---
title: Managed installations and updates
description: How Goldfish updates itself, and where to download installers for managed deployments.
---

Goldfish does not yet provide step-by-step guides for MDM tools like Jamf,
Kandji or Intune. The recommended setup is to install Goldfish so it can keep
itself up to date.

If your organization manages installs, this page lists what Goldfish needs,
explains how updates work, and gives the endpoints to use for your own
packaging. To set organization policies, see [Configure Goldfish with
MDM](/get-started/configure-with-mdm).

## At a glance

| Item | Details |
|---|---|
| Platforms | macOS (one universal app for Apple silicon and Intel), Windows x64 |
| Installer | `.dmg` on macOS, `.exe` on Windows |
| Install location | `/Applications` on macOS, per user on Windows |
| Signing | Developer ID, Team ID `3NBSP8VQ8T`. Deploy the app unmodified: re-signing it breaks permissions and updates. |
| Bundle IDs | `com.kaspi.goldfish` (app), `com.goldfish.daemon` (helper process inside the app) |
| Permissions | Accessibility (required), Microphone (only for voice dictation) |
| Background | Starts at login through a login item, Team ID `3NBSP8VQ8T` |
| Network | HTTPS and WebSocket to `goldfish.sh` and its subdomains |
| Updates | Automatic, about once an hour. Can be turned off with `AutoUpdate`. |
| Data | Each person's memory is stored on their own device. See [Privacy](/privacy). |

## Permissions

Goldfish needs **Accessibility** to read on-screen text and to write into
text fields. You can pre-approve it with a PPPC payload. Add an entry for
both bundle IDs, because the helper process has its own permission. Read the
code requirements from an installed copy:

```bash
codesign -dr - /Applications/Goldfish.app
codesign -dr - /Applications/Goldfish.app/Contents/MacOS/goldfish_d
```

The **Microphone** can't be pre-approved by an MDM, so people allow it the
first time they use dictation. Goldfish does not use Screen Recording, Input
Monitoring or Full Disk Access. On Windows, Goldfish needs no special
permissions.

## How Goldfish handles updates

Goldfish checks for updates about once an hour while it runs. When a new
version is available, it downloads it in the background, installs it and
restarts.

Automatic updates need:

- **macOS:** Goldfish in the Applications folder, and a user who is allowed to
  replace the app.
- **Windows:** the default per-user installation.
- **Both:** network access to `goldfish.sh` and its subdomains.

If your policies prevent Goldfish from updating itself, turn automatic
updates off (`AutoUpdate` in [Configure Goldfish with
MDM](/get-started/configure-with-mdm)) and deploy new versions with the
installers below.

## Download the latest installers

These endpoints need no sign-in:

- **macOS:** `https://app.goldfish.sh/download/mac-arm64` (one universal app
  for Apple silicon and Intel)
- **Windows:** `https://app.goldfish.sh/download/win-x64`

Both redirect to the current installer: a `.dmg` for macOS and an `.exe` for
Windows.

## Version-specific download URLs

Package managers need a stable URL. The endpoints above always point at the
newest release, so capture the redirect target instead:

```bash
curl -s -o /dev/null -w '%{redirect_url}\n' https://app.goldfish.sh/download/mac-arm64
```

This returns a permanent URL like
`https://u.goldfish.sh/releases/0.1.56/Goldfish_0.1.56_universal.dmg`.
Compute the SHA256 of the file you download from it for your package
manifest.

## Detect new releases

The current version is public, with no sign-in:

```
https://u.goldfish.sh/latest.json
```

Its `version` field holds the newest release. Check it on a schedule, for
example daily, and package the new installer when it changes.
