Krate
Try Krate
Answer

Ship a desktop app without code signing for every OS

Native installers need an Apple Developer ID and notarization on macOS and a trusted signature on Windows; a .krate file is not a native installer, so you ship one file and the people you send it to install the Krate app runtime once. The runtime then opens your file and shows what the app asks for before it runs.

Reviewed against Krate 0.5.4. 2 min read

What signing takes for a native app

  • macOS: an Apple Developer Program membership with an annual fee, Xcode on a Mac, signing certificates, then an upload to Apple for notarization.
  • Windows: an unsigned download shows "Windows protected your PC" and the user must choose to run it anyway. A file signed with a new certificate can still be flagged as unrecognized until it builds reputation, and an EV certificate no longer skips that. On Windows 11, Smart App Control can block unsigned files that have no positive reputation.
  • Linux: package and repository signing depends on the format and the store.

Sources: Electron's code signing guide and Microsoft's SmartScreen reputation guide.

What a signature tells your users

A signature identifies the publisher and shows the file has not been changed since it was signed. It does not limit what the program can reach once it runs: a signed installer still gets the same access to files and the network as the person who opened it.

How it works with a .krate

The operating system checks the Krate runtime once, when it is installed. Krate for Mac is signed and notarized by Apple.

Your app is a file the runtime opens, not a program the operating system launches, so there is no per-OS package of yours to sign or notarize. When someone opens it, Krate shows what it asks for, and the app gets only what they allow.

Signing a .krate with your own key

You can sign a bundle so recipients can check it came from you and has not changed. The key is an Ed25519 key you create; it stays on your machine, and signing and checking work offline with no account:

krate sign app.krate --key publisher.key --generate-key --namespace com.example.app

--generate-key writes a new key the first time and refuses to overwrite one. Run krate sign --help for your version's options. This signature ties releases to your key; it is not a certificate authority's check of your legal identity.

What you still own

  • Telling people where to get Krate, and that Windows asks once at install today.
  • Publishing your app's hash or signing key somewhere they trust, so they can check what they received.
  • Testing on the systems you support, within the current limits.

Questions

Does a Krate app need its own Apple Developer ID?

No. The app is a file that the Krate runtime opens, and Krate for Mac is signed and notarized by Apple. You do not sign or notarize the .krate for each system.

Can I distribute a Windows app without a code signing certificate?

Yes, but users see a SmartScreen warning and must choose to run it anyway, and some managed or Smart App Control machines block it. With Krate you ship a .krate instead of an .exe; Windows checks the Krate runtime when it is installed, and that runtime is unsigned today.

Do I need an Apple Developer account to share a Mac app?

For a native Mac app downloaded from the web, in practice yes: notarization needs a Developer ID from the paid Apple Developer Program. A .krate is opened by Krate for Mac, which is signed and notarized, so you don't need your own Apple account to share one.

Is a signed app safe to run?

A signature tells you who made it and that it was not changed. It does not limit what the app can do once it runs. Krate adds a second check: the app asks before it gets your files or the network.

More answers about shipping desktop apps

Build with Krate

Start with the runtime and a project that fits the current APIs. The runtime and CLI are MIT OR Apache-2.0; Studio has a separate license. Check the licensing details and capability limits.