Apple's command-line tool that signs a binary or bundle, and verifies an existing signature. Lives at `/usr/bin/codesign` on macOS and is what xcodebuild calls under the hood.
/usr/bin/codesigncodesign tool
codesign is the macOS command-line tool that signs and verifies Apple binaries. xcodebuild calls it during the archive and export steps; fastlane gym, EAS Build, and every iOS CI plugin eventually shell out to it. Knowing what it does is the difference between staring at 'Code Signing Error' for an hour and fixing the build in two minutes.
Where it lives, and which Macs have it
The binary is at /usr/bin/codesign on every Mac. You will see it written as codesign, OS X codesign, or just "code sign on Mac" depending on how old the documentation is: OS X was renamed macOS in 2016, and the tool itself has not changed name since it shipped with Mac OS X 10.5 Leopard. Anything you read about OS X codesign still applies.
It arrives with the Xcode Command Line Tools rather than with the operating system alone, so a clean Mac needs xcode-select --install before the command resolves. There is no version for Linux or Windows, which is the constraint behind building an iOS app on Windows: signing has to happen on a Mac even when everything else does not.
bash
# Confirm the tool is present and see its version
which codesign
codesign --version
# Install it if the command is not found
xcode-select --install
# Quick health check
codesign --verify --verbose=4 MyApp.app
# Show identity, timestamp, hardened runtime, and entitlements
codesign -dvv --entitlements :- MyApp.app
Common errors and what they mean
errSecInternalComponent
The keychain refused codesign access to the private key, which on a build machine means a locked keychain or a missing partition list. The fix and the ordering the steps have to run in are on errSecInternalComponent.
The certificate is not in any keychain in the search list, or the keychain is locked, or you typed the identity name wrong.
resource fork, Finder information, or similar detritus not allowed
Some file inside the bundle has extended attributes that codesign refuses to sign over. Run xattr -cr MyApp.app before signing, then work out which build step keeps adding them back.
FAQ
Common questions about codesign (command)
At /usr/bin/codesign on every Mac. It ships with the Xcode Command Line Tools rather than with macOS alone, so on a clean machine you may need to run xcode-select --install before the command resolves. Check with `which codesign`.
Yes. Apple renamed OS X to macOS in 2016 but the tool kept its name, its path, and its flags. Guides written for OS X code signing still apply on current macOS. Newer options exist, such as --options runtime for the hardened runtime, but nothing documented for OS X has been removed.
No. codesign is a macOS binary that talks to the system Security framework, and Apple does not ship it for other platforms. Teams developing on Windows or Linux run the signing step on a macOS CI runner or a rented cloud Mac instead. Unofficial reimplementations exist but are not supported by Apple and are a poor choice for App Store builds.
HexSign tracks every Apple certificate and provisioning profile and alerts you ahead of expiry. The Free plan covers tracking and alerts. Paid plans renew them for you.