This repository is part of the source code of Wire. You can find more information at wire.com or by contacting opensource@wire.com.
You can find the published source code at github.com/wireapp/wire.
For licensing information, see the attached LICENSE file and the list of third-party licenses at wire.com/legal/licenses/.
If you compile the open source software that we make available from time to time to develop your own mobile, desktop or web application, and cause that application to connect to our servers for any purposes, we refer to that resulting application as an “Open Source App”. All Open Source Apps are subject to, and may only be used and/or commercialized in accordance with, the Terms of Use applicable to the Wire Application, which can be found at https://wire.com/legal/#terms. Additionally, if you choose to build an Open Source App, certain restrictions apply, as follows:
a. You agree not to change the way the Open Source App connects and interacts with our servers; b. You agree not to weaken any of the security features of the Open Source App; c. You agree not to use our servers to store data for purposes other than the intended and original functionality of the Open Source App; d. You acknowledge that you are solely responsible for any and all updates to your Open Source App.
For clarity, if you compile the open source software that we make available from time to time to develop your own mobile, desktop or web application, and do not cause that application to connect to our servers for any purposes, then that application will not be deemed an Open Source App and the foregoing will not apply to that application.
No license is granted to the Wire trademark and its associated logos, all of which will continue to be owned exclusively by Wire Swiss GmbH. Any use of the Wire trademark and/or its associated logos is expressly prohibited without the express prior written consent of Wire Swiss GmbH.
Cross platform desktop app, wrapping the wire-webapp. Based on Electron.
- Node.js matching the version defined in
.node-version - Npm
- Git
- Yarn (Install using the official instructions at https://yarnpkg.com/lang/en/docs/install/, and not using the package recommended by apt-get)
sudo apt install git npm nodejs
npm install --global yarngit clone https://github.com/wireapp/wire-desktop.git
cd wire-desktop
yarnyarn startyarn testOn company-managed devices, an MDM administrator can force App-lock on, overriding the team-level App-lock setting. The desktop app reads a single applockOverride flag at startup — without spawning any shell command — and forwards it to the webapp as window.desktopAppConfig.managedConfig.
The flag is read from organization-agnostic, Wire-vendor locations (no customer/company name is hardcoded):
| OS | Source | Signal |
|---|---|---|
| Windows | Registry …\SOFTWARE\Policies\Wire (HKLM, HKCU fallback) |
applockOverride value = 1, or the device is MDM-enrolled / Azure-AD joined |
| macOS | App's managed preferences domain (MDM AppConfig profile) | applockOverride boolean = true |
| Linux | /etc/wire/managed.json |
{"applockOverride": true} (presence means managed unless explicitly false) |
For each OS: plant the flag, relaunch the app, then open DevTools on the webapp's <webview> and evaluate window.desktopAppConfig.managedConfig — expect {applockOverride: true}. With nothing planted it must be {applockOverride: false} and the app behaves as before.
Windows (elevated prompt):
reg add "HKLM\SOFTWARE\Policies\Wire" /v applockOverride /t REG_DWORD /d 1 /f
:: relaunch app -> applockOverride === true
reg delete "HKLM\SOFTWARE\Policies\Wire" /fEnrollment is detected automatically on an Intune/MDM-enrolled or Azure-AD-joined machine (no Policies\Wire value needed).
