macOS notarization with asc — archive, export, submit, staple
Step-by-step xcodebuild + asc workflow to Developer ID-sign and Apple-notarize macOS apps, zips, dmgs and pkgs — with trust-settings and signature troubleshooting
- What
- Step-by-step xcodebuild + asc workflow to Developer ID-sign and Apple-notarize macOS apps, zips, dmgs and pkgs — with trust-settings and signature troubleshooting
- Cost
- Free
- Needs
- macOS with Xcode and command line tools installed; asc CLI installed and authenticated (asc auth login or ASC_* env vars — saved in the secure vault); a Developer ID Application certificate in the local keychain (requires Apple Developer Program membership — created at developer.apple.com, not via API)
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @rorkai's step-by-step skill for notarizing macOS apps for distribution outside the App Store. The workflow runs: preflight (verify a Developer ID Application identity exists in the keychain, inspect trust settings read-only), archive with `xcodebuild`, export with Developer ID signing via an ExportOptions plist, verify the exported signature and timestamp chain strictly (never re-sign as a diagnostic step), create the notarization ZIP with `ditto`, submit with `asc notarization submit` (fire-and-forget or `--wait` with custom polling and upload timeouts), check status and fetch the developer log on failure, then staple the ticket (including DMG/PKG variants — PKG needs the separate Developer ID Installer certificate). Includes troubleshooting for the classic failures (invalid trust settings, unsigned nested binaries, missing hardened runtime, missing secure timestamp) and cautions against destructive "fixes" like removing trust overrides without authorization. MIT-licensed. Honest caveats: macOS-only and Xcode-dependent by nature; you need an Apple Developer Program membership and a Developer ID certificate in the local keychain — the API cannot create those, and signing identities live on your machine, not in the cloud; notarization submissions hit Apple's servers, so expect real waiting time. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: macOS with Xcode and command line tools installed; asc CLI installed and authenticated (asc auth login or ASC_* env vars — saved in the secure vault); a Developer ID Application certificate in the local keychain (requires Apple Developer Program membership — created at developer.apple.com, not via API) Install "macOS notarization with asc — archive, export, submit, staple" for me. It gives my agent @rorkai's step-by-step workflow: preflight signing-identity checks, xcodebuild archive, Developer ID export, strict signature verification, ZIP creation, asc notarization submit (with --wait/polling options), status and log inspection, and stapling — plus DMG/PKG variants and troubleshooting for classic notarization failures. MIT-licensed. Repository: https://github.com/rorkai/app-store-connect-cli-skills/blob/main/skills/asc-notarization/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "asc-notarization". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install Xcode and the asc CLI, authenticate asc, and have my Developer ID certificate in the keychain — never share private keys in chat). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.