Apple Developer ID · Application
How an agent gets a Apple Developer ID · Application key through KeyKeeper, what to choose on developer.apple.com, and how KeyKeeper verifies it.
| Template id | developer-id (also codesign, developer-id-application) |
|---|---|
| Field | signing-identity · signing identity in the macOS Keychain |
| Key looks like | whether it can be viewed again is unconfirmed |
| Created at | developer.apple.com |
| Verified by KeyKeeper | not verified |
| Template checked | 2026-09-15 |
This is a signing identity that stays in the macOS Keychain. KeyKeeper stores no private key material for it; the template only records where Apple manages it.
What only you can do
Sign in to the Apple Developer account
Choose Developer ID Application
Create the certificate from a CSR whose private key remains in this Mac's Keychain
What to choose
Keep the non-exportable signing private key in the macOS Keychain and refer to the Developer ID Application identity by name. Do not copy it into a text credential.
The agent is told the same thing. It opens the page for you and says what to pick; it never logs in, passes 2FA or pays on your behalf.
Rotation and expiry
Developer ID certificates have an Apple-issued expiration date; replace before expiry. Rotate or revoke at developer.apple.com.