You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac命令行工具分发遇阻:未识别开发者报错求助

Fixing the "Unidentified Developer" Error for Your Mac CLI Tool

Hey there, let's get this sorted out once and for all—no more asking users to fumble through Security & Privacy settings to open your CLI tool. The issue boils down to using the right certificate, proper code signing, and critical Apple notarization steps that you might have missed. Here's a step-by-step breakdown:

1. Use the Correct Certificate First

First off, let's clarify which certificates are meant for what, since you tried a few:

  • Mac Developer: Only for testing on devices registered to your Apple Developer team. This won't work for external users (even internal non-team employees) and will trigger the error every time.
  • Mac App Distribution: Strictly for submitting apps to the Mac App Store. If you're distributing directly to users (not via the App Store), this certificate is irrelevant.
  • Developer ID Application: This is the one you need. It's designed specifically for distributing apps/cli tools outside the App Store to any Mac user.

2. Properly Sign Your CLI Tool

GUI apps get signed automatically during archivation, but CLI tools sometimes need a little extra care. If you're not already manually signing it, run this command (replace placeholders with your details):

codesign --force --sign "Developer ID Application: Your Company Name (YOUR_TEAM_ID)" /path/to/your/cli-tool
  • You can find your full certificate name by opening Keychain Access and looking under "My Certificates".
  • The --force flag ensures any existing (invalid) signatures are overwritten.

3. Notarize Your Tool (Non-Negotiable for macOS 10.14.5+)

Apple now requires all externally distributed Mac software to be notarized—this is the big one that's likely missing from your process. Here's how to do it for a CLI tool:

  1. Package your tool into a zip: Notarization requires a compressed archive. Use ditto to ensure it's properly packaged:
    ditto -c -k --sequesterRsrc --keepParent /path/to/your/cli-tool /path/to/cli-tool.zip
    
  2. Submit to Apple's notary service: Use notarytool (replace placeholders with your Apple ID, team ID, and App Store Connect app-specific password—never use your regular Apple ID password here):
    xcrun notarytool submit /path/to/cli-tool.zip --apple-id "your-apple-id@example.com" --team-id "YOUR_TEAM_ID" --password "your-app-specific-password" --wait
    
    The --wait flag will keep the command running until notarization completes, so you'll see a success/failure message right away.
  3. Staple the notarization ticket: This attaches the notarization proof directly to your tool, so users don't need an internet connection to verify it:
    xcrun stapler staple /path/to/your/cli-tool
    

4. Verify Everything Worked

Run these commands to confirm your tool is properly signed and notarized:

  • Check the signature details:
    codesign -dv --verbose=4 /path/to/your/cli-tool
    
    Look for Authority=Developer ID Application: Your Company... and Stapled: Yes in the output.
  • Check if macOS accepts it:
    spctl -a -vvv -t install /path/to/your/cli-tool
    
    If you see accepted at the end, you're good to go.

5. Bonus: Internal Distribution Tips

If you're distributing to internal employees only, you could also use MDM (Mobile Device Management) to push a trust profile for your Developer ID certificate. But notarization is still the best approach—it works for both internal and external users without extra setup on their end.

内容的提问来源于stack exchange,提问作者Alejandro Cotilla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:33:22