Docs

macOS agent

LiminalKeysHost + CryptoTokenKit extension. No DYLD insertion into platform binaries.

Console devices view used to enroll Mac hosts

What it does

The host app holds the device credential from enrollment, talks to the production API, and surfaces virtual certificates to macOS through CryptoTokenKit. When codesign or Xcode requests a signature, the digest is sent to cloud custody for signing. The Mac keeps public certificates and device credentials only — never private key bytes.

Enrollment

  1. In Console, open Devices and issue an enrollment code
  2. In LiminalKeysHost, set API URL to https://api.liminalkeys.com
  3. Paste the enrollment code, complete enroll, then refresh identities
  4. Approve the CryptoTokenKit extension in System Settings if macOS prompts

Signing with codesign and Xcode

After identities appear, use your normal signing workflow. Select the Liminal virtual identity where you would select a local certificate. The extension presents the public cert; the private operation happens in cloud HSM custody through the API.

Sign confirmation

If the applied Console policy rule requires confirmation, the first sign attempt does not return a signature. LiminalKeysHost prompts the user to approve or deny. Only after approval does the digest get signed. If the user denies, or no matching applied rule exists, the sign is refused and recorded in audit.

Troubleshooting checklist

Never paste private keys, PKCS#12 files, or long-lived enrollment secrets into support tickets or public channels. Rotate enrollment codes if exposure is suspected.

← Console · Security →