Fixing macOS Permission and TCC Issues
I have spent many hours wondering why an app suddenly stops asking for permissions or why a previously granted access just vanishes. macOS permissions, managed by TCC (Transparency, Consent, and Control), are notoriously picky. If your app signature or path changes even slightly, the system might decide your app is a total stranger and stop showing permission prompts entirely.
Here is how I handle these permission headaches to keep things running smoothly.
What You’ll Need
Section titled “What You’ll Need”- A fixed on-disk path for your app (for OpenClaw, this is
dist/OpenClaw.app). - A consistent bundle identifier.
- An Apple Development or Developer ID certificate.
Quick Start
Section titled “Quick Start”To keep your permissions stable, you need to satisfy macOS’s strict identity requirements. If you don’t, you will find yourself re-granting access every time you rebuild your code.
- Use a fixed path: Always run your app from the same location, such as
dist/OpenClaw.app. - Stick to one bundle ID: If you change the bundle identifier, macOS treats it as a brand-new app.
- Sign your builds: Use a real Apple Development certificate. Ad-hoc signatures change every time you build, which causes macOS to forget your previous permission grants.
- Avoid ad-hoc signing: Only use ad-hoc builds for quick local tests where you do not care about persistent permissions.
Troubleshooting
Section titled “Troubleshooting”When permission prompts stop appearing, the system database is likely confused by stale entries. I use this checklist to force macOS to recognize the app again:
- Quit the app completely.
- Open System Settings > Privacy & Security and remove the app entry manually.
- Relaunch the app from its original path and wait for the prompts.
- If the prompt still fails to show up, reset the TCC entries using the terminal.
Use these commands to reset specific permissions (replace the bundle ID if yours is different):
sudo tccutil reset Accessibility bot.molt.macsudo tccutil reset ScreenCapture bot.molt.macsudo tccutil reset AppleEventsIf these steps fail, restart your Mac. Some TCC changes only take effect after a full system reboot.
File and folder access
Section titled “File and folder access”If your app hangs while trying to read files in Desktop, Documents, or Downloads, macOS is likely blocking the process. You must grant access to the specific context running the code, such as your Terminal, iTerm, or an SSH process.
If you want to avoid these per-folder permission prompts, I recommend moving your files into the workspace at ~/.openclaw/workspace.
If you have more questions about your specific environment, check the AI Setup Assistant.
What’s Next
Section titled “What’s Next”OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.