Docs

Getting started

Use production hostnames only. Local loopback APIs are for contributors, not customers.

Service URLs

RoleURL
API https://api.liminalkeys.com
Console https://console.liminalkeys.com

Operator path

  1. Open Console Sign in with your organization’s Microsoft work account at console.liminalkeys.com.
  2. Prepare an identity Import a PKCS#12 into custody or generate a CSR, complete it with the issued certificate, then create policy rules (subjects, optional confirmation) and Apply policy.
  3. Issue an enrollment code Create a short-lived enrollment code for the Mac that will sign. Treat it as a secret.
  4. Enroll the Mac In LiminalKeysHost, set API URL to https://api.liminalkeys.com, paste the code, enroll, and refresh identities.
  5. Enable CryptoTokenKit and sign Allow the token extension when prompted. Sign with codesign or Xcode as usual. If a rule requires confirmation, approve the prompt in the host.
Console devices and enrollment where Mac enrollment codes are issued

Next: Console guide · macOS agent · Security