Docs
CI & pipelines
Before you automate
- Finish Console setup Create or import a signing identity, apply an allow policy for the build Mac, then issue an enrollment code in Console → Devices.
-
Install the Mac agent
Install LiminalKeysHost (and its signing extension) on the build Mac so virtual certificates can appear to
codesign/ Xcode after enroll. - Store the enrollment code as a secret Prefer a CI secret or environment variable. Do not commit enrollment codes or paste them into public logs.
Host CLI (non-interactive)
From the Liminal Keys macOS package (src/macos), the product command is
LiminalKeysHostCLI. Enroll always needs an explicit API base URL.
export LIMINAL_KEYS_API_BASE_URL=https://api.liminalkeys.com
export LIMINAL_KEYS_ENROLLMENT_CODE='…from Console…' # CI secret; do not commit
swift run LiminalKeysHostCLI enroll --json
swift run LiminalKeysHostCLI refresh --json
swift run LiminalKeysHostCLI status --require-enrolled --json
swift run LiminalKeysHostCLI identities --json
Commands
| Command | Purpose |
|---|---|
enroll | Register the Mac with production using an enrollment code |
status | Report enrolled state, device id, and identity count |
refresh | Reload session and assigned public identities |
identities | List public identity metadata (never private keys) |
Useful flags
--api-base-url/LIMINAL_KEYS_API_BASE_URL— required for enroll (use production above)--enrollment-code/LIMINAL_KEYS_ENROLLMENT_CODE— required for enroll--json— machine-readable result on stdout--require-enrolled—statusexits non-zero when not enrolled--no-publish— skip publishing identities to the Mac signing extension (API-only checks)
Exit codes
0— success (statusmay report not enrolled unless--require-enrolled)1— operational failure2— usage / validation error
After enroll
- Allow the Liminal signing extension when macOS prompts (once per Mac).
- Keep the Host app available if your policy rules require sign confirmation.
- Sign with
codesignor Xcode using the published virtual identity. - For App Store IPA export of nested Watch apps, use Host Export IPA… or
LiminalKeysExport.
Private keys never leave cloud custody. CLI output must not include private key material or access tokens.
Local loopback APIs are for contributors only — not the customer default. Always set the production API URL
explicitly in customer pipelines.
Related: Getting started · macOS agent · Console