Skip to main content

Overview

To diagnose most issues, run:
Then reproduce the issue in a supported AI application and watch the log. If the client never arrived on the device in the first place, start with Fleet and MDM instead.

Fleet and MDM

The app was added with the wrong app type. 0x87D13B67 is not an install failure — it means Intune has no install status for the app at all, which is also why nothing about Velatir appears in the device logs.Velatir installs a background agent under /Library, uses install scripts, and places a small stub bundle (not the self-updating host) at /Applications/Velatir.app. Intune’s Line-of-business app type cannot handle that shape: with Install as managed set to Yes it supports only a package containing a single application that installs into /Applications, and either way it detects an install solely by finding an application bundle. A quick way to tell which type you used: if the app’s properties show an Install as managed field, it is a line-of-business app.Delete the app in Intune and add it again as macOS app (PKG), following Enterprise deployment. Check the Included apps list as you go — an entry of com.velatir.agent.bootstrap is the package identifier rather than an application, and while it is listed the install can never be detected.
The detection rule never matches, so Intune keeps concluding the app is missing and installs it again. Confirm it on one device by looking at the install history, which should show one install rather than several in a week:
Fix the rule as described in Enterprise deployment: Included apps must hold com.velatir.desktopapp and not com.velatir.agent.bootstrap, with Ignore app version set to Yes.Worth correcting promptly rather than treating as noise. Each reinstall restarts the agent, so devices drop out of the dashboard for a few minutes at a time, and while the agent is down the browser extension on macOS asks users for an ingest key: Microsoft Edge does not deliver managed configuration to extensions on macOS, so the agent is what hands the extension its key.
The agent daemon is not running. Ask launchd what it holds for it:
Then start it:
If bootstrap reports Input/output error, the label is either still being torn down, in which case waiting a few seconds and repeating clears it, or it is blocked from loading. macOS 13 and later can disable background services and an MDM can control that list, so check both:
A disabled item has to be re-enabled wherever it was disabled: System Settings → General → Login Items & Extensions for a user choice, or a Managed Login Items payload from your MDM on a managed fleet.
The installer never ran, so there is nothing on the device to find. Check in this order:
No package receipt and nothing in install.log puts the problem in the MDM rather than on the device. With Intune, the Microsoft Intune management agent for macOS is what runs the installer, and configuration profiles arrive over a different channel — so profiles applying successfully tells you nothing about whether apps can install.To rule out the package itself, install it by hand on one device:
Check what actually reached the device:
If that prints nothing, the profile is not delivering the key. The preference domain must be com.velatir.agent and the key must be named exactly ApiKey. INGEST_KEY is the Windows MSI property and has no meaning in a configuration profile, so a profile using that name applies without error and does nothing.Set the key directly to get the device working now, then correct the profile:
Installing without an ingest key completes successfully, but the agent cannot finish setting itself up — so /Applications/Velatir.app is left pointing at nothing and will not open.Supply the key. The agent finishes setup on its next check, within a few minutes:
Across a fleet this usually means the app reached the devices but the profile carrying the ingest key did not. Confirm the profile is scoped to the same devices as the app.

Interception

Confirm in this order:
  1. Velatir is running. velatir status should show capture active.
  2. Ingest key configured. velatir get-config should show a masked ingest key. If empty, set it: velatir set-api-key --key vltr_....
  3. The application is supported. Velatir captures only supported applications. See Overview.
  4. Certificate trust. Some runtimes use their own trust store. See Certificate not trusted by a specific runtime.
  5. Network reachability. The device must reach api.velatir.com: curl -I https://api.velatir.com.
If all check out, run velatir logs --host -f while reproducing and share the output with support.
This is expected. Velatir only captures supported AI applications; everything else is passed through untouched.To request coverage for an application, contact your account team with the application name, vendor, operating system, and the AI provider it talks to (for example, “Editor X on Windows talks to api.anthropic.com”).
Windows: usually the install did not complete correctly. Reinstall the MSI with administrator elevation. If it persists, run velatir logs -f while attempting velatir start and capture the error.macOS: usually the system extension has not been approved. Open System Settings → General → Login Items & Extensions → Network Extensions and confirm Velatir is enabled. See Permissions.

Certificates

Browsers and most native apps use the operating system trust store and pick up the Velatir CA automatically. A few runtimes use their own trust store and need explicit configuration.Node.js
On macOS the installer sets this automatically. Restart any Node.js process that was running before the install.Python (requests, urllib)
JVMImport the Velatir CA into the JVM truststore:
curlcurl follows the OS trust store on macOS and Windows. On Linux, point it explicitly:
Some applications only trust one specific certificate and reject any other. There is no workaround; Velatir detects these connections and passes them through unmodified.If a pinned application is critical to your compliance workflow, contact your account team about coverage options.

Agent and Host

This means the Velatir process is not running.Windows: it runs as the VelatirAgent service. Start it with sc start VelatirAgent from an elevated prompt, or restart the device. If the service is missing, reinstall the MSI.macOS: relaunch Velatir from Applications, or run open /Applications/Velatir.app. If that reports the application cannot be found, it was installed without an ingest key and never finished setting itself up — see Velatir installed, but never started.If it keeps disappearing, run velatir logs -f (it reconnects once the client comes up) and share the output with support.
Velatir restarts itself within 30 seconds if it stops unexpectedly. Frequent restarts usually mean a problem. Inspect the log:
Common causes: an invalid ingest key, a bad bring-your-own CA password, or (rarely) a failed update. Reset to a known-good state by reapplying the ingest key:
Velatir only runs one copy at a time, so an accidental second launch exits silently. This is expected. To restart it:

Updates

Velatir checks for updates periodically. To force a check now:
If the version is still older than expected, or you use a tenant-specific update channel, contact support.
A failed update stays on the previous version. Inspect the log:
A common cause is insufficient disk space. Free up space and retry with velatir update --apply.

Networking

Velatir re-binds on its own when the network changes, so this usually resolves within seconds. If it does not:
See VPN compatibility.
On Windows, Velatir keeps known AI hosts on a connection it can observe; other traffic (including HTTP/3 to non-AI sites) is untouched, so this rarely causes visible issues. On macOS, QUIC is not captured at all.

Getting Help

When you contact support, attach:
These four files describe the state of the desktop client and let support reproduce most issues without further round trips.

Next Steps

FAQ

Quick answers to common questions.

CLI reference

Full command surface for diagnosing and recovering.

Permissions

What the app needs from the operating system, and why.

VPN compatibility

Detail on coexistence with corporate VPNs.