Cannot run Catalyst app on other devices?!?

I prepare a private project in Xcode, use Archive, Distribute/Copy, save the application somewhere. Copy it to my other computer, run.

Works perfectly with normal MacOS applications.

With Catalyst ones though it does not; whatever I try, all I get is “The application XXX cannot be opened”.

What do I do wrong and how to fix the problem? Thanks!

Answered by DTS Engineer in 907568022
the profile linked to my personal team BHHT72562H is available on the machine where the app has been developed

Kinda.

The profile is actually embedded within your app, but a development profile contains a list of machines that it applies to and I suspect that your profile lists your development machine but not the other machine.

You can confirm this using the instructions in TN3125 Inside Code Signing: Provisioning Profiles.

The easiest way out of this is to not use a provisioning profile. However, your app’s entitlements include com.apple.developer.homekit, and I presume that’s required. In that case you need a profile because that entitlement is restricted, that is, its use must be authorised by a profile.

If you were a member of a paid team there’s a standard way to fix this:

  1. Use the Developer website to add the other Mac’s provisioning UDID to your team.
  2. In Xcode, choose Product > Archive.
  3. Then in the Xcode organiser, click Distribute App and follow the Debugging workflow.

Xcode will notice the new UDID in your team and regenerate the profile to include it.

However, I don’t think this will work for you. AFAICT you’re not a member of a paid team (in Xcode parlance you’re using a Personal Team), and that means you don’t have access to Certificate, Identifiers, and Profiles section of the Developer website.

Are you sure you need HomeKit? Without that entitlement this problem should just go away.

Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Hmmm, I doubt this is a Mac Catalyst problem per se, but rather a provisioning profile one. What does this report:

% codesign -d --entitlements - /path/to/your.app

Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Thanks!

On the other computer, where it does not run:

ocs@iMac Desktop % codesign -d --entitlements - HomeLog.app       
Executable=/Users/ocs/Desktop/HomeLog.app/Contents/MacOS/HomeLog
[Dict]
	[Key] application-identifier
	[Value]
		[String] BHHT72562H.cz.ocs.HomeLog
	[Key] com.apple.application-identifier
	[Value]
		[String] BHHT72562H.cz.ocs.HomeLog
	[Key] com.apple.developer.homekit
	[Value]
		[Bool] true
	[Key] com.apple.developer.team-identifier
	[Value]
		[String] BHHT72562H
	[Key] get-task-allow
	[Value]
		[Bool] true
ocs@iMac Desktop % ./HomeLog.app/Contents/MacOS/HomeLog 
zsh: killed     ./HomeLog.app/Contents/MacOS/HomeLog
ocs@iMac Desktop % 

To compare, on the one where the app was built and runs all right:

1048 ocs /Volumes/ocs/Desktop> codesign -d --entitlements - HomeLog.app       
Executable=/Volumes/ocs/Desktop/HomeLog.app/Contents/MacOS/HomeLog
[Dict]
	[Key] application-identifier
	[Value]
		[String] BHHT72562H.cz.ocs.HomeLog
	[Key] com.apple.application-identifier
	[Value]
		[String] BHHT72562H.cz.ocs.HomeLog
	[Key] com.apple.developer.homekit
	[Value]
		[Bool] true
	[Key] com.apple.developer.team-identifier
	[Value]
		[String] BHHT72562H
	[Key] get-task-allow
	[Value]
		[Bool] true
1049 ocs /Volumes/ocs/Desktop> ./HomeLog.app/Contents/MacOS/HomeLog 
2026-09-30 16:59:19.512 HomeLog[64856:4105486] sysname: 'Darwin'
nodename: 'Mac.OCSluj'
release: '27.0.0'
version: 'Darwin Kernel Version 27.0.0: Tue Aug 11 21:02:57 PDT 2026; root:xnu-13432.1.9~1/RELEASE_ARM64_T8132'
machine: 'arm64'
2026-09-30 16:59:19.512 HomeLog[64856:4105486] hw.model: 'Mac16,12'
2026-09-30 16:59:19.520 HomeLog[64856:4105486] *** HomeLog v1.0b1 running on 'Mac.OCSluj (arm64-Mac16,12)' E3C0147F-0447-599D-9537-6A13B4F09282
^C
1050 ocs /Volumes/ocs/Desktop> 

Seems pretty much the same :(

Aha! I guess the culprit would be most probably that the profile linked to my personal team BHHT72562H is available on the machine where the app has been developed, but not on the other ones (the MacOS apps work since they are not signed, but for Catalyst ones this seems to be mandatory). Sigh, this is a qagmire :(

How do I get it there (there is no Xcode on the other machine; otherwise I would simply moved the project there and built)?

I've actually tried to

  • go Settings / Apple Accounts in Xcode on the original one
  • open my account, and inside of it, open my Personal Team
  • Manage Certificates
  • export the certificate to a p12
  • move the file to the target computer and import it to its login keychain through Keychain Access.

Alas it did not help, not even after a restart :( What's the proper way to do that? Or am I on a completely wrong track and the culprit would be elsewhere? Thanks a lot!

the profile linked to my personal team BHHT72562H is available on the machine where the app has been developed

Kinda.

The profile is actually embedded within your app, but a development profile contains a list of machines that it applies to and I suspect that your profile lists your development machine but not the other machine.

You can confirm this using the instructions in TN3125 Inside Code Signing: Provisioning Profiles.

The easiest way out of this is to not use a provisioning profile. However, your app’s entitlements include com.apple.developer.homekit, and I presume that’s required. In that case you need a profile because that entitlement is restricted, that is, its use must be authorised by a profile.

If you were a member of a paid team there’s a standard way to fix this:

  1. Use the Developer website to add the other Mac’s provisioning UDID to your team.
  2. In Xcode, choose Product > Archive.
  3. Then in the Xcode organiser, click Distribute App and follow the Debugging workflow.

Xcode will notice the new UDID in your team and regenerate the profile to include it.

However, I don’t think this will work for you. AFAICT you’re not a member of a paid team (in Xcode parlance you’re using a Personal Team), and that means you don’t have access to Certificate, Identifiers, and Profiles section of the Developer website.

Are you sure you need HomeKit? Without that entitlement this problem should just go away.

Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

I suspect that your profile lists your development machine but not the other machine. You can confirm this...

Seems so. Far as I understand the description right, it looks like there is only one computer ID in the profile indeed (see my steps below).

--Incidentally, how do I find the ID of a particular computer to make completely sure? Though the probability 00008132-0016495E2199801C is my development machine is, of course, extremely high.-- Found it meantime in System Information as “Provisioning UDID”, of course, checks.

As for the solution, that seems the hard part, since HomeKit is a must in case of this particular app :( Can you see any, aside of my switching to a paid team?

Thanks a lot!

1062 ocs /Volumes/ocs/Desktop> security cms -D -i HomeLog.app/Contents/embedded.provisionprofile -o /tmp/p.plist
1063 ocs /Volumes/ocs/Desktop> plutil -extract ProvisionedDevices xml1 -o - /tmp/p.plist                        
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<array>
	<string>00008132-0016495E2199801C</string>
</array>
</plist>
1064 ocs /Volumes/ocs/Desktop> 

Just to wrap loose ends, I checked that indeed the darned profile is a requirement for HomeKit: if I remove the capability from the target, macOS Provisioning Profile immediately turns to None Required. Soon as HK is added back, it's again at Xcode Managed. Sigh.

Found it meantime in System Information

Yep. My favourite trick is:

% system_profiler SPHardwareDataType
…
Hardware:

    Hardware Overview:

      …
      Provisioning UDID: 00006034-001401301E88001C
      …
HomeKit is a must in case of this particular app

Yeah, that makes things tricky.

This is a Mac, so there are always options [1], but none of them are particularly good options.

One thing that’d probably work is to set up Xcode on the other machine and use it to create a provisioning profile for that machine. You could then swap in that profile, and re-sign, as you bring the app to the other Mac. However, that’s not exactly easy, and you might run into other problems (I’m specifically concerned about Xcode invalidating the certificate in your original signing identity when you create a new signing identity on the new Mac).

Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

[1] I talk about one ‘nuclear option’ here.

Thanks a lot!

Meantime, pursuing the problem further, I've found there are other problems as well, e.g., an absurdly near expiration date generated in the profile.

Not to hijack my own thread :), and, more importantly, to allow any other user who might perhaps bump into similar problems to find the debate under a more apt name, I've started a new topic for this at https://developer.apple.com/forums/thread/849339.

Cannot run Catalyst app on other devices?!?
 
 
Q