DNIe for Mac

Help

The DNIe in Safari, Chrome and Edge on a Mac

Guide updated: · by David Pelayo (nexoapex)

Yes, the DNIe (Spain's electronic national ID card) works in Safari, Chrome and Edge on a Mac, but not on its own: those browsers take certificates from the macOS keychain, and the DNIe only gets there if an app publishes it, such as DNIe for Mac with DNIe Pro. The official, free route is Firefox with the PKCS#11 module.

Why don't Safari, Chrome and Edge see the DNIe?

Because they don't talk to the card: they take certificates from the macOS keychain, and macOS includes nothing that brings the DNIe there. Smart cards reach the keychain through CryptoTokenKit, which, according to Apple's documentation, presents their certificates to apps as keychain items.

What macOS supports out of the box is summed up in Apple's deployment guide: "Apple offers native support for personal identity verification (PIV) smart cards, USB CCID class-compliant readers, and hard tokens that support the PIV standard." That's why the Mac recognizes the reader without drivers. But the DNIe isn't a PIV card: according to the Police, the authentication it uses to open its encrypted channel is based on the European specification CWA 14890.

The Police state that on macOS the electronic ID is used "a través de un módulo criptográfico denominado PKCS#11" (through a cryptographic module called PKCS#11), and their libpkcs11-dnie 1.6.8 package includes no CryptoTokenKit extension. Of the common browsers, Firefox is the one that lets you load a PKCS#11 module.

Where it gets certificates fromWith the official softwareWith DNIe Pro
SafarimacOS keychainDoesn't see the DNIeYes
ChromemacOS keychainDoesn't see the DNIeYes
EdgemacOS keychain (Chromium-based)Doesn't see the DNIeYes
FirefoxIts own store and, by default, the keychain tooYes, by loading the PKCS#11 moduleYes, with no module

Sources: Apple (Safari), the Chromium 153 source code (Chrome) and Mozilla (Firefox), as of 16 September 2026. For Edge we found no Microsoft documentation covering macOS; it is based on Chromium.

To use the DNIe in Safari, Chrome or Edge, an app has to publish it into the keychain. DNIe Pro does that, and other apps on the Mac App Store advertise the same; the official, free route is still Firefox. For a browser-by-browser summary, see how to install the DNIe on a Mac.

How to use the DNIe in Safari, Chrome and Edge with DNIe for Mac

DNIe Pro, the only paid feature of DNIe for Mac, publishes the DNIe into the keychain so that Safari, Chrome and Edge can see it. The app needs macOS 13 or later and a USB contact card reader.

  1. Connect the reader and insert the DNIe. Any CCID-class USB contact reader will do; if you're unsure about yours, see which DNIe card reader works on a Mac.
  2. Install DNIe for Mac. On the Mac App Store it's listed as "DNIe - Firma y autenticación".
  3. Activate DNIe Pro. In "Tu DNIe en el navegador" (Your DNIe in the browser), click "Desbloquear" (Unlock) and choose "Suscripción anual" (Annual subscription), which starts with 3 free days, or "Licencia de por vida" (Lifetime license). If you've already bought it, click "Restaurar compras" (Restore purchases).
  4. Connect the DNIe with your PIN. Click "Conectar" (Connect) and enter the PIN. Inserting the card isn't enough: the app only publishes the DNIe into the keychain after this step, and the "Tu DNIe en el navegador" box confirms it.
  5. Go to the e-government portal. From Safari, Chrome or Edge, or with the app's "Sedes" (Portals) button, choose the sign-in option for the DNIe or an electronic certificate.
  6. Choose your certificate. The dialog is the browser's own and may show both of the DNIe's certificates. If DNIe for Mac asks for your PIN, enter it.
  7. Keep the app open and the card inserted. If you remove the DNIe or click "Desconectar" (Disconnect), the certificate disappears until you repeat step 4.

DNIe Pro costs €9.99 a year with a 3-day trial, or €44.99 once (Mac App Store prices in Spain as of 16 September 2026). The subscription renews automatically unless you cancel it at least 24 hours before the end of the period. Reading, signing and validating are free and don't expire: pricing and free features.

Which certificate to choose: authentication or signing?

The authentication certificate is the one meant for signing in to a portal, but Spain's Tax Agency (Agencia Tributaria) asks for the signing one in its help page for Mac. If the portal rejects the one you picked, close the browser and try the other.

The DNIe carries two certificates in your name, and the Police add "(AUTENTICACIÓN)" or "(FIRMA)" at the end of their names to "facilitar al ciudadano el reconocimiento del tipo de certificado" (make it easier for citizens to recognize the type of certificate), according to their Declaración de Prácticas y Políticas de Certificación (Certification Practice and Policy Statement). On dnielectronico.es, the Police explain that the authentication certificate "tiene como finalidad garantizar electrónicamente la identidad del ciudadano al realizar una transacción telemática" (is meant to guarantee the citizen's identity electronically when carrying out an online transaction), and that the signing one is for "firmar trámites o documentos" (signing procedures or documents).

The Tax Agency's help page puts it this way: "Si es DNIe se debe seleccionar el certificado de 'firma' no el de 'autenticación'" (with a DNIe, select the 'signing' certificate, not the 'authentication' one). With the signing certificate, DNIe for Mac asks for your PIN every time.