macOS (use the running build's bundle id — production is com.wearezeta.zclient.mac; dev/internal differ):
defaults write com.wearezeta.zclient.mac applockOverride -bool true
# relaunch app -> applockOverride === true
defaults delete com.wearezeta.zclient.mac applockOverrideTo validate the real MDM path (managed-preferences domain):
sudo defaults write "/Library/Managed Preferences/com.wearezeta.zclient.mac.plist" applockOverride -bool trueLinux:
echo '{"applockOverride": true}' | sudo tee /etc/wire/managed.json
# relaunch app -> applockOverride === true
sudo rm /etc/wire/managed.json| Stage | Branch | Action | Version |
|---|---|---|---|
| 1 (Feature development) | (varies) | commit | x.y+3 (e.g. 3.20) |
| 2 (Nightly test automation) | dev | commit or squash merge from feature branch | x.y+2 (e.g. 3.19) |
| 3 (Internal release) | staging | merge (don't squash) from dev | x.y+1 (e.g. 3.18) |
| 4 (Production release) | main | merge (don't squash) from staging | x.y (e.g. 3.17) |
Compare Views
- Updates from "dev" to "staging" (changelog): https://github.com/wireapp/wire-desktop/compare/staging...dev
- Updates from "staging" to "main" (changelog): https://github.com/wireapp/wire-desktop/compare/main...staging
# Build for macOS
yarn build:macos
# Build for Windows
yarn build:win
# Build for Linux
yarn build:linuxOn macOS, desktop SSO uses ASWebAuthenticationSession through the optional objc-js bridge. Authentication runs in a supporting default browser, with Safari as fallback. Windows and Linux retain embedded SSO; the standalone webapp is unchanged.
The macOS flow follows Wire iOS's existing backend contract: a validated callback returns a session cookie to the initiating account. Callback URLs and cookies must not be logged. This is not a single-use-code/PKCE exchange.
macOS packaging unpacks and signs the native bridge using the existing app-signing identity. Browser SSO does not require the former WebAuthn keychain-group entitlement or additional provisioning-profile credentials. Both Jenkins jobs use the configured node-v23.0.0 tool for the upgraded Electron runtime.
Embedded SSO windows support website window.prompt() requests through a local text dialog. This covers passkey labels requested by Keycloak and other providers using the same browser API, without changing the identity provider's theme. The dialog shows the requesting origin, returns entered text on OK and null on cancellation, and closes when the requesting page navigates or closes. Prompt messages and entered values are not logged. This addresses prompt compatibility; each provider's complete login flow still needs testing.
On Windows and Linux, SSO opens in an independent window using the shared persistent persist:wire-sso session. The backend completion callback is checked against the expected origin before copying its Wire login cookie into the requesting account. SSO website storage is cleared on close and before a new login, while passkey session preferences remain. Removing one sub-app/account does not remove this shared session. Reuse requires the same identity-provider account and relying-party ID; unrelated providers still need separate credentials. Deleting the entire desktop user-data directory or the credential in Keycloak is different. In a signed build, test registration, restart, account removal/re-addition, and login from another sub-app.
To test authentication, launch the signed app with --enable-logging and search its logs/YYYY-MM-DD/electron.log (inside Electron's user-data directory) for [Passkeys]. For macOS browser SSO, search for [SSO] to follow session startup, callback validation failures, and cookie installation. Browser authentication does not use the embedded account picker. For embedded WebAuthn, account-picker logs show requests, selection, cancellation, or failure without account names or credential IDs. An account-selection event only occurs when the authenticator needs a choice: its absence does not prove WebAuthn failed. Complete login against the intended identity provider to verify the result. Build checks do not establish authenticator compatibility; test the signed app against the intended IdP.
If you would like to build for another Linux target, run the following command:
export LINUX_TARGET=<target>
yarn build:linuxReplace <target> with your desired target (e.g. rpm). Have a look at the documentation for electron-builder for the available targets. Multiple targets can be combined by comma separation (e.g. rpm,deb). Note that we cannot offer support for uncommon targets.
Furthermore, you can disable asar packaging (not recommended, but e.g. needed for target dir) by setting ENABLE_ASAR="false" before building. Example:
export ENABLE_ASAR="false"
yarn build:linuxIf you are having troubles building Wire for Desktop, then our troubleshooting page might be of help.
All Wire translations are crowdsourced via Crowdin.
You can of course use the webapp in your browser, but if you prefer to install wire-desktop, continue reading here:
https://github.com/wireapp/wire-desktop/wiki/How-to-install-Wire-for-Desktop-on-Linux
