Docs

Console

Administrative UI at console.liminalkeys.com.

Liminal Console identities view

Sign-in

Console uses your organization’s Microsoft work account (directory SSO). Your organization must grant access to the Liminal Console application. There is no password login on the marketing site.

Identities

Onboard signing identities whose private keys stay in cloud HSM custody:

Pending, failed, or expired identities never appear on enrolled Macs and cannot be used in policy.

Devices & enrollment

List enrolled Macs, revoke a machine that leaves the fleet, and issue short-lived enrollment codes for LiminalKeysHost. Treat codes as secrets — do not post them to shared mailing lists. Revocation stops signs from that device on the next request.

Liminal Console policy rules view

Policy rules

Rules are the operational control plane for signing. Each rule specifies:

Edits are drafts until you click Apply policy. Until applied, a change MUST NOT grant signing. No matching applied rule means deny. If one applied rule would allow and another would deny the same request, the result is deny.

Sign audit

Review allow and deny outcomes with tenant, device, identity, and timing identifiers — without downloading digests, signatures, or key material.

Typical admin path

  1. Onboard an identity (import or generate + complete)
  2. Add policy rules (subjects, optional confirmation, optional window)
  3. Apply policy so the API and enrolled devices honor the live set
  4. Issue an enrollment code and enroll the Mac
  5. Watch Overview metrics and Sign audit for denials and successful signs

← Getting started · macOS agent →