Skip to main content

“You should always download Xcode directly from the Mac App Store, or from the Apple Developer website, and leave Gatekeeper enabled on all your systems to protect against tampered software.

When you download Xcode from the Mac App Store, OS X automatically checks the code signature for Xcode and validates that it is code signed by Apple. When you download Xcode from the Apple Developer website, the code signature is also automatically checked and validated by default as long as you have not disabled Gatekeeper.

Whether you downloaded Xcode from Apple or received Xcode from another source, such as a USB or Thunderbolt disk, or over a local network, you can easily verify the integrity of your copy of Xcode.

To verify the identity of your copy of Xcode run the following command in Terminal on a system with Gatekeeper enabled:
spctl –assess –verbose /Applications/Xcode.app

where /Applications/ is the directory where Xcode is installed. This tool performs the same checks that Gatekeeper uses to validate the code signatures of applications. The tool can take up to several minutes to complete the assessment for Xcode.

The tool should return the following result for a version of Xcode downloaded from the Mac App Store:
/Applications/Xcode.app: accepted
source=Mac App Store

and for a version downloaded from the Apple Developer web site, the result should read either
/Applications/Xcode.app: accepted
source=Apple

or

/Applications/Xcode.app: accepted
source=Apple System

Any result other than ‘accepted’ or any source other than ‘Mac App Store’, ‘Apple System’ or ‘Apple’ indicates that the application signature is not valid for Xcode. You should download a clean copy of Xcode and recompile your apps before submitting them for review.”

Sourced from Apple

Joey Stardust

Joey Stardust Digital Marketing Pioneer | Tech Entrepreneur | Editor-in-ChiefA web enthusiast since the dawn of the digital age (1984), I've left my mark across multiple industries. As Editor-in-Chief of TooSquare Magazine (featured on Wikipedia), I shaped tech and culture discourse during the internet's formative years. My technical roots run deep as the creator of Wurm Mud, an influential DIKU/ROM-based MUD source code that powered early online communities.My entrepreneurial journey includes founding InterZ0n3 Coffee Shop (a hacker-space café before its time) and launching Daddy Zero Clothing, blending subculture with streetwear. Today, I channel this diverse experience into The Real Social Company, where we combine old-school digital wisdom with cutting-edge social media marketing, SEO, and conversion-focused web design.Four decades in tech have taught me this: The platforms change, but the fundamentals of authentic engagement remain constant. Let's use that knowledge to make your brand impossible to ignore.

author avatar
Joey Stardust Founder
With 20+ years in digital marketing, I specialize in helping medical spas, wellness clinics, and healthcare providers dominate their markets. My team and I have partnered with 300+ medical spas nationwide, driving patient acquisition through tailored SEO, conversion-focused web design (WordPress, Wix, Squarespace, Shopify), and data-driven social media strategies.

Joey Stardust Digital Marketing Pioneer | Tech Entrepreneur | Editor-in-ChiefA web enthusiast since the dawn of the digital age (1984), I've left my mark across multiple industries. As Editor-in-Chief of TooSquare Magazine (featured on Wikipedia), I shaped tech and culture discourse during the internet's formative years. My technical roots run deep as the creator of Wurm Mud, an influential DIKU/ROM-based MUD source code that powered early online communities.My entrepreneurial journey includes founding InterZ0n3 Coffee Shop (a hacker-space café before its time) and launching Daddy Zero Clothing, blending subculture with streetwear. Today, I channel this diverse experience into The Real Social Company, where we combine old-school digital wisdom with cutting-edge social media marketing, SEO, and conversion-focused web design.Four decades in tech have taught me this: The platforms change, but the fundamentals of authentic engagement remain constant. Let's use that knowledge to make your brand impossible to ignore.