nomac

Notarize a Mac app without a Mac

Gatekeeper needs Apple hardware. You don't have to buy it for one command.

Route
1 codesign
2 notarytool
3 stapler

You built your Electron, Tauri, Godot, or Unity app on Windows or Linux — everything works until macOS users hit 'app can't be opened because Apple cannot check it for malicious software'. Notarization is the fix, and it only runs on a Mac.

nomac's notarize endpoint takes your zip (one .app inside), runs codesign + notarytool + stapler on real Apple hardware, and hands back an artifact Gatekeeper accepts. Your Developer ID certificate is created via your App Store Connect API key — no p12 files ever uploaded.

From git push to TestFlight.

  1. Connect your repo

    Sign in with GitHub and point nomac at your Flutter, React Native, or Xcode repository.

    git push origin main
  2. nomac builds on real Macs

    Your code builds and signs on Apple hardware with your App Store Connect key — you watch the logs live.

    xcodebuild archive · sign
  3. TestFlight, done

    The signed IPA uploads to TestFlight automatically. You get an email; your testers get a build.

    → TestFlight

What you get

Auto-detects your stack

pubspec.yaml → Flutter. package.json + ios/ → React Native. A root .xcodeproj → bare Xcode. Zero config unless you want it.

Live build logs

Stream xcodebuild output in your browser while the build runs — no guessing what broke.

Cached, fast rebuilds

Per-project pub, node_modules, and DerivedData caches. Cached rebuilds target under 15 minutes.

Your keys stay yours

Sign with your own App Store Connect API key — encrypted at rest, decrypted only into an ephemeral keychain per build. nomac never stores p12s.

Artifacts, signed & temporary

IPAs and dSYMs land as signed download links, expiring after 7 days. Nothing lives forever.

Notified, not nagged

Email or Slack when a build finishes or fails. Watch it live if you'd rather.

Questions

What exactly do I upload?

A zip containing exactly one .app bundle — the same thing notarytool expects. nomac validates the bundle structure and Mach-O headers with non-executing tools before anything runs.

Do you need my Developer ID certificate?

No p12 uploads, ever. nomac creates a Developer ID Application certificate via the App Store Connect API from a per-job keypair — the cert lands in your Apple account and nothing secret leaves it.

How long does notarization take?

Apple's notary service answers in seconds to hours — nomac shows the honest status live, and the stapled artifact is ready the moment Apple replies.

Notarize a Mac app without a Mac — starting today.

Trusted beta — free builds while we harden the service.

Join the beta