Tokaware

updated September 30, 2026

Deploying the desktop app

An organization's IT can put the desktop app on every computer with its device management (Intune, Jamf, Group Policy, Kandji and the like): installers that install it for everyone on a computer, and a managed configuration that connects each computer to the organization as soon as someone signs in. Settings, Desktop app gives both with your organization filled in.

Installers

The MSI installs the app in Program Files for everyone on the computer, with a Start menu entry and no desktop icon, and has it start at every sign-in, in the notification area; msiexec /x with the same file removes it. The PKG installs it in Applications and adds a launch agent that starts it at every sign-in, in the menu bar; to remove it, delete /Applications/Tokaware.app and /Library/LaunchAgents/com.tokaware.app.plist. Each installs over an older version.

Installed for everyone, the app does not update itself: install each new version the same way. The EXE, DMG and AppImage, which people install for themselves, keep themselves up to date unless the configuration below turns that off. Every release is on the releases page (tokaware.com/releases), its files at downloads.tokaware.com with the checksum of each in SHA256SUMS.txt.

SystemFileInstalls silently with
Windows, for everyonetokaware-windows-x64.msimsiexec /i tokaware-windows-x64.msi /qn
macOS, Apple Silicontokaware-macos-arm64.pkgsudo installer -pkg tokaware-macos-arm64.pkg -target /
macOS, Inteltokaware-macos-x64.pkgsudo installer -pkg tokaware-macos-x64.pkg -target /
Linuxtokaware-linux-x64.AppImageinstall -m 755 tokaware-linux-x64.AppImage /opt/tokaware/tokaware.AppImage

The managed configuration

What the configuration sets comes before anything chosen in the app, and before the organization's policy where it is stricter. The app reads it when it starts, so a change takes effect the next time it starts. Leave out what you do not set.

KeyValuesWhat it does
organizationThe organization's idComputers connect to this organization only: not as personal computers, and not to another one. Settings, Desktop app shows the id.
requireEnrollmenttrue or falseThe app asks whoever uses it to sign in, and connects the computer to the organization as soon as they have. Needs organization.
lockConnectiontrue or falseNo Disconnect: signing out of the app leaves the computer connected and reporting.
remoteMaxoff, read, edit, fullThe furthest remote sessions may go on the computer (off, read only, edit files, full access), whatever the app's settings and the organization's policy allow.
contentoff, titles, fullThe most of what sessions say that may leave the computer: numbers only, titles too, or conversations too, whatever the organization's policy allows.
autoUpdatetrue or falsefalse: the app never updates itself, and you install new versions with device management.
accountsServerAn https:// addressWhere people sign in and computers report. Leave it out for the hosted service.

Where it goes

On Windows the app reads the policy key in HKEY_LOCAL_MACHINE first, then managed.json in ProgramData, then the same policy key in HKEY_CURRENT_USER: the first with a good value for a key decides it. In the registry, text is a string value and true or false a DWORD of 1 or 0. On macOS it reads the computer's profile before the user's.

SystemWherePushed with
WindowsThe registry key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Tokaware (the .reg file), or the file C:\ProgramData\Tokaware\managed.jsonIntune (a PowerShell script or a Win32 app), Group Policy preferences, or anything that writes the registry or copies a file
macOSA configuration profile for the preference domain com.tokaware.app (the property list)Jamf Pro, Intune, Kandji, Mosyle or any MDM's custom settings
Linux/etc/tokaware/managed.jsonAnsible, Puppet, Chef, or a package of your own

managed.json

For C:\ProgramData\Tokaware\managed.json on Windows and /etc/tokaware/managed.json on Linux.

{
  "organization": "YOUR-ORGANIZATION-ID",
  "requireEnrollment": true,
  "lockConnection": true
}

The registry

A .reg file for the policy key, or the same values set by Group Policy preferences or a script.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Tokaware]
"organization"="YOUR-ORGANIZATION-ID"
"requireEnrollment"=dword:00000001
"lockConnection"=dword:00000001

macOS

The keys for a configuration profile's custom settings, for the preference domain com.tokaware.app. On macOS 13 and later, people are told a background item was added; a managed login items payload for the label com.tokaware.app keeps them from turning it off.

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>organization</key>
  <string>YOUR-ORGANIZATION-ID</string>
  <key>requireEnrollment</key>
  <true/>
  <key>lockConnection</key>
  <true/>
</dict>
</plist>

What people see

  • With requireEnrollment, the app asks whoever uses it to sign in, with a notification when it started out of sight, and connects the computer to the organization as soon as they have, again when someone else signs in there. Someone who is not in the organization is told to ask for an invite.
  • Settings, General says the app is managed by their organization and lists what it sets; the computer's panel says what its IT set, offers no organization but the one named, and no Disconnect with lockConnection.
  • Remote sessions and what sessions say go no further than the configuration and the organization's policy both allow, whatever the app's own settings say.

What the organization sees

The Computers tab marks each managed computer, next to its enrollment, version and settings, and holds it to the organization's policy like any other. Computers without the app can report through Claude Code's and Codex's own telemetry instead (Settings, Collection).