macMCP 0.1.0
================

Contents
  MacMCP-0.1.0.pkg          Signed and notarized installer (installs /Applications/MacMCP.app)
  MacMCP-0.1.0.pkg.sha256   Checksum
  Docs/                         README, admin guide, design and threat model
  Profiles/                     Example settings plist, Jamf custom schema,
                                MacMCP-BackgroundItems.mobileconfig (keeps agent/daemon enabled)
  Tools/                        macmcpctl (admin CLI), make-org-key.sh, make-key-profile.sh,
                                encrypt.html (offline secret encryptor)
  Catalog/                      Signed connector catalog bundled with this version

Quick start
  1. Deploy the pkg and Profiles/MacMCP-BackgroundItems.mobileconfig.
  2. Organisation key (skip if you already use Gimle's or Mimir's):
       Tools/make-org-key.sh ~/macmcp-key "Acme macMCP Key"
       Tools/make-key-profile.sh ~/macmcp-key/macmcp-org.p12 '<p12 password>' macmcp-orgkey.mobileconfig
  3. Encrypt secrets: Tools/macmcpctl encrypt --cert ~/macmcp-key/macmcp-org.cert.pem
  4. Settings: upload Profiles/macmcp-jamf-schema.json in Jamf (External Applications), or edit
     Profiles/com.spectrechen.macmcp.plist, check it with Tools/macmcpctl check, deploy it.
  Details: Docs/ADMIN-GUIDE.md

Requirements
  macOS 26 or later, Apple silicon.

Configuration
  Managed preferences domain: com.spectrechen.macmcp

Privacy
  No telemetry. macMCP talks only to the servers an administrator configures and downloads
  the signed catalog from GitHub. Secrets in profiles are encrypted with the organisation key.
