All skills

Tauri v2+ cross-platform app development with Rust backend. Use when configuring tauri.conf.json, implementing Rust commands (#[tauri::command]), setting up IPC patterns (invoke, emit, channels), configuring permissions/capabilities, troubleshooting build issues, or deploying desktop/mobile apps. Triggers on Tauri, src-tauri, invoke, emit, capabilities.json.

Use this Skill: https://skilld.dev/gh/nodnarbnitram/claude-code-extensions/tauri-v2

This session only. Nothing lands on disk.

referencesupdater-distribution-reference.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Tauri v2+ Updater & Distribution Reference

Contents

  • Part 1: Updater (tauri-plugin-updater)
  • Part 2: Distribution and Signing
  • Part 3: Bundle Configuration

⚠️ Signing is MANDATORY for production updates. Unsigned artifacts will be rejected by the Tauri updater. Production update endpoints MUST use HTTPS.

Part 1: Updater (tauri-plugin-updater)

Install

cargo tauri add updater

Configuration (tauri.conf.json)

{
  "plugins": {
    "updater": {
      "active": true,
      "endpoints": ["https://your-server.com/update/{{target}}/{{current_version}}"],
      "pubkey": "BASE64_PUBLIC_KEY_HERE",
      "dialog": true
    }
  }
}
  • Endpoints: Array of HTTPS URLs.
  • Pubkey: Base64 encoded public key.
  • Dialog: Boolean to show built-in update dialog.
  • HTTPS: Endpoints MUST be HTTPS in production.

Key Generation

cargo tauri signer generate -w ~/.tauri/myapp.key

Outputs: private key file + public key string.

  • Store private key SECURELY. Never commit to repo.
  • Set TAURI_SIGNING_PRIVATE_KEY env var for CI/CD.
  • Set TAURI_SIGNING_PRIVATE_KEY_PASSWORD if key is encrypted.
  • Add pubkey to tauri.conf.json plugins.updater.pubkey.

Signed Build

TAURI_SIGNING_PRIVATE_KEY=... cargo tauri build

Produces: installer file + .sig signature file. Both files must be served from your update server.

Update Server Response Format

The update endpoint must return this JSON format:

{
  "version": "1.0.1",
  "notes": "Bug fixes",
  "pub_date": "2026-04-02T00:00:00Z",
  "platforms": {
    "darwin-aarch64": {
      "signature": "<content of .sig file>",
      "url": "https://your-server/MyApp_1.0.1_aarch64.dmg"
    },
    "windows-x86_64": {
      "signature": "<content of .sig file>",
      "url": "https://your-server/MyApp_1.0.1_x64-setup.exe"
    }
  }
}

Capability Permission

The updater plugin requires capability permission: updater:default

Checking for Updates in Code

use tauri_plugin_updater::UpdaterExt;

#[tauri::command]
async fn check_for_updates(app: tauri::AppHandle) -> Result<String, String> {
    let update = app.updater().map_err(|e| e.to_string())?
        .check().await.map_err(|e| e.to_string())?;
    
    if let Some(update) = update {
        update.download_and_install(|_, _| {}, || {})
            .await.map_err(|e| e.to_string())?;
        Ok("Updated".to_string())
    } else {
        Ok("Already up to date".to_string())
    }
}

Part 2: Distribution and Signing

macOS

  • Code signing requires Apple Developer certificate.
  • Notarization required for distribution outside Mac App Store.
  • Environment vars: APPLE_CERTIFICATE, APPLE_CERTIFICATE_PASSWORD, APPLE_SIGNING_IDENTITY, APPLE_ID, APPLE_PASSWORD, APPLE_TEAM_ID.
  • Command: cargo tauri build handles signing/notarization with env vars set.
  • Bundle type: .dmg, .app.
  • macOS bundles for arm64 (Apple Silicon) and x86_64 are separate.

Windows

  • Code signing requires a code signing certificate (EV or OV).
  • Without signing, SmartScreen warnings appear for users.
  • Self-signed certs are only suitable for development.
  • Env vars for signing: via TAURI_WINDOWS_SIGNING_CERTIFICATE or custom script.
  • Bundle types: .msi (WiX), .exe (NSIS).
  • bundle.windows.certificateThumbprint in tauri.conf.json for direct cert config.

Linux

  • No mandatory code signing, but packaging for distros matters.
  • Bundle types: .deb (Debian/Ubuntu), .rpm (Fedora/RHEL), .AppImage (universal).
  • AppImage is portable but unsigned.
  • For store distribution: use appropriate store SDK.

Part 3: Bundle Configuration

Key bundle section in tauri.conf.json:

{
  "bundle": {
    "active": true,
    "targets": "all",
    "identifier": "com.example.myapp",
    "icon": ["icons/32x32.png", "icons/icon.icns", "icons/icon.ico"],
    "resources": [],
    "copyright": "",
    "category": "Utility",
    "shortDescription": "",
    "longDescription": ""
  }
}

Last verified: 2026-04-02. Check the updater plugin changelog for any updates to the signing/key format.

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides comprehensive and legitimate documentation for Tauri v2 development. It emphasizes the framework's security-first approach, particularly the new capabilities and permissions model. All described behaviors, including plugin usage and the update mechanism, are standard for Tauri and accompanied by appropriate security guidance.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    1/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 3493e21. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago
version
1.0.1
  • Rust
  • tauri
  • desktop-apps
  • mobile-apps
  • ipc
  • cross-platform
  • capabilities
  • serde
  • webview

README badge

README badge for nodnarbnitram/claude-code-extensions/tauri-v2

Builds cross-platform desktop and mobile apps with Rust backends and web frontends using Tauri v2+. Covers command registration, IPC patterns (invoke/emit/channels), capability configuration, state management, and common build/deployment issues. Prevents 8+ typical Tauri setup errors including permission denials, unregistered commands, and mobile build failures.

Generated from the current SKILL.md.

Does this skill work with Tauri v1?
No. This skill is for Tauri v2+ only. It covers the v2 API (e.g., `@tauri-apps/api/core`, the `lib.rs` split for mobile, and v2 capability system).
Can I use this for mobile apps?
Yes. The skill covers both desktop and mobile Tauri builds, including the required `#[cfg_attr(mobile, tauri::mobile_entry_point)]` pattern and Rust target setup.
What IPC patterns does this cover?
The skill documents commands, events, channels, and state management. Deeper IPC decision guidance is in the bundled `references/ipc-patterns.md` file.
Does this cover plugin setup?
Yes. The skill explains how to add plugin permissions to capabilities and references the bundled `references/plugin-reference.md` for official Tauri plugins.
What are the minimum Rust changes needed to add a command?
Add a `#[tauri::command]` function in `lib.rs`, register it in `tauri::generate_handler![]`, add required permissions to `capabilities/default.json`, and call it from frontend with `invoke()`.

Generated from the current SKILL.md. These answers refresh after source changes.