Skip to main content

Install the Endpoint Suite

The Endpoint Suite is the desktop app that puts a developer's machine under governance. It signs them in, registers the device, and points their AI tools at the Gateway.

macOS

  1. Download the .dmg from the link your admin gave you.
  2. Drag the app into Applications before opening it. Opening it from the mounted disk image leaves macOS running it from a temporary read-only location, and it will not be able to store its device key.
  3. Open it from Applications. It is signed and notarized, so there is no security warning to click through.

Windows

  1. Download setup.exe and run it. It installs per user — no administrator prompt, nothing written to Program Files.
  2. Windows SmartScreen currently shows a "Windows protected your PC" warning, because the Windows build is not yet Authenticode-signed. Click More info → Run anyway. We will remove this step when the certificate is in place; if that warning makes you uneasy, that is a reasonable instinct and you should check the download came from your admin.

Signing in

The app opens your normal browser to sign in with a passkey — Touch ID, Windows Hello, or a security key. Nothing is typed into the app itself, which is why there is no password field anywhere in it.

If the browser window closes without finishing, press Sign in with browser again.

Device identity

On first run the app creates an ECDSA P-256 key pair and stores the private key in the operating system's secure storage — Keychain on macOS, Credential Manager on Windows. The private key never leaves the machine and is not something you can export or copy to another computer.

The card on the sign-in screen shows whether this succeeded. If it says it failed, see The app cannot create a device identity.

Seats

Signing in consumes one of your organization's seats. The topbar and the Account tab both show the current count.