npx skills add ...
npx skills add rorkai/app-store-connect-cli-skills --skill asc-notarization
Archive, export, and notarize macOS apps using xcodebuild and asc. Use when you need to prepare a macOS app for distribution outside the App Store with Developer ID signing and Apple notarization.
npx skills add rorkai/app-store-connect-cli-skills --skill asc-notarization
Use this skill when you need to notarize a macOS app for distribution outside the App Store.
asc auth login or ASC_* env vars).Before archiving, confirm a valid Developer ID Application identity exists:
If no identity is found, create one at https://developer.apple.com/account/resources/certificates/add (the App Store Connect API does not support creating Developer ID certificates).
If codesign or xcodebuild fails with "Invalid trust settings" or "errSecInternalComponent", the certificate may have custom trust overrides that break the chain:
These errors do not by themselves prove a trust override is the cause. Inspect the affected certificate before proposing a repair. Changing trust settings requires explicit authorization for that certificate; do not remove trust overrides or re-sign an arbitrary app as a diagnostic step.
Create an ExportOptions plist for Developer ID distribution:
Export the archive:
This produces a .app bundle signed with Developer ID Application and a secure timestamp.
Verify the exported app's existing signature and nested code, then display its signing details:
Confirm:
Stop before packaging or uploading if verification fails or the signing identity is unexpected. Diagnose the failure and rebuild or re-export the intended app before checking again. These checks do not modify the bundle and do not establish notarization acceptance.
Do not add --sign or --force to verification. Apple's code-signing guidance distinguishes recursive verification with --deep from signing with --deep --force, which forcibly re-signs nested code.
Fetch the log URL to see detailed issues:
After notarization succeeds, staple the ticket so the app works offline:
For DMG or PKG distribution, staple after creating the container:
| Format | Use Case |
|---|---|
.zip | Simplest; zip a signed .app bundle |
.dmg | Disk image for drag-and-drop install |
.pkg | Installer package (requires Developer ID Installer certificate) |
To notarize .pkg files, you need a Developer ID Installer certificate (separate from Developer ID Application). This certificate type is not available through the App Store Connect API — create it at https://developer.apple.com/account/resources/certificates/add.
Sign the package:
Then submit:
Custom trust overrides are one possible cause. Use the read-only inspection in Preflight, identify the affected certificate, and obtain authorization before changing its trust settings.
The app was signed with a Development or App Store certificate. Re-export with method: developer-id in ExportOptions.plist.
Add --timestamp to manual codesign calls, or use xcodebuild -exportArchive which adds timestamps automatically.
Set a longer upload timeout:
Fetch the developer log for specific issues:
Common causes: unsigned nested binaries, missing hardened runtime, embedded libraries without timestamps.
asc notarization commands use the Apple Notary API v2, not xcrun notarytool.asc commands.--help to verify flags: asc notarization submit --help.xcodebuild archive \
-scheme "YourMacScheme" \
-configuration Release \
-archivePath /tmp/YourApp.xcarchive \
-destination "generic/platform=macOS"<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>method</key>
<string>developer-id</string>
<key>signingStyle</key>
<string>automatic</string>
<key>teamID</key>
<string>YOUR_TEAM_ID</string>
</dict>
</plist>xcodebuild -exportArchive \
-archivePath /tmp/YourApp.xcarchive \
-exportPath /tmp/YourAppExport \
-exportOptionsPlist ExportOptions.plistcodesign --verify --deep --strict --verbose=2 "/tmp/YourAppExport/YourApp.app" && \
codesign --display --verbose=4 "/tmp/YourAppExport/YourApp.app" 2>&1ditto -c -k --keepParent "/tmp/YourAppExport/YourApp.app" "/tmp/YourAppExport/YourApp.zip"asc notarization submit --file "/tmp/YourAppExport/YourApp.zip"asc notarization submit --file "/tmp/YourAppExport/YourApp.zip" --waitasc notarization submit --file "/tmp/YourAppExport/YourApp.zip" --wait --poll-interval 30s --timeout 1hasc notarization status --id "SUBMISSION_ID" --output tableasc notarization log --id "SUBMISSION_ID"asc notarization log --id "SUBMISSION_ID"curl -sL "LOG_URL" | python3 -m json.toolasc notarization list --output table
asc notarization list --limit 5 --output tablexcrun stapler staple "/tmp/YourAppExport/YourApp.app"# Create DMG
hdiutil create -volname "YourApp" -srcfolder "/tmp/YourAppExport/YourApp.app" -ov -format UDZO "/tmp/YourApp.dmg"
xcrun stapler staple "/tmp/YourApp.dmg"productsign --sign "Developer ID Installer: YOUR NAME (TEAM_ID)" unsigned.pkg signed.pkgasc notarization submit --file signed.pkg --waitASC_UPLOAD_TIMEOUT=5m asc notarization submit --file ./LargeApp.zip --wait