All guides
Desktop apps

Building a desktop app (macOS, Windows, Linux)

Like mobile, the desktop app is your web app in a native shell — Tauri this time. Builds run on GitHub Actions, which provides macOS, Windows and Linux runners.

Building

Open the GitHub panel (Code or Preview tab) and use the Desktop row. Choose all three platforms or just one, then Build.

You get .dmg for macOS, .msi and .exe for Windows, and .deb, .rpm and .AppImage for Linux. Download them from the run's files link.

Unsigned builds

Without certificates the installers work but show a warning: macOS says the developer is unidentified (right-click → Open bypasses it), Windows SmartScreen shows a caution screen. This is normal and fine for internal use or early testers.

Signing and notarizing macOS

Needs the Apple Developer Program ($99/yr). Add these repository secrets:

  • APPLE_CERTIFICATE — Developer ID certificate (.p12), base64
  • APPLE_CERTIFICATE_PASSWORD
  • APPLE_SIGNING_IDENTITY — e.g. "Developer ID Application: Your Name (TEAMID)"
  • APPLE_ID — your Apple ID email
  • APPLE_PASSWORD — an app-specific password, not your account password
  • APPLE_TEAM_ID

With all six present, the build signs and notarizes automatically and the warning disappears. Partial secrets are ignored on purpose — an empty certificate value used to fail the entire macOS build, so signing is now all-or-nothing.

Windows signing

Optional. Removing the SmartScreen warning needs an OV or EV code-signing certificate from a certificate authority (typically $200–500/yr). Linux packages need no signing.