Safari doesn't ask for the certificate or the DNIe doesn't appear

Safari can only offer you the DNIe while it's in the keychain. If Safari doesn't ask for the certificate or the DNIe isn't in the list, go through these checks in order.

Chrome or Edge doesn't recognize the DNIe certificate

Chrome looks for client certificates among the identities in the macOS keychain, according to its source code, and Edge is based on Chromium. The Safari checklist applies to both, with two caveats.

"Error de conexión con DNI electrónico en Mac OS X" and error 403 at the Tax Agency

For the Tax Agency, both are usually identification errors: the browser doesn't detect or doesn't recognize your certificate, or the right one isn't selected. For the DNIe, its help pages point you to Firefox because they describe the official software; with DNIe Pro, Safari, Chrome and Edge see the DNIe too.

The help pages for error 403 with Safari and with Chrome on a Mac, updated on 4 November 2025, say that "se trata generalmente de un error de identificación" (it is generally an identification error) and, for the DNIe, refer you to the Mac OS X help page and to Firefox: "El navegador compatible en Mac con el DNI electrónico es Mozilla Firefox" (the browser compatible with the electronic ID on a Mac is Mozilla Firefox), says the Safari one.

The help page "Error de conexión con DNI electrónico en Mac OS X" (connection error with the electronic ID on Mac OS X), updated on 7 May 2026, explains: "Se trata de un error de identificación, debido a que el DNIe no está correctamente instalado o el navegador no lo reconoce" (it is an identification error, because the DNIe is not correctly installed or the browser does not recognize it). It asks you to restart the browser session, choose the signing certificate and check that it is valid. It also says that "los certificados caducan a los 60 meses" (the certificates expire after 60 months), but article 11.3 of Royal Decree 255/2025 sets two years.

What about the DNIe in Firefox?

The DNIe that DNIe Pro publishes also appears in Firefox, with nothing to install. Firefox has its own certificate store, but on macOS it also reads the identities in the keychain through the security.osclientcerts.autoload preference, which as of 16 September 2026 is on by default in Firefox 156. All it takes is for that preference to stay true in about:config.

Without the app, Firefox is the official, free route, with the Police's PKCS#11 module. Which version to download, how to load it and what its errors mean: the DNIe in Firefox on a Mac.

When the portal asks for AutoFirma

Signing in and signing a submission are two different things. To sign in, the browser only needs to see your certificate, but to sign, many portals call AutoFirma, which doesn't use the certificate DNIe Pro publishes into the keychain. According to its installation manual, it reads the DNIe with JMulticard, its Java driver, which is enabled by default.

DNIe for Mac and AutoFirma can both be installed on the same Mac, but those submissions still need AutoFirma. Its usual failures, such as "No se han encontrado certificados válidos en el almacén" (no valid certificates were found in the store), are covered in AutoFirma on Mac.

The portal talks to AutoFirma over a WebSocket connection to 127.0.0.1, which is your own Mac, and since Chrome 147 (7 April 2026) and Edge 147 (9 April 2026) that connection needs your permission. If you ignore or deny the prompt, the portal can't communicate with AutoFirma. How to recognize it and what to do: AutoFirma isn't working on your Mac.

To sign your own documents you need neither a browser nor AutoFirma: signing a PDF with the DNIe is free with DNIe for Mac. You can see how the app works or download DNIe for Mac.

Frequently asked questions

Can I use the DNIe in Safari on a Mac?

Yes, with an app that publishes it into the macOS keychain, such as DNIe for Mac with DNIe Pro. Safari takes certificates from there, and macOS has no built-in support for the DNIe. The Police's official software is a PKCS#11 module for Firefox.

How do I install the DNIe in Chrome on a Mac?

On a Mac, Chrome looks for certificates in the macOS keychain, so what you install is not a module for Chrome but an app that publishes the DNIe there. With DNIe for Mac, activate DNIe Pro, click "Conectar" (Connect) and enter the PIN; the certificate will appear in Chrome's dialog. Without an app, the official route is Firefox with the PKCS#11 module.

Why doesn't Chrome recognize the DNIe certificate on my Mac?

Because the DNIe isn't in the keychain, which is where Chrome looks for certificates on macOS. With DNIe Pro, check that the "Tu DNIe en el navegador" (Your DNIe in the browser) box confirms it is active and connected, and that the certificates are valid. If you canceled the dialog, quit Chrome with Cmd+Q and open it again.

How much does it cost to use the DNIe in the browser with DNIe for Mac?

DNIe Pro costs €9.99 a year with a 3-day trial, or €44.99 once (Mac App Store prices in Spain as of 16 September 2026). Reading the DNIe and signing and validating documents is free and doesn't expire. The official route in Firefox, with the Police's PKCS#11 module, is free too.

I have an FNMT certificate, not the DNIe. Does this guide apply to me?

Not entirely. A software certificate, such as the FNMT one, lives on the Mac itself: to use it with Safari, the Tax Agency says "el certificado electrónico debe estar instalado en el Acceso a Llaveros" (the electronic certificate must be installed in Keychain Access). DNIe for Mac doesn't manage software certificates, only the DNIe's.