Deploy on Windows

Install the Tokenize MSI with Intune or Group Policy, enroll each PC, and push settings through the registry.

On Windows, Tokenize ships as a signed MSI. It installs the background app for every user on the PC and runs it on a schedule. This article covers what IT needs to know for a fleet rollout.

Who can do this: Windows administrators. An Admin in Tokenize creates the enrollment key.

Pick the right installer

Get the installers from Settings → Downloads → Deploy with MDM, or from https://app.tokenizehq.com/download/shipper.

  • Download Windows installer is for x64 PCs.
  • Download Arm64 installer is for Windows on Arm PCs.

For a silent install:

msiexec /i <installer>.msi /qn

The MSI installs to C:\Program Files\PalindromeLabs\ (PalindromeLabs is Tokenize's former name) and shows as "Transcript Shipper" in installed apps. You can deploy it with Group Policy software installation or Intune. To upgrade, deploy a newer MSI. It replaces the old version in place.

Enroll each PC

Installing doesn't connect a PC to your workspace. After the MSI is on the PC, enroll it one of these ways:

Until a PC is enrolled, the app runs and does nothing.

The Scheduled Task

The MSI registers a per-user Scheduled Task named dev.palindromelabs.transcript-shipper. It runs every few minutes for each logged-on user, shortly after install and again at each logon. It runs without opening a window.

The task is hidden and sits at the root of Task Scheduler, so you won't see it unless you turn on Show Hidden Tasks. To check it from a command prompt:

schtasks /Query /TN dev.palindromelabs.transcript-shipper

After a successful enrollment, the script starts the task once so the first upload happens right away.

The tray app

The MSI also installs the Tokenize tray app and starts it at every logon. It runs hidden by default and keeps the app up to date. To show the tray icon, set the ShowMenuBarIcon policy to 1 under the tray app key below.

Push settings with Group Policy or Intune

Tokenize reads policy from the registry under:

HKLM\SOFTWARE\Policies\PalindromeLabs\dev.palindromelabs.transcript-shipper

Deliver values with a GPO registry item, an Intune settings catalog entry, or a PowerShell script. Name each value after the setting. Use REG_DWORD with 0 or 1 for on/off settings, REG_SZ for text, and REG_DWORD for numbers. Policy values override anything set on the PC.

Tray app settings go under HKLM\SOFTWARE\Policies\PalindromeLabs\dev.palindromelabs.palbar.

Don't push APIKey or OrgId here. Enrollment writes them for each PC, and a policy value would override the device's own key.

Where files live

WhatLocation
AppC:\Program Files\PalindromeLabs\
Device enrollmentC:\ProgramData\PalindromeLabs\config.json (readable by users, writable only by admins)
Per-user log%LOCALAPPDATA%\dev.palindromelabs.transcript-shipper\Logs\shipper.log
Enrollment script logC:\ProgramData\TranscriptShipperEnroll\enroll-windows.log

Uninstall

Run msiexec /x with the MSI, or remove it with your deployment tool. Uninstalling removes the Scheduled Task, the hooks and telemetry settings Tokenize added to Claude Code, Codex, and Cursor, the app, and the device enrollment. Each user's local logs and state stay. Remove any registry policy through GPO or Intune.