Skip to main content
Velatir for Desktop is a standard MSI (Windows) and PKG (macOS). One ingest key configures every device: no per-feature flags, no per-customer builds.

Build the installer and profiles

Generate an ingest key on the Setup tab of the Velatir dashboard. The same key works for every device. Opening this guide from the dashboard carries the key across, so the builder below is already filled in. On Windows the key is an installer property. On macOS it lives in MDM Deployment: download the profile and the two optional quiet-install profiles, then assign them with the package. The profile also force-installs the Velatir browser extension, so a later MDM check-in keeps the extension installed.
The macOS profile from the builder force-installs the Velatir extension for Chrome, Edge, Firefox, Vivaldi, and Brave, and writes the ingest key into each extension’s managed storage. Deploy this profile on its own. Do not also deploy the browser extension profile, and do not upload it beside an existing configuration profile for one of those browsers: macOS does not merge those payloads, so one profile’s extension list replaces the other. If you already manage one of those browsers, add Velatir’s force-install entry to that profile and set the agent key separately. Jamf Application & Custom Settings for domain com.velatir.agent and key ApiKey sets only the agent key and does not force-install the extension.Firefox reads extension policy only when EnterprisePoliciesEnabled is true. This profile sets that. Edge is force-installed here as well; when Edge does not read extension managed storage, the desktop app supplies the key.

Deploy with your MDM

Pick your platform. Each path is: upload the installer, assign the ingest key, assign to device groups.
Assign Velatir to device groups, not user groups. It is a per-machine agent — a Windows service, a macOS LaunchDaemon — so it has to land on the device itself. A user assignment either never installs it, or waits until a targeted user signs in.
  1. Apps → All apps → Add → Line-of-business app. Upload the MSI from the builder.
  2. Command-line arguments: paste the Intune arguments from the builder.
  3. Assign Required to device groups, not user groups. Intune handles elevation.
To rotate the key, update the arguments and redeploy.
  1. Upload the PKG under Packages. Policy: Recurring Check-in, Once per computer.
  2. Upload the .mobileconfig from the builder, scoped to the same Macs. It sets the ingest key and force-installs the browser extension. Application & Custom Settings with domain com.velatir.agent and key ApiKey sets only the agent key.
  3. Upload the background items and notifications profiles from the builder (or create them in Jamf: Team Identifier AA7QLU3S4R, bundle ID com.velatir.desktopapp, alert type Alert). Assign these first so macOS never shows the background-items prompt.
Rotate the key by re-downloading the profile from the builder and replacing it — no reinstall. Replacing only ApiKey leaves the extension on the old key.
Use macOS app (PKG), not Line-of-business app.
  1. Apps → All apps → Create → macOS → macOS app (PKG). Upload the PKG from the builder.
  2. Detection rules: delete com.velatir.agent.bootstrap. Add one entry: bundle ID com.velatir.desktopapp, Ignore app version: Yes. Confirm one Mac shows Installed before you go wide — the wrong rule reinstalls Velatir at every check-in. See troubleshooting.
  3. Requirements: macOS 13.0. Assign Required to device groups, not user groups.
  4. Devices → Configuration → Create → Profile type: Templates → Custom. Set Deployment channel to Device channel: the agent reads the key from the device-level managed preferences, which only that channel writes, and Intune cannot change the channel of a saved profile. Upload the .mobileconfig from the builder. It sets the ingest key and force-installs the browser extension. Repeat for background items and notifications. Assign all three to the same device groups as the app. The profile can arrive before or after the package: the agent waits for the key and finishes setup within a minute of receiving it. The background-items and notifications profiles only take effect if they arrive first, and the background-items profile is device-channel only, so a user assignment cannot deliver it.
Apple Silicon and Intel are separate packages, assigned to matching device groups. Devices need the Intune management agent (2308.006+) — a profile that applies is not evidence the app can install. Confirm with velatir status or the dashboard Devices view, not Intune alone.
Any tool that runs msiexec (Windows) or installer (macOS) works: use the command from the builder. For a Windows detection rule, check for the VelatirAgent service or the install path C:\Program Files\Velatir\.

Removing Velatir from a fleet

Change the assignment first. While the app is still Required, Intune reinstalls it behind the removal. Windows. Set the assignment to Uninstall. If devices do not come off, deploy the cleanup script in Uninstall cleanup as an Intune remediation running as SYSTEM. macOS. Remove the configuration profile before the app. That profile force-installs the extension and stores the ingest key, and MDM writes both back for as long as the profile stays assigned. velatir-uninstall cannot clear a policy the profile still asserts.
  1. In your MDM, remove the assignment for the profile downloaded from the builder (display name Velatir Desktop Agent, identifier com.velatir.desktopapp.mdm). Remove the background-items and notifications profiles in the same pass if you deployed them.
  2. Let the Mac check in, then confirm the profile is gone. No output means it is gone:
  3. The PKG app type has no Uninstall assignment, so remove the app assignment, then run the bundled uninstaller as a root script under Devices → Scripts:
Chrome, Edge, Vivaldi, and Brave uninstall the extension once the force-install policy is gone. A missing key, or a list that does not contain Velatir’s extension id, is what you want. Chrome, Vivaldi, and Brave use bbiokppljpbjgiogcoggjnfffbeiihja. Edge uses phgnjcoglpdamjjmidheehacjbkgkooc.
The ingest key in extension managed storage goes with the same profile. It lives at apiToken under com.google.Chrome.extensions.bbiokppljpbjgiogcoggjnfffbeiihja, and under the matching domain for Edge, Vivaldi, and Brave. Firefox keeps the extension after the policy disappears. Confirm velatir@velatir.com is absent from ExtensionSettings, restart Firefox, then remove Velatir under Menu → Add-ons and themes → Extensions. If Remove is greyed out, the policy is still applied.
If an older version left a system extension on the device, a restart finishes removing it.

Reference

Windows. Redeploy with the new key in the command-line arguments.macOS. Re-download the profile from the builder and replace it in your MDM. Devices apply the new ingest key for the agent and the extension on the next check-in, with no reinstall.
Optional. Together they stop the “background items added” alert and turn Velatir’s alerts on before anyone sees a prompt. Download them from the builder; assign them to the same Macs as the package, first.The Managed Login Items payload needs macOS 13+ and an MDM; macOS refuses it in a profile a user installs by hand.To mute Velatir’s own update and lifecycle toasts, set ShouldMuteSystemNotifications to true in com.velatir.agent. Blocked-request alerts still appear.
Run velatir status --json as a Microsoft Intune Remediation or a Jamf Pro extension attribute. It reports client state, version, and the last trace timestamp.
Velatir auto-updates by default. To coordinate updates with your own change-management process, contact support to enable a per-tenant update channel.

Next steps

Permissions

What the installer asks for on each platform.

Health checks

Monitor agent health across the fleet.

How it works

What the desktop client does on each device.

Troubleshooting

Diagnose failures during scaled rollouts.