Nefarius.Tools.SignRelay 1.3.0

Prefix Reserved
dotnet tool install --global Nefarius.Tools.SignRelay --version 1.3.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local Nefarius.Tools.SignRelay --version 1.3.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=Nefarius.Tools.SignRelay&version=1.3.0
                    
nuke :add-package Nefarius.Tools.SignRelay --version 1.3.0
                    

Nefarius.Tools.SignRelay

NuGet .NET License

.NET global tool — submit files to a SignRelay server, wait for signing (Server-Sent Events), and download the signed outputs. Keeps code-signing keys off the CI runner entirely.

About

signrelay is the CI-facing client for SignRelay. It uploads one or more files to the relay, waits on the job’s SSE stream until the Windows agent finishes signtool, then downloads the signed artifacts (--output or --in-place).

Features

  • Single verb: submit
  • Bearer auth via --token or SIGN_RELAY_CI_TOKEN
  • SSE wait with configurable --timeout (default 45 minutes)
  • --dry-run — validate args and print the job manifest without contacting the server
  • Stable exit codes 0–6 for CI scripting

Supported systems

Component OS Architecture Runtime
CLI (this tool) Windows, Linux, macOS x64, Arm64 .NET 10 runtime or SDK
Signing agent (separate) Windows 10 / 11 only x64 (primary) Self-contained release zip; not required on the CI runner

Unsupported: using this tool as a substitute for local signtool without a running SignRelay server and online agent.

Install

dotnet tool install --global Nefarius.Tools.SignRelay --version 1.0.0

Omit --version only when you intentionally want the latest NuGet version. Prefer pinning. Command name: signrelay.

Requires a running SignRelay server (same major release as this tool; see releases) and a CI token matching SignRelay__CiToken.

Quick start

signrelay submit \
  --server https://relay.example.com \
  --token "$SIGN_RELAY_CI_TOKEN" \
  --output ./signed \
  ./artifacts/MyApp.exe

Usage

signrelay submit --server <url> [--token <token>] (--output <dir> | --in-place) [options] <files>...

Options

  • --server <url> (required) — Base URL of the SignRelay server, e.g. https://relay.example.com.
  • --token <token> / -t <token> — CI bearer token. Falls back to the SIGN_RELAY_CI_TOKEN environment variable.
  • --output <dir> — Write signed files under this directory, preserving relative paths.
  • --in-place — Overwrite each input file with its signed copy. Mutually exclusive with --output.
  • --timeout <timespan> — Maximum time to wait for signing to complete. Default: 00:45:00 (45 minutes).
  • --allow-insecure — Allow http:// server URLs. Not recommended; bearer tokens are sent in cleartext.
  • --dry-run — Validate arguments and resolve input files, print the job manifest, then exit without contacting the server.

Either --output or --in-place must be specified, but not both.

Arguments

  • <files>... (required) — One or more explicit paths to the files to sign. The CLI does not expand globs.

Exit codes

Code Meaning
0 Success
1 Unexpected error
2 Invalid arguments or bad input
3 Server rejected the submit (4xx/5xx)
4 Signing failed on the agent side
5 Timeout or connection lost before signing completed
6 SSE stream ended without a terminal event (server or proxy issue)

Environment variables

  • SIGN_RELAY_CI_TOKEN — CI bearer token. Used when --token is not passed.

Build prerequisites (contributors)

Tool Version
.NET SDK 10.0.100 minimum (rollForward: latestFeature in repo global.json)
Git 2.40+ (required; MinVer release tags use a v prefix, e.g. v1.0.0)

Pin the source tree to a release tag (replace v1.0.0 with the tag you are building). This repository does not ship NuGet packages.lock.json files, so restore is not --locked-mode.

git clone --branch v1.0.0 --depth 1 https://github.com/nefarius/SignRelay.git
cd SignRelay
dotnet restore SignRelay.sln
dotnet pack src/SignRelay.Cli/SignRelay.Cli.csproj -c Release -o ./artifacts/nuget

Or via NUKE:

./build.sh PackCli
.\build.ps1 PackCli

Support policy

Server and agent setup

License

MIT — Copyright (c) 2026 Benjamin Höglinger-Stelzer.

Windows, .NET, and other product names are trademarks of their respective owners. References here are for identification only.

Sources / credits

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
1.3.0 252 9/3/2026
1.2.0 110 9/2/2026
1.1.1 104 9/2/2026
1.1.0 103 9/2/2026
1.0.0 108 9/2/2026
1.0.0-pre010 87 9/1/2026
1.0.0-pre009 103 9/1/2026
1.0.0-pre008 118 7/29/2026
1.0.0-pre007 100 7/28/2026
1.0.0-pre006 100 7/28/2026
1.0.0-pre005 100 7/28/2026
1.0.0-pre004 104 7/28/2026
1.0.0-pre003 96 7/28/2026
1.0.0-pre002 115 7/28/2026
1.0.0-pre001 109 4/13/2026