Help
How to install and use the DNIe (Spanish electronic ID) on a Mac
Guide updated: · by David Pelayo (nexoapex)
Installing the DNIe (Spain's electronic ID card) on a Mac means installing the software that reads it: its private keys never leave the chip. There are two routes: the Police's official module, free but for Firefox only, or an app such as DNIe for Mac, which reads and signs for free and, with DNIe Pro, lets you sign in with the DNIe in Safari, Chrome, Edge and Firefox.
- You only use Firefox: the official route, set up by hand.
- You use Safari, Chrome or Edge: an app that publishes the DNIe into the macOS keychain, such as DNIe for Mac with DNIe Pro.
- You want to read your data or sign a PDF of your own: DNIe for Mac, free (AutoFirma also works for signing). If an e-government site asks for the signature, AutoFirma.
Do you have to install the DNIe or its certificate on the Mac?
No. The certificates are on the card. According to the Police's page on DNIe security, the keys are generated inside the card, and the private keys, the ones that sign, "no se pueden extraer nunca de la tarjeta" (can never be extracted from the card). That is why the DNIe has to be in the reader every time you sign in or sign: the chip carries out the operation after you enter the PIN.
What you install is the software that talks to the card, and each program looks for your certificate in a different place: Firefox can load a PKCS#11 module, Safari and Chrome take it from the macOS keychain, and AutoFirma reads the card on its own.
What do you need before you start?
- A USB contact reader. macOS natively supports USB readers that conform to CCID, with no drivers. It has to be a contact reader, with a slot for the chip: the Mac has no NFC reader that apps can use (which reader to choose).
- Valid certificates. They expire after two years (article 11.3 of Royal Decree 255/2025). If they have expired or been revoked, the card can still be read, but they cannot be used to sign in or to sign. They are renewed free and without an appointment, in person, at a DNIe Update Point (PAD).
- The PIN. The original one came in a sealed envelope. Three wrong PINs in a row block it, there is no PUK, and the PIN cannot be changed over the internet: it is sorted out at a PAD, as the blocked or expired PIN guide explains.
- Knowing which Mac you have. Apple menu > About This Mac shows the macOS version and, according to Apple, a "Chip" or "Processor" line. If it shows an Apple chip, choose the Apple Silicon downloads; if it shows an Intel processor, the Intel ones.
The official route: the Police's PKCS#11 module, Firefox only
The official DNIe software for Mac is a PKCS#11 module from the Police, libpkcs11-dnie. The package includes nothing that publishes the DNIe into the macOS keychain, and its instructions only explain how to load it into Firefox. Spain's Tax Agency (Agencia Tributaria) sums it up: "El navegador compatible en Mac con el DNI electrónico es Mozilla Firefox" (the browser compatible with the DNIe on a Mac is Mozilla Firefox).
As of 16 September 2026, the downloads area of dnielectronico.es offers version 1.6.8 for Intel (no suffix) and for Apple Silicon (with _arm), each as a .dmg and as a .pkg. The steps, in short:
- Download and install the package for your Mac. The module ends up at
/Library/Libpkcs11-dnie/lib/libpkcs11-dnie.so. - In Firefox, go to Settings > Privacy and security > Certificates, click "Manage security devices" and then "Load", and enter that path.
- Import the root certificate that the installer leaves behind into Firefox, and tick the trust boxes.
- Quit Firefox, insert the DNIe and open Firefox again, as the Tax Agency instructs.
It is free, but you set it up by hand. The root certificate, the "No es posible añadir el módulo" ("Unable to add module") error and how to remove the module: the DNIe in Firefox on a Mac.
The app route: DNIe for Mac, from the Mac App Store
DNIe for Mac is an unofficial app by nexoapex, with no Java and no modules to configure. On the Mac App Store it is listed as "DNIe - Firma y autenticación" and it requires macOS 13 or later.
- Connect the reader and insert the DNIe with the chip facing up.
- Download "DNIe - Firma y autenticación" for free from the Mac App Store and open it.
- The app detects the card, reads your certificates without asking for the PIN and marks each one as "Vigente" (valid), "Caducado" (expired) or "Revocado" (revoked); for "Vigente" and "Revocado" it needs an internet connection.
- Click "Conectar" (Connect) and enter your PIN. That turns on "Mostrar datos" (Show data), with your personal details and photo, and "Firmar documento" (Sign document).
- To sign in from the browser, click "Desbloquear" (Unlock) under "Tu DNIe en el navegador" (Your DNIe in the browser) and choose the annual subscription or the lifetime license. With DNIe Pro active, including during the trial, your certificate appears in the browser's dialog in Safari, Chrome, Edge and Firefox.
With DNIe Pro, inserting the card is not enough: the app only publishes the DNIe into the keychain once you have connected it with your PIN. Keep the app open while you sign in; when you remove the card, the certificate stops appearing.
