install-claude-macos.sh and install-chatgpt-macos.sh. Admin offers them to copy into your RMM, or, for N-sight RMM and without an RMM, to download as mspilot-install-claude-macos.sh and mspilot-install-chatgpt-macos.sh. They are separate from the agent enroll script, which installs only the MSPilot agent.
What the scripts do
Each script runs as root and works on/Applications/Claude.app or /Applications/ChatGPT.app:
- It reads the version that is installed, if any.
- It asks the vendor’s own update feed for the newest version. Anthropic rolls Claude releases out in stages, so the script asks the feed the same way the app does, and Macs can get a new version in different weeks. The script sends a hash derived from the Mac’s hardware UUID, not the UUID itself.
- When the app is current, it changes nothing.
- Otherwise it downloads the vendor’s package and checks it before it installs anything: signed with the vendor’s Developer ID Installer certificate (Anthropic PBC, Team ID
Q6L2SF6YDW; OpenAI OpCo, LLC, Team ID2DC432GLL2), notarized by Apple, and holding the expected app and version. - It installs the package with macOS
installer, then checks the installed app’s signature and version again.
status=deferred_running, and the next scheduled run upgrades it. The script checks before the download and again right before it installs, because the download can take minutes.
After an install or upgrade on a Mac with the MSPilot agent, the script starts the signed-in user’s config pull, so the new app is pointed at the gateway right away. Other users get it at their next sign-in, then hourly.
Requirements
- Tested on macOS 15 and later. Claude and ChatGPT support macOS 13, and the scripts stop on anything older.
- ChatGPT needs an Apple Silicon Mac. Claude runs on Apple Silicon and Intel Macs, but the MSPilot agent itself needs Apple Silicon.
- Root. Run the scripts as root, like the enroll script. Nobody needs to be signed in.
Get the scripts
- Open the client and go to Deployment, or open Scripts and pick the client.
- Pick macOS.
- Tick Claude Desktop, ChatGPT, or both: under AI applications on Deployment, or under AI apps to install on Scripts, where both start ticked. You get one script per app.
Save each script in your RMM the same way as the enroll script, with the fields on your RMM’s page:
Each package is several hundred megabytes. On a slow link the script tries the package download at most twice, 20 minutes each, before it reports
download_failed, and the install itself takes more time after that. Give the job a timeout of at least 1 hour (3600 seconds).
On one Mac without an RMM, download the file, then run it in Terminal and type the Mac’s administrator password:
Schedule it weekly
Schedule each script weekly in your RMM, or in your MDM. A run installs the app when it is missing, upgrades it when the vendor has a newer version, and otherwise changes nothing. Users without administrator rights cannot install the apps’ own updates into/Applications, so the weekly run is what keeps the apps current.
Results
A successful run prints oneclaude_install_ok or chatgpt_install_ok line and exits 0. A ChatGPT run can also print a warning line.
The same
status=deferred_running week after week means the app never closes on that Mac, or a process imitates it. Check the Mac.
A failure prints claude_install_failed reason=<reason> or chatgpt_install_failed reason=<reason> and exits 1. For every reason above installer_failed in the table, the app on the Mac is unchanged. installer_failed and post_install_verify_failed come after macOS installer started; with post_install_verify_failed the package was installed but the app did not verify. Check the Mac in both cases.
ChatGPT package behind its feed
OpenAI publishes one unversionedChatGPT.pkg. After a release it can trail OpenAI’s update feed for hours. The script installs or upgrades whenever that package is newer than the app on the Mac, and otherwise reports status=already_current. When the script checks the package and it is older than the feed’s newest version, the script also prints this line and still exits 0. It does not check the package, and prints no warning, when the Mac already has the feed’s version or the app is open.
/Library/Application Support/MSPilot/apps/chatgpt-pkg.state, so an unchanged package is not downloaded again. The file is only a cache. When it is missing, or its owner or permissions are not what the script wrote, the script downloads the package again.
ChatGPT Classic
When/Applications/ChatGPT.app is the older ChatGPT Classic, OpenAI’s package keeps it and renames it to ChatGPT Classic.app, then installs the new ChatGPT. When /Applications/ChatGPT Classic.app already exists, the package cannot rename the old app, so the script stops with classic_path_occupied. Remove or rename one of the two apps, then run the script again.
MSPilot configures only the new ChatGPT. It does not configure or restart ChatGPT Classic.
N-sight RMM: install from a URL
For N-sight RMM, Deployment and Scripts (once you pick the client) also show direct links to the vendors’ packages when Admin can look them up. The N-sight guide for the MDM install method lists them too, as optional steps. You can use them with N-sight’s Install Application from URL Automated Task: put the link in Command Line and run the task once. The URL task installs once; the weekly script keeps the app current. To deploy the agent itself from N-sight Device Management for Apple, see macOS MDM.From an MDM
To keep the apps current from your MDM, run the same scripts there. Get them on Deployment or Scripts as above, add each one to your MDM as a shell script that runs as root, and schedule it weekly with a timeout of at least 1 hour. On Deployment, the MDM install method shows the same script buttons above the MDM steps. Or deploy the vendors’ signed packages from your MDM instead of running the scripts:- Claude: the
.pkgfrom Anthropic’s Deploy Claude Desktop for macOS. - ChatGPT:
https://persistent.oaistatic.com/codex-app-prod/ChatGPT.pkg. OpenAI’s app updates guide covers the app’s updater.
- Claude reads the managed preference
disableAutoUpdatesin the domaincom.anthropic.claudefordesktop. See Anthropic’s enterprise configuration. - ChatGPT reads
[features] in_app_updates = falsefromrequirements.toml, through ChatGPT’s managed configuration or the MDM domaincom.openai.codexkeyrequirements_toml_base64.