PayloadKit

Privacy Preferences Policy Control

com.apple.TCC.configuration-profile-policy

The payload that configures privacy preferences.

macOS
macOS 10.14+combined

Configuration Keys (1)

KeyTypeTitle
Servicesrequired

A dictionary whose keys are limited to the privacy policy control services. In the case of conflicting specifications, the most restrictive setting (deny) is used.

dictServices
Accessibility

Specifies the policies for the app via the Accessibility subsystem. The ability to grant access by this profile is deprecated as of macOS 26.2, and will be removed in macOS 27.0.

arrayAccessibility
AppleEvents
arrayAppleEvents
BluetoothAlways

Specifies the policies for the app to access Bluetooth devices.

arrayBluetooth Always
Calendar
arrayCalendar
Camera
arrayCamera
AddressBook
arrayContacts
FileProviderPresence
array
ListenEvent
array
MediaLibrary
array
Microphone
arrayMicrophone
Photos
arrayPhotos
PostEvent

Specifies the policies for the application to use CoreGraphics APIs to send CGEvents to the system event stream.

arrayPostEvent
Reminders
arrayReminders
SystemPolicyAllFiles
arraySystemPolicyAllFiles
ScreenCapture
array
SpeechRecognition
array
SystemPolicyDesktopFolder
array
SystemPolicyDocumentsFolder
array
SystemPolicyDownloadsFolder
array
SystemPolicyNetworkVolumes
array
SystemPolicyRemovableVolumes
array
SystemPolicySysAdminFiles
arraySystem Policy Sys Admin Files
SystemPolicyAppData

Allows the application to access data of other apps.

array
SystemPolicyAppBundles
arrayApp Management
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
AEReceiverIdentifierrequired

The identifier of the process receiving an ApplEvent sent by the Identifier process.

stringAEReceiverIdentifier
AEReceiverIdentifierTyperequired

The type of AEReceiverIdentifier value.

Range: Bundle ID (bundleID), Path (path)

stringAEReceiverIdentifierType
AEReceiverCodeRequirementrequired

Code requirement for the receiving binary.

stringAEReceiverCodeRequirement
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Authorization

The 'Authorization' key is an optional replacement for the 'Allowed' key. Every payload must specify either 'Authorization' or 'Allowed', but not both. 'Allow': Equivalent to a 'true' value for the 'Allowed' key. 'Deny': Equivalent to a 'false' value for the 'Allowed' key.

Range: Allow, Deny

string
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment
IdentityDict
dict
Identifierrequired

The bundle ID or installation path of the binary.

string
IdentifierTyperequired

The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.

Range: bundleID, path

string
CodeRequirementrequired

Obtained via the command ''codesign -display -r -''.

string
StaticCode

If 'true', statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

boolean
Allowedrequired

If 'true', access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.

boolean
Authorization

The 'Authorization' key is an optional replacement for the 'Allowed' key. Every payload must specify either 'Authorization' or 'Allowed', but not both. 'Allow': Equivalent to a 'true' value for the 'Allowed' key. 'Deny': Equivalent to a 'false' value for the 'Allowed' key. 'AllowStandardUserToSetSystemService:' allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization. 'AllowStandardUserToSetSystemService' is only valid for the 'ListenEvent' and 'ScreenCapture' services. Available in macOS 11 and later.

Range: Allow, Deny, AllowStandardUserToSetSystemService

string
Comment

Not used.

string
AEReceiverIdentifier

The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.

string
AEReceiverIdentifierType

The type of AEReceiverIdentifier value, either 'bundleID' or 'path'. This setting is required for AppleEvents service; not valid for other services.

Range: bundleID, path

string
AEReceiverCodeRequirement

The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.

string
Servicesrequired

Keys are limited to the privacy service names listed below. Each key is an array of dictionaries describing the app or process to which access is given. In the case of conflicting specifications, the most restrictive setting (deny) will be used.

dictServices
Identifierrequired

The bundle ID or installation path of the binary.

stringIdentifier
IdentifierTyperequired

The type of Identifier value.

Range: Bundle ID (bundleID), Path (path)

stringIdentifier Type
CodeRequirementrequired

The designated requirement describing the code signature of this executable.

stringCode Requirement
StaticCode

If set to true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.

booleanStaticCode
Allowed

If set to true, access is granted. Otherwise the process does not have access. The user is not prompted and cannot change this value.

Range: Deny (false), Allow (true)

booleanAllowed
Comment

Not Used

stringComment