Free and with no expiry: reading your data, PAdES, CAdES and XAdES signing, validation of signed PDFs, your certificates' status and the e-government site launcher. DNIe Pro, browser sign-in, is the only paid feature: €9.99 a year with a 3-day trial, or €44.99 once (Mac App Store prices in Spain as of 16 September 2026). The subscription renews automatically unless you cancel it at least 24 hours before the end of the period.
Which browsers does each route work in?
| Official route (PKCS#11 module) | DNIe for Mac with DNIe Pro | |
|---|---|---|
| Safari | No | Yes |
| Chrome | No | Yes |
| Edge | No | Yes |
| Firefox | Yes, loading the module by hand | Yes, without loading any module |
| What you install | libpkcs11-dnie 1.6.8 and the root certificate in Firefox | The app, from the Mac App Store |
| Cost | Free | €9.99 a year with a 3-day trial, or €44.99 once |
Firefox sees the DNIe that DNIe Pro publishes thanks to the security.osclientcerts.autoload preference, which has existed since Firefox 75 and, as of 16 September 2026, is on by default in Firefox 156 and in the ESR 140 and 153 releases; if you turn it off, Firefox stops seeing the DNIe.
For more detail, see the guides to the DNIe in Safari, Chrome and Edge and to the DNIe in Firefox.
Do you need AutoFirma on a Mac?
You need it when an e-government site asks for the signature: many of them open AutoFirma from the browser so you can sign the submission. It is the Government of Spain's signing application and it does not depend on the Firefox module or on DNIe for Mac: according to its installation manual, it reads the DNIe with its own Java library, JMulticard, which is enabled by default.
- Download it only from firmaelectronica.gob.es, which publishes one version for x64 processors and another "para MacOS procesadores M1 y siguientes" (for M1 processors and later).
- When you install it, it asks for an administrator's password, because it adds trusted certificates to the system store and to Firefox.
- It can be installed on the same Mac as DNIe for Mac, and it does not use the DNIe that DNIe Pro publishes into the keychain.
To sign a PDF of your own, with no e-government site involved: how to sign a PDF with the DNIe on a Mac. If AutoFirma fails: AutoFirma on Mac.
The DNIe on macOS Tahoe, macOS 27 and Apple Silicon Macs
macOS 27 Golden Gate came out on 14 September 2026 and only installs on Macs with Apple Silicon, MacBook Neo included. As of 16 September 2026:
- Official module. Its downloads page lists macOS 26 Tahoe, 15 Sequoia, 14 Sonoma and 13 Ventura, and does not mention macOS 27 yet.
- DNIe for Mac. Its Mac App Store listing says "Requiere macOS 13.0 o posterior" (requires macOS 13.0 or later).
- Rosetta. According to the macOS 27 release notes, if you had Rosetta installed, it is not restored automatically when you upgrade. That affects software built for Intel, such as AutoFirma for x64: on an Apple Silicon Mac, install the "para MacOS procesadores M1 y siguientes" version.
- AutoFirma on Tahoe. Issues with AutoFirma 1.9.2 on Tahoe are still open: it does not list the software certificates installed in the keychain (issues 520 and 548) or, according to one user, never manages to open its local service for talking to the browser (issue 551). Details in AutoFirma on Mac.
The DNIe doesn't work on your Mac: where to start
- The Mac doesn't see the reader, or it appears and disappears. Try a port on the Mac itself or a powered hub, and follow the DNIe card reader guide.
- The reader works, but you don't know whether the DNIe does. Read how to check that the DNIe works.
- Blocked PIN, or expired or revoked certificates. It can't be fixed online: blocked or expired PIN.
- Firefox says "No es posible añadir el módulo" ("Unable to add module") or "Falló el inicio de sesión" ("Failed to Login"). The DNIe in Firefox on a Mac.
- Safari, Chrome or Edge doesn't show the certificate. With DNIe Pro, check that the app is open and the card is connected with your PIN. If it still doesn't appear: Safari doesn't ask for the certificate or Chrome or Edge doesn't recognize it.
- The Tax Agency gives a connection error or a 403 error with the DNIe. See what its help pages for Mac say.
- AutoFirma says "No se han encontrado certificados válidos en el almacén" (no valid certificates were found in the store). What it means and what to check.
- "No se pudo contactar con AutoFirma" (AutoFirma could not be contacted), or macOS won't let you open it. AutoFirma problems on macOS.
Frequently asked questions
Do I need to install the DNIe certificate on my Mac?
No. The certificates are on the chip, and according to the Police the private keys "no se pueden extraer nunca de la tarjeta" (can never be extracted from the card). What you install is the software that reads it. On the official route, the only thing you import, into Firefox, is the Police's root certificate.
What software do I need to use the DNIe on a Mac?
To sign in from Firefox, the official PKCS#11 module, free. From Safari, Chrome or Edge, an app that publishes the DNIe into the keychain, such as DNIe for Mac with DNIe Pro. To read your data, DNIe for Mac, free; to sign a PDF of your own, DNIe for