Deploy with Rippling
Install Tokenize on Rippling-managed Macs and Windows PCs with the Rippling enrollment scripts.
If you manage devices with Rippling, use the Rippling scripts from the dashboard. They work like the standard MDM scripts, but they find each person's email on the device, so you don't have to map it per device.
Who can do this: Admins create the enrollment key. A Rippling admin uploads the package and script.
Step 1: Create an enrollment key
- Go to Settings → Downloads and click Deploy with MDM.
- Check the allowed email domains. Click Add another domain if you need more.
- Click Create key and copy it. It's shown once and expires after 90 days.
See Deploy with MDM for how domains limit who can enroll.
Step 2: Download the files
Under Deploy, choose Rippling, then Mac or Windows. Download both:
- Download Mac installer or Download Windows installer (Windows on Arm: Download Arm64 installer)
- Download Mac script or Download Windows script
Step 3: Install and run the script
- In Rippling, install the package on the devices.
- Upload the script in Rippling Scripts. Set it to run as root on Mac or SYSTEM on Windows.
- Add the arguments the dashboard shows, with your key filled in:
- Mac:
--enrollment-token '<your-key>' - Windows:
-EnrollmentToken '<your-key>'
- Mac:
- Assign the script only to the admins and devices in this rollout. Run it after the person assigned to each device has logged in.
Instead of an argument, you can paste the key between the quotes of CONFIGURED_ENROLLMENT_CREDENTIAL="" (Mac) or $script:ConfiguredEnrollmentCredential = '' (Windows) near the top of your copy of the script. The key is then stored in plain text in Rippling's script library and in each device's script cache, so keep the rollout short and don't reuse that copy later.
How the script finds the email
The script tries these sources in order:
- An email you pass with
--email(Mac) or-Email(Windows). If you set one, it's the only one used. - Rippling's agent data on the device.
- On Windows, the signed-in Windows account.
- The accounts the person is signed in to in Claude Code, Codex, and Cursor (Cursor on Mac only).
Tokenize only accepts emails on the key's allowed domains, so personal accounts are refused and the script moves to the next one. The script prints each email it tries and where it came from.
A company-domain login that belongs to someone else, such as a shared team account, would be accepted. If your team shares tool accounts, pass --email / -Email, or add --require-user-match / -RequireUserMatch so only emails that match the computer's username are used.
Pass -Email for your first Windows devices. On either platform, try the script on one or two devices before a full rollout.
Troubleshooting
- "this copy of the script has no enrollment key": add the key as an argument or paste it into the script, then run it again. Exit code 12.
- "device is not eligible for enrollment": none of the emails found are on the allowed domains or in your synced directory. Pass
--email/-Email. - Exit code 11: no logged-in user or no email was found. Run it again while the person is logged in, or pass the email.
The full exit code table is in Deploy with MDM.
Don't also push OrgId or APIKey through managed preferences. They would override the key the script creates.