Nefarius.Tools.SignRelay
1.3.0
Prefix Reserved
dotnet tool install --global Nefarius.Tools.SignRelay --version 1.3.0
dotnet new tool-manifest
dotnet tool install --local Nefarius.Tools.SignRelay --version 1.3.0
#tool dotnet:?package=Nefarius.Tools.SignRelay&version=1.3.0
nuke :add-package Nefarius.Tools.SignRelay --version 1.3.0
Nefarius.Tools.SignRelay
.NET global tool — submit files to a SignRelay server, wait for signing (Server-Sent Events), and download the signed outputs. Keeps code-signing keys off the CI runner entirely.
About
signrelay is the CI-facing client for SignRelay. It uploads one or more files to the relay, waits on the job’s SSE stream until the Windows agent finishes signtool, then downloads the signed artifacts (--output or --in-place).
Features
- Single verb:
submit - Bearer auth via
--tokenorSIGN_RELAY_CI_TOKEN - SSE wait with configurable
--timeout(default 45 minutes) --dry-run— validate args and print the job manifest without contacting the server- Stable exit codes
0–6for CI scripting
Supported systems
| Component | OS | Architecture | Runtime |
|---|---|---|---|
| CLI (this tool) | Windows, Linux, macOS | x64, Arm64 | .NET 10 runtime or SDK |
| Signing agent (separate) | Windows 10 / 11 only | x64 (primary) | Self-contained release zip; not required on the CI runner |
Unsupported: using this tool as a substitute for local signtool without a running SignRelay server and online agent.
Install
dotnet tool install --global Nefarius.Tools.SignRelay --version 1.0.0
Omit --version only when you intentionally want the latest NuGet version. Prefer pinning. Command name: signrelay.
Requires a running SignRelay server (same major release as this tool; see releases) and a CI token matching SignRelay__CiToken.
Quick start
signrelay submit \
--server https://relay.example.com \
--token "$SIGN_RELAY_CI_TOKEN" \
--output ./signed \
./artifacts/MyApp.exe
Usage
signrelay submit --server <url> [--token <token>] (--output <dir> | --in-place) [options] <files>...
Options
--server <url>(required) — Base URL of the SignRelay server, e.g.https://relay.example.com.--token <token>/-t <token>— CI bearer token. Falls back to theSIGN_RELAY_CI_TOKENenvironment variable.--output <dir>— Write signed files under this directory, preserving relative paths.--in-place— Overwrite each input file with its signed copy. Mutually exclusive with--output.--timeout <timespan>— Maximum time to wait for signing to complete. Default:00:45:00(45 minutes).--allow-insecure— Allowhttp://server URLs. Not recommended; bearer tokens are sent in cleartext.--dry-run— Validate arguments and resolve input files, print the job manifest, then exit without contacting the server.
Either --output or --in-place must be specified, but not both.
Arguments
<files>...(required) — One or more explicit paths to the files to sign. The CLI does not expand globs.
Exit codes
| Code | Meaning |
|---|---|
| 0 | Success |
| 1 | Unexpected error |
| 2 | Invalid arguments or bad input |
| 3 | Server rejected the submit (4xx/5xx) |
| 4 | Signing failed on the agent side |
| 5 | Timeout or connection lost before signing completed |
| 6 | SSE stream ended without a terminal event (server or proxy issue) |
Environment variables
SIGN_RELAY_CI_TOKEN— CI bearer token. Used when--tokenis not passed.
Build prerequisites (contributors)
| Tool | Version |
|---|---|
| .NET SDK | 10.0.100 minimum (rollForward: latestFeature in repo global.json) |
| Git | 2.40+ (required; MinVer release tags use a v prefix, e.g. v1.0.0) |
Pin the source tree to a release tag (replace v1.0.0 with the tag you are building). This repository does not ship NuGet packages.lock.json files, so restore is not --locked-mode.
git clone --branch v1.0.0 --depth 1 https://github.com/nefarius/SignRelay.git
cd SignRelay
dotnet restore SignRelay.sln
dotnet pack src/SignRelay.Cli/SignRelay.Cli.csproj -c Release -o ./artifacts/nuget
Or via NUKE:
./build.sh PackCli
.\build.ps1 PackCli
Support policy
- Use the SignRelay issue tracker for defects in this tool.
- Operational setup (relay URL, tokens, proxies, certificates) is out of scope for the issue tracker — read CI-INTEGRATION.md and DEPLOYMENT.md first.
- Issues without reproduction details may be closed.
Server and agent setup
- Repository: nefarius/SignRelay
- CI integration: docs/CI-INTEGRATION.md
- Agent install: docs/AGENT-SETUP.md
- Deployment: docs/DEPLOYMENT.md
License
MIT — Copyright (c) 2026 Benjamin Höglinger-Stelzer.
Legal / trademark notes
Windows, .NET, and other product names are trademarks of their respective owners. References here are for identification only.
Sources / credits
- Project: nefarius/SignRelay
- CLI parsing: System.CommandLine
- Versioning: MinVer
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.3.0 | 252 | 9/3/2026 |
| 1.2.0 | 110 | 9/2/2026 |
| 1.1.1 | 104 | 9/2/2026 |
| 1.1.0 | 103 | 9/2/2026 |
| 1.0.0 | 108 | 9/2/2026 |
| 1.0.0-pre010 | 87 | 9/1/2026 |
| 1.0.0-pre009 | 103 | 9/1/2026 |
| 1.0.0-pre008 | 118 | 7/29/2026 |
| 1.0.0-pre007 | 100 | 7/28/2026 |
| 1.0.0-pre006 | 100 | 7/28/2026 |
| 1.0.0-pre005 | 100 | 7/28/2026 |
| 1.0.0-pre004 | 104 | 7/28/2026 |
| 1.0.0-pre003 | 96 | 7/28/2026 |
| 1.0.0-pre002 | 115 | 7/28/2026 |
| 1.0.0-pre001 | 109 | 4/13/2026 |