecInternalComponent, validating the signing chain through Developer ID Application to Apple Root CA, archiving with xcodebuild, exporting with a Developer ID ExportOptions plist, submitting the app for notarization via asc, stapling tickets, and verifying gatekeeper acceptance. It documents common failure modes around custom trust overrides, missing certificates, and runtime hardening options. Use when shipping signed macOS binaries to customers who download directly rather than through the App Store.
- Walks xcodebuild archive and Developer ID export with automatic signing teamID plist.
- Documents asc auth, notarization submit, staple, and Gatekeeper verify steps.
- Covers broken trust settings fixes via security dump-trust-settings and remove-trusted-cert.
- Requires Developer ID Application certificate preflight before archive.
- Targets non-App Store macOS distribution with hardened runtime options.
Asc Notarization by the numbers
- 2,117 all-time installs (skills.sh)
- +20 installs in the week ending Jul 28, 2026 (Skillselion tracking)
- Ranked #20 of 257 Release Management skills by installs in the Skillselion catalog
- Security screen: MEDIUM risk (skills.sh audit)
- Data as of Jul 28, 2026 (Skillselion catalog sync)
asc-notarization capabilities & compatibility
- Capabilities
- developer id preflight checks · xcodebuild archive and export · asc notarization submit and staple · trust settings remediation · gatekeeper verification
- Use cases
- ci cd · orchestration
What asc-notarization says it does
Use this skill when you need to notarize a macOS app for distribution outside the App Store.
security find-identity -v -p codesigning | grep "Developer ID Application"
The signing must show the chain: Developer ID Application → Developer ID Certification Authority → Apple Root CA.
npx skills add https://github.com/rudrankriyam/app-store-connect-cli-skills --skill asc-notarizationAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 2.1k |
|---|---|
| repo stars | ★ 934 |
| Security audit | 1 / 3 scanners passed |
| Last updated | July 21, 2026 |
| Repository | rudrankriyam/app-store-connect-cli-skills ↗ |
How do I notarize a macOS app for direct download distribution outside the App Store?
Archive, export, and notarize macOS apps with xcodebuild, Developer ID signing, and asc notarization for non-App Store distribution.
Who is it for?
macOS developers distributing signed apps with Developer ID and Apple notarization.
Skip if: Skip for iOS App Store submission or Windows cross-platform builds.
When should I use this skill?
User needs macOS notarization, Developer ID export, or asc notarize workflow.
What you get
A stapled, Gatekeeper-approved macOS app bundle ready for non-App Store release.
- Notarized macOS app
- Stapled notarization ticket
By the numbers
- Five-step archive export notarize staple verify flow
Files
macOS Notarization
Use this skill when you need to notarize a macOS app for distribution outside the App Store.
Preconditions
- Xcode installed and command line tools configured.
- Auth is configured (
asc auth loginorASC_*env vars). - A Developer ID Application certificate in the local keychain.
- The app's Xcode project builds for macOS.
Preflight: Verify Signing Identity
Before archiving, confirm a valid Developer ID Application identity exists:
security find-identity -v -p codesigning | grep "Developer ID Application"If no identity is found, create one at https://developer.apple.com/account/resources/certificates/add (the App Store Connect API does not support creating Developer ID certificates).
Fix Broken Trust Settings
If codesign or xcodebuild fails with "Invalid trust settings" or "errSecInternalComponent", the certificate may have custom trust overrides that break the chain:
# Check for custom trust settings
security dump-trust-settings 2>&1 | grep -A1 "Developer ID"
# If overrides exist, export the cert and remove them
security find-certificate -c "Developer ID Application" -p ~/Library/Keychains/login.keychain-db > /tmp/devid-cert.pem
security remove-trusted-cert /tmp/devid-cert.pemVerify Certificate Chain
After fixing trust settings, verify the chain is intact:
codesign --deep --force --options runtime --sign "Developer ID Application: YOUR NAME (TEAM_ID)" /path/to/any.app 2>&1The signing must show the chain: Developer ID Application → Developer ID Certification Authority → Apple Root CA.
Step 1: Archive
xcodebuild archive \
-scheme "YourMacScheme" \
-configuration Release \
-archivePath /tmp/YourApp.xcarchive \
-destination "generic/platform=macOS"Step 2: Export with Developer ID
Create an ExportOptions plist for Developer ID distribution:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>method</key>
<string>developer-id</string>
<key>signingStyle</key>
<string>automatic</string>
<key>teamID</key>
<string>YOUR_TEAM_ID</string>
</dict>
</plist>Export the archive:
xcodebuild -exportArchive \
-archivePath /tmp/YourApp.xcarchive \
-exportPath /tmp/YourAppExport \
-exportOptionsPlist ExportOptions.plistThis produces a .app bundle signed with Developer ID Application and a secure timestamp.
Verify the Export
codesign -dvvv "/tmp/YourAppExport/YourApp.app" 2>&1 | grep -E "Authority|Timestamp"Confirm:
- Authority chain starts with "Developer ID Application"
- A Timestamp is present
Step 3: Create a ZIP for Notarization
ditto -c -k --keepParent "/tmp/YourAppExport/YourApp.app" "/tmp/YourAppExport/YourApp.zip"Step 4: Submit for Notarization
Fire-and-forget
asc notarization submit --file "/tmp/YourAppExport/YourApp.zip"Wait for result
asc notarization submit --file "/tmp/YourAppExport/YourApp.zip" --waitCustom polling
asc notarization submit --file "/tmp/YourAppExport/YourApp.zip" --wait --poll-interval 30s --timeout 1hStep 5: Check Results
Status
asc notarization status --id "SUBMISSION_ID" --output tableDeveloper Log (for failures)
asc notarization log --id "SUBMISSION_ID"Fetch the log URL to see detailed issues:
curl -sL "LOG_URL" | python3 -m json.toolList Previous Submissions
asc notarization list --output table
asc notarization list --limit 5 --output tableStep 6: Staple (Optional)
After notarization succeeds, staple the ticket so the app works offline:
xcrun stapler staple "/tmp/YourAppExport/YourApp.app"For DMG or PKG distribution, staple after creating the container:
# Create DMG
hdiutil create -volname "YourApp" -srcfolder "/tmp/YourAppExport/YourApp.app" -ov -format UDZO "/tmp/YourApp.dmg"
xcrun stapler staple "/tmp/YourApp.dmg"Supported File Formats
| Format | Use Case |
|---|---|
.zip | Simplest; zip a signed .app bundle |
.dmg | Disk image for drag-and-drop install |
.pkg | Installer package (requires Developer ID Installer certificate) |
PKG Notarization
To notarize .pkg files, you need a Developer ID Installer certificate (separate from Developer ID Application). This certificate type is not available through the App Store Connect API — create it at https://developer.apple.com/account/resources/certificates/add.
Sign the package:
productsign --sign "Developer ID Installer: YOUR NAME (TEAM_ID)" unsigned.pkg signed.pkgThen submit:
asc notarization submit --file signed.pkg --waitTroubleshooting
"Invalid trust settings" during export
The Developer ID certificate has custom trust overrides. See the Preflight section above to remove them.
"The binary is not signed with a valid Developer ID certificate"
The app was signed with a Development or App Store certificate. Re-export with method: developer-id in ExportOptions.plist.
"The signature does not include a secure timestamp"
Add --timestamp to manual codesign calls, or use xcodebuild -exportArchive which adds timestamps automatically.
Upload timeout for large files
Set a longer upload timeout:
ASC_UPLOAD_TIMEOUT=5m asc notarization submit --file ./LargeApp.zip --waitNotarization returns "Invalid" but signing looks correct
Fetch the developer log for specific issues:
asc notarization log --id "SUBMISSION_ID"Common causes: unsigned nested binaries, missing hardened runtime, embedded libraries without timestamps.
Notes
- The
asc notarizationcommands use the Apple Notary API v2, notxcrun notarytool. - Authentication uses the same API key as other
asccommands. - Files are uploaded directly to Apple's S3 bucket with streaming (no full-file buffering).
- Files over 5 GB use multipart upload automatically.
- Always use
--helpto verify flags:asc notarization submit --help.
Related skills
Forks & variants (3)
Asc Notarization has 3 known copies in the catalog totaling 3.1k installs. They canonicalize to this original listing.
- rorkai - 2k installs
- rudrankriyam - 1.1k installs
- ehmo - 1 installs
How it compares
Use asc-notarization for Developer ID direct-download macOS releases; use App Store upload skills when distribution stays inside Apple's store channels.
FAQ
What certificates are required?
A Developer ID Application identity in the local keychain; create at developer.apple.com if missing.
How are trust errors fixed?
Remove custom trust overrides with security remove-trusted-cert after exporting the Developer ID cert.
Is asc-notarization safe to install?
Review Security Audits; it runs local signing and Apple notarization commands on your machine.