Skip to main content
FixMyTech

App Can't Be Opened: Unidentified Developer on Mac

By

Published

7 min read

Share

Short answer

The warning means the app is not signed with an Apple Developer certificate, so macOS cannot confirm who made it or that it is unmodified. It is not a malware detection. To open an app you genuinely trust, launch it once, then go to System Settings → Privacy & Security and use the Open Anyway button that appears there.

On this page

You download an app, double-click it, and macOS refuses — the developer cannot be verified, or the app cannot be opened because it is from an unidentified developer.

The warning is frequently read as “this is malware”. It does not say that and it does not mean that. What it means is narrower and more useful: macOS cannot tell who wrote this software, because nobody attached a verifiable identity to it.

What Gatekeeper actually checks

Three layers, and the warning you get tells you which one failed.

Status What it proves What you see
Notarised and signed Known developer, scanned by Apple for malware Opens normally
Signed, not notarised Known developer, no Apple scan A warning, with an option to proceed
Unsigned Nothing about origin or integrity The unidentified developer block
Signature revoked Apple withdrew the developer’s certificate A firmer block
Damaged or incomplete File was altered or truncated A message about the app being damaged

A signature is a cryptographic proof that a specific Apple Developer account built the app and that nobody has modified it since. Notarisation adds Apple having scanned that build for known malware before distribution.

The honest consequence of this design: a signature proves identity, not trustworthiness. Malware signed with a stolen certificate passes the check until Apple revokes it. An unsigned open-source utility written by someone meticulous fails it. The warning is information, not a verdict.

Opening an app you trust

If you downloaded the app from the developer’s own site and you know what it is, the supported route is straightforward.

  1. Double-click the app. The warning appears. Dismiss it.
  2. Open System Settings → Privacy & Security and scroll to the security section.
  3. A message about the blocked app appears, with a button to open it anyway. Click it and confirm.

The button only appears for a limited period after the failed launch attempt, so if you do not see it, try opening the app again and come straight back.

The older method — right-clicking the app and choosing Open from the context menu — still works on some macOS versions but Apple has been tightening it. The Privacy & Security route is the one that works consistently on current versions.

macOS remembers your decision for that app. You will not be asked again unless you replace it with a new download.

Decide before you click, not after

Approving an app bypasses the only automated check macOS performs. That is fine for software you have reason to trust and reckless for software you do not.

Worth proceeding when:

  • You downloaded it from the developer’s own website, typing the address yourself rather than following a search advert.
  • It is established open-source software from its official repository.
  • A colleague or your IT department supplied it directly.

Worth stopping when:

  • It arrived as an email attachment you were not expecting.
  • A website told you it was required to view a page, play a video, or update Flash — which has not existed for years and remains a staple of fake prompts.
  • It was downloaded from an aggregator or crack site, both of which routinely repackage legitimate apps with additions.
  • The app claims to clean, optimise or speed up your Mac and you did not go looking for it.

That last category deserves naming. Unsolicited Mac cleaner and optimiser apps are the most common form of genuinely unwanted software on macOS, and they arrive through exactly this route. A Mac that is slow or full has causes you can find yourself — what is filling the startup disk covers the storage side without installing anything.

Do not turn Gatekeeper off

A Terminal command exists that disables the check globally and restores the old “anywhere” option. It is widely posted and it is a bad trade.

Turning Gatekeeper off removes the check for every app you download from that point on, not just the one you wanted. You lose the protection for the case you did not anticipate — a compromised download, a lookalike site, software someone else installs on your machine. Approving apps individually gets you the same practical result and keeps the check for everything else.

If you have previously disabled it, re-enabling it is a one-line Terminal command using spctl, and it is worth doing.

The “app is damaged” variation

A different message, often confused with this one: macOS says the app is damaged and should be moved to the Bin.

This usually means the download was incomplete or corrupted, or the quarantine flag interacted badly with how the app was packaged. Re-download it from the original source first. If the same thing happens repeatedly with a known-good app, the developer’s packaging is at fault and their support pages generally acknowledge it.

Do not reach for commands that strip quarantine attributes from arbitrary files. That advice circulates widely and it removes the flag that makes Gatekeeper work at all.

Realistic expectations

For an app you trust, the Privacy & Security route takes about fifteen seconds and you never see the warning again for that app. That is the entire fix, and it is how Apple intends unsigned software to be handled.

The honest limit is that Gatekeeper cannot tell you whether software is trustworthy, only whether it is identifiable. Judging the source remains your job, and no macOS setting substitutes for it. If you are uncertain whether something you already approved was a good idea, checking a Mac for malware covers what the built-in tools can and cannot tell you afterwards.

Frequently asked questions

Does the unidentified developer warning mean an app has a virus?
No. It means the app lacks a valid Apple Developer signature, so macOS cannot verify its origin. Plenty of legitimate open-source and small-developer software is unsigned because the certificate costs money, and plenty of malware is signed with stolen or throwaway certificates.
What is the difference between signing and notarisation?
Signing proves which developer account built the app and that it has not been altered since. Notarisation means Apple additionally scanned the build for known malware before it was distributed. Notarised apps open without any warning at all.
Is it safe to disable Gatekeeper entirely?
No, and there is no good reason to. Disabling it removes the check for every app you ever download, not just the one you want to run. Approving individual apps through Privacy & Security achieves the same result without lowering your defences permanently.
Why do I get the warning on an app I downloaded before?
Because macOS attaches a quarantine flag to files downloaded from the internet, and the check happens on first launch of each copy. A re-downloaded or updated version is a new file with a new flag, so the warning returns.
Why does the Open Anyway button not appear for me?
It only appears for a short window after you attempt to launch the app, so try opening it again and then return to Privacy & Security immediately. On a managed work Mac the option may be removed entirely by device management policy.

All Mac guides