Drag ToolPiper out of the disk image into Applications before opening it.
Opening it straight from the mounted .dmg is what produces most of these
errors, and the message macOS shows reads like a signing problem when it is a
location problem.
Install
- Open the downloaded
.dmg. - Drag ToolPiper onto the Applications shortcut inside the window.
- Eject the disk image.
- Open ToolPiper from Applications.
ToolPiper requires macOS 26 or later on Apple Silicon, an M1 chip or newer. It is not distributed through the App Store, so the first launch goes through Gatekeeper rather than through the store's own trust path.
If macOS still refuses to open it
Open System Settings > Privacy & Security, scroll to the Security section, and choose Open Anyway next to the ToolPiper entry. The entry appears only after a refused launch attempt, so try opening the app first.
This is the standard flow for a notarized app distributed outside the App Store.
It also explains why opening from the disk image behaves differently. The
notarization ticket is attached to the .dmg, not to the copy of the app inside
it, so launching that inner copy asks Gatekeeper to confirm notarization over the
network instead of reading a ticket off the app. On a slow or absent connection
that check stalls or fails, and the refusal looks identical to an untrusted app.
macOS also runs a freshly downloaded app from a randomized read-only location
rather than from where you opened it.
Dragging to Applications settles all of it in one step, which is why it is the first thing to try.
What ToolPiper does on first launch
It starts a local server on port 9998 and checks the update feed, which it keeps doing every six hours; an update is offered, never installed on its own. No account and no sign-in. Models are downloaded when you ask for one, not at install time, so a fresh install is small and the first launch is fast.