Docs

CI & pipelines

Use LiminalKeysHostCLI to enroll and refresh a Mac build agent without opening the Host UI. Production API hostname is the environment of record: https://api.liminalkeys.com.

Before you automate

  1. Finish Console setup Create or import a signing identity, apply an allow policy for the build Mac, then issue an enrollment code in Console → Devices.
  2. Install the Mac agent Install LiminalKeysHost (and its signing extension) on the build Mac so virtual certificates can appear to codesign / Xcode after enroll.
  3. Store the enrollment code as a secret Prefer a CI secret or environment variable. Do not commit enrollment codes or paste them into public logs.

Host CLI (non-interactive)

From the Liminal Keys macOS package (src/macos), the product command is LiminalKeysHostCLI. Enroll always needs an explicit API base URL.

export LIMINAL_KEYS_API_BASE_URL=https://api.liminalkeys.com
export LIMINAL_KEYS_ENROLLMENT_CODE='…from Console…'   # CI secret; do not commit

swift run LiminalKeysHostCLI enroll --json
swift run LiminalKeysHostCLI refresh --json
swift run LiminalKeysHostCLI status --require-enrolled --json
swift run LiminalKeysHostCLI identities --json

Commands

CommandPurpose
enrollRegister the Mac with production using an enrollment code
statusReport enrolled state, device id, and identity count
refreshReload session and assigned public identities
identitiesList public identity metadata (never private keys)

Useful flags

Exit codes

After enroll

  1. Allow the Liminal signing extension when macOS prompts (once per Mac).
  2. Keep the Host app available if your policy rules require sign confirmation.
  3. Sign with codesign or Xcode using the published virtual identity.
  4. For App Store IPA export of nested Watch apps, use Host Export IPA… or LiminalKeysExport.
Private keys never leave cloud custody. CLI output must not include private key material or access tokens. Local loopback APIs are for contributors only — not the customer default. Always set the production API URL explicitly in customer pipelines.

Related: Getting started · macOS agent · Console