Managed installations and updates
How Goldfish updates itself, and where to download installers for managed deployments.
Goldfish does not yet provide step-by-step guides for MDM tools like Jamf, Kandji or Intune. The recommended setup is to install Goldfish so it can keep itself up to date.
If your organization manages installs, this page lists what Goldfish needs, explains how updates work, and gives the endpoints to use for your own packaging. To set organization policies, see Configure Goldfish with MDM.
At a glance
| Item | Details |
|---|---|
| Platforms | macOS (one universal app for Apple silicon and Intel), Windows x64 |
| Installer | .dmg on macOS, .exe on Windows |
| Install location | /Applications on macOS, per user on Windows |
| Signing | Developer ID, Team ID 3NBSP8VQ8T. Deploy the app unmodified: re-signing it breaks permissions and updates. |
| Bundle IDs | com.kaspi.goldfish (app), com.goldfish.daemon (helper process inside the app) |
| Permissions | Accessibility (required), Microphone (only for voice dictation) |
| Background | Starts at login through a login item, Team ID 3NBSP8VQ8T |
| Network | HTTPS and WebSocket to goldfish.sh and its subdomains |
| Updates | Automatic, about once an hour. Can be turned off with AutoUpdate. |
| Data | Each person’s memory is stored on their own device. See Privacy. |
Permissions
Goldfish needs Accessibility to read on-screen text and to write into text fields. You can pre-approve it with a PPPC payload. Add an entry for both bundle IDs, because the helper process has its own permission. Read the code requirements from an installed copy:
codesign -dr - /Applications/Goldfish.app
codesign -dr - /Applications/Goldfish.app/Contents/MacOS/goldfish_d
The Microphone can’t be pre-approved by an MDM, so people allow it the first time they use dictation. Goldfish does not use Screen Recording, Input Monitoring or Full Disk Access. On Windows, Goldfish needs no special permissions.
How Goldfish handles updates
Goldfish checks for updates about once an hour while it runs. When a new version is available, it downloads it in the background, installs it and restarts.
Automatic updates need:
- macOS: Goldfish in the Applications folder, and a user who is allowed to replace the app.
- Windows: the default per-user installation.
- Both: network access to
goldfish.shand its subdomains.
If your policies prevent Goldfish from updating itself, turn automatic
updates off (AutoUpdate in Configure Goldfish with
MDM) and deploy new versions with the
installers below.
Download the latest installers
These endpoints need no sign-in:
- macOS:
https://app.goldfish.sh/download/mac-arm64(one universal app for Apple silicon and Intel) - Windows:
https://app.goldfish.sh/download/win-x64
Both redirect to the current installer: a .dmg for macOS and an .exe for
Windows.
Version-specific download URLs
Package managers need a stable URL. The endpoints above always point at the newest release, so capture the redirect target instead:
curl -s -o /dev/null -w '%{redirect_url}\n' https://app.goldfish.sh/download/mac-arm64
This returns a permanent URL like
https://u.goldfish.sh/releases/0.1.56/Goldfish_0.1.56_universal.dmg.
Compute the SHA256 of the file you download from it for your package
manifest.
Detect new releases
The current version is public, with no sign-in:
https://u.goldfish.sh/latest.json
Its version field holds the newest release. Check it on a schedule, for
example daily, and package the new installer when it changes.
