Deploy with MDM

Create an enrollment key and roll Tokenize out to managed Macs and Windows PCs with your MDM.

For a company-wide rollout, IT installs the Tokenize package with your MDM and then runs a short enrollment script on each computer. The script gives every device its own key, tied to the person who uses it. Nobody has to sign in by hand.

Who can do this: Admins create the enrollment key. Your IT team runs the deployment.

Before you start

  • Your MDM must be able to install a package and then run a script as root (Mac) or SYSTEM (Windows).
  • Run the script while the device's user is logged in. Enrollment stops if it can't find a logged-in user.
  • Use Rippling? Follow Deploy with Rippling instead. The Rippling scripts find each person's email for you.

Step 1: Create an enrollment key

  1. Go to Settings → Downloads and click Deploy with MDM.
  2. Under Create an enrollment key, check the domains listed in "Enrollment will allow emails on …". To add a subsidiary or second domain, click Add another domain and enter them separated by commas.
  3. Click Create key.
  4. Copy the key. It's shown once. Give it to IT through a secure channel, not email or a shared doc.

The key expires after 90 days. It can only register devices for people with an email on the allowed domains. If you use directory sync, the person must also be in your synced directory.

Step 2: Download the installer and script

Under Deploy, choose Other MDM for How does IT deploy?, then choose Mac or Windows.

  • Click Download Mac installer or Download Windows installer. Windows on Arm devices need Download Arm64 installer.
  • Click Download Mac script (enroll-macos.sh) or Download Windows script (enroll-windows.ps1).

Step 3: Install, then enroll

  1. Deploy the installer to the devices.
  2. After it installs, run the script as root or SYSTEM. Fill in each person's email and a stable device ID (for example a serial number) from your MDM's variables.
  3. Pass the enrollment key as a secret environment variable named ENTAI_ENROLL_CREDENTIAL, so it doesn't appear in logs.

Mac:

chmod 700 ./enroll-macos.sh
sudo -E ./enroll-macos.sh --email '<employee-email>' --device-id '<device-id>'

Windows:

Set-ExecutionPolicy -Scope Process Bypass
.\enroll-windows.ps1 -Email '<employee-email>' -DeviceId '<device-id>'

If your MDM can't set environment variables, pass the key with --enrollment-token (Mac) or -EnrollmentToken (Windows). Arguments can be visible to other admin processes while the script runs, so the environment variable is safer.

The script checks the installed app's signature, enrolls the logged-in user, and runs a status check. It never prints the enrollment key or the device key. On Windows it writes a log to C:\ProgramData\TranscriptShipperEnroll\enroll-windows.log. For Windows details, see Deploy on Windows.

Running the script again on the same device for the same person replaces that device's old key.

Exit codes

CodeMeaningWhat to do
0Enrolled and status verifiedNothing
1General enrollment failureCheck the script output
2Enrollment key rejectedStop the rollout and revoke the key
3Network, rate-limit, or server errorRetry later
10App signature invalidCheck the package you deployed
11No logged-in user, or (with --require-user-match) the username doesn't match the emailFix the user assignment
12Missing or invalid arguments, or not run as root/SYSTEMFix the script settings in your MDM
13App not installedInstall the package before the script
14Enrolled, but the status check failedCheck the device
15Windows Scheduled Task couldn't be registeredRepair the MSI install

An email outside the allowed domains fails with "device is not eligible for enrollment".

Don't use API keys from Settings → API keys

Keys you create under Settings → API keys are marked Usage only. A device using one sends usage, but never receives guidance, model policies, MCP servers, or app updates. Always enroll devices with the script.

For the same reason, don't put APIKey or OrgId in a managed preferences profile. Managed values override the device's own key.

After the rollout

Treat the enrollment key like a password. Devices you've already enrolled keep working after the key expires. If a key leaks or you see exit code 2, contact your Tokenize account team to revoke it.