Download
scmtr DSC Signer
A small utility that signs a filing with your own DSC token without leaving the app. It runs quietly in the background while you file, and does nothing the rest of the time.
Version 1.1.1 · free · Windows and macOS
Windows
Most filers want the Intel/AMD build. Choose ARM only if you know your machine is a Windows-on-ARM device.
Install it on Windows
- 1. Run the installer you downloaded. Windows may show “Windows protected your PC” the first time and hide the button behind More info → Run anyway. Read the publisher on that dialog before you click: it should say TAGQA Pty Ltd. The prompt appears because Windows builds reputation for a signing certificate from the installs it has seen, and this one is new — not because anything was found in the program. Verify the download against the checksums below if you want to be sure. Once it has run, the downloaded file is no longer needed — the Signer is installed under your user profile, and deleting the installer from Downloads does not stop it.
- 2. It asks nothing and needs no administrator rights. A progress bar, then done; it installs under your own user profile. No window opens afterwards — the signer sits in the notification area, where a right-click on the scmtr icon shows its version and port, opens its log, or quits it.
- 3. Plug in your DSC token and go back to the filing. On Windows the signer reads your certificate from the Windows certificate store, so there is no file to point it at and no password to type here.
Check it is running
Open http://127.0.0.1:13913/health in any browser. A short block of text naming the version means it is running; a connection error means it is not, and the Start menu entry scmtr DSC Signer starts it.
It starts with Windows, and updates in place
After a restart it is already running; you do not launch it before filing. To update, run the newer installer over it — it closes the running copy, replaces it and starts the new one, with nothing to uninstall first. The app refuses a signer older than it needs and says so with both version numbers.
Verify what you downloaded
In PowerShell, compare the result against the published checksums:
Get-FileHash $HOME\Downloads\scmtr-dsc-signer-1.1.1-win-x64.exe -Algorithm SHA256
macOS
Apple Silicon is any Mac with an M-series chip. Browsers cannot tell the two apart, so pick the one matching your machine — an Apple Silicon build will not run on an Intel Mac.
Install it on macOS
Paste this into Terminal. It picks the right build for your Mac, checks it against the published checksums, and installs it — with none of the Gatekeeper trouble a double-clicked download runs into.
curl -fsSL https://downloads.scmtr.io/install-mac.sh | sh
It is a short script and it is worth reading first — open it , or download it and run it separately if you prefer not to pipe anything into a shell.
Or do it by hand
cd ~/Downloads tar -xzf scmtr-dsc-signer-*-mac-*.tar.gz ./scmtr-sign -pkcs12 /path/to/your-dsc.p12
Unpack with tar rather than by double-clicking. If you already double-clicked and saw “Apple could not verify … is free of malware”, that is the quarantine tag rather than a finding about the program — clear it once with xattr -d com.apple.quarantine ~/Downloads/scmtr-sign.
macOS support exists mainly for testing — a Mac has no Windows certificate store, so the signer reads your DSC from a PKCS#12 (.p12) file rather than a USB token. If you file on Windows, none of this applies.
Cannot install software on your work machine?
You can still file. When Sign & upload finds no signer on the computer, the dialog that offers this download also offers Sign on ICEGATE: the platform hands you the frozen file, you sign it on ICEGATE's own portal with your DSC, and upload it back to the same filing. Nothing about the filing changes between the two routes — the same bytes are signed, and the same checks run before anything is sent.
What it does, and does not do
- It never sees your declaration. The app sends it a 32-byte fingerprint of the frozen filing — not the consignee, the bill of lading, or anything else on it.
- Your private key never leaves your token. The token performs the signature itself and asks you for its PIN, exactly as it does on ICEGATE's own portal.
- It signs for this site and nothing else. The addresses it will answer are built into the program — scmtr.io and www.scmtr.io — and every other page asking it to sign is refused. There is no prompt to click through, because a prompt is the thing a lookalike domain would be counting on.
How a filing is signed
Press Sign & upload on a finished filing. The platform freezes it to exact bytes, the signer asks your DSC token for a signature — your token asks for its PIN — and the signed filing is verified against those bytes and sent to ICEGATE. If several certificates are present you are asked which, with each one's holder, issuer and dates shown.