The usual route, step by step
- Build once per operating system. Electron and Tauri share your code, then produce a separate package for macOS, Windows and Linux. In practice that means a build machine or CI runner for each system, and macOS signing needs a Mac.
- Often build once per processor. Apple silicon and Intel Macs, x64 and ARM64 Windows, x86_64 and arm64 Linux each need native code built for them, or a universal build that carries both.
- Sign and notarize. For direct downloads, macOS expects a Developer ID signature and Apple notarization, which needs a paid Apple Developer Program membership. On Windows, an unsigned download shows "Windows protected your PC", and even a newly signed app can be flagged as unrecognized until it builds reputation.
- Package and host each one. A DMG or app bundle for macOS, an installer for Windows, and AppImage, deb, RPM, Flatpak or Snap for Linux. Each gets its own download link and its own update path.
After all that, a conventional desktop program usually runs with the same access to files and the network as the person who opened it, unless the platform sandboxes it, as the Mac App Store does. A signature says who made the app. It does not limit which of your files the app can read.
Sources: Electron's code signing guide, Tauri's distribution guide and Microsoft's SmartScreen reputation guide.
The Krate route
- Make the app. Describe it to an AI coding agent in Krate Studio, or write it in Rust against the Krate SDK. Studio can also port a project you already have: the AI rewrites it against Krate's interfaces, so read the plan it shows before you start.
- Pack one file. The result is one
.krate: a manifest that names the access the app wants, a WebAssembly component that holds the app, and optionally its assets and source. It contains no Intel or ARM machine code, so there is nothing to build per processor. - Send it like a document. Email it, drop it in a shared folder or a chat, or publish it and send a link. Every recipient gets the same bytes.
- Your users install Krate once. Krate for Mac is signed and notarized by Apple. After that, each new app is only its own file.
- They decide what it may touch. An app starts without file or network access and asks for what it needs. The runtime checks protected calls against what was allowed; the known gaps are on the limits page. See how to inspect an app before running it.
What you stop doing, and what you still do
You stop producing a separate app package for each operating system and processor, signing and notarizing each app for each platform, and asking people to run an installer that gets their full permissions.
You still test the app on the systems you support, write it against Krate's interfaces (Rust today), check the current limits and tell recipients where to get the runtime. Runtime updates are separate from your app's updates. Krate does not turn an existing .exe or .app into a .krate.
Check it yourself
Download chart.krate, one file of 11,455 bytes with SHA-256 3d290c48f74936d5cdb45ceb0ee945bd0f7b5b0b21f87f79917bced3b4ca73c3. Follow the quickstart to see what it asks for and run it on any of the three systems.
Ten ported apps, as the same committed .krate files, passed their replay checks on macOS (Apple silicon), Ubuntu (x86_64) and Windows (x86_64) GitHub runners with runtime 0.5.4 on 29 September 2026. An eleventh app has no replay check defined yet and is skipped. Records: macOS, Ubuntu, Windows. These are automated headless checks, not hands-on testing of every feature. Runtimes are also published for Intel Macs, ARM64 Windows and arm64 Linux; those are not in these checks yet.
When another route fits better
- Your app also needs phones or the web: Tauri, Flutter or a web app cover more platforms today.
- Your app depends on the browser DOM or Node.js packages: Electron runs that code as it is.
- You need native libraries, subprocesses or a demanding 3D renderer; see the limits page.
Krate fits desktop tools, internal utilities, dashboards, editors, small games and apps made with AI, where getting one file to people safely matters more than reaching every platform.
Questions
Can one file run on Windows, macOS and Linux?
A normal native executable can't, because each system uses its own executable format. A .krate can, because it is not a native executable: it holds a WebAssembly component that the installed Krate runtime runs on each system.
Do the people I send it to need to install anything?
Yes, once: the Krate runtime for their system, from the download page. After that, every Krate app is a single file they open.
Do I need a code signing certificate to ship a .krate?
No. You don't sign and notarize a package per operating system, because the file isn't one. You can still sign a .krate with your own key so people can check it came from you. See code signing and Krate.
Can I ship an app I made with AI this way?
Yes, if it is a Krate app. Make it in Krate Studio with the AI agent you already use, or open an existing project in Studio and port it. See how to share an AI-built desktop app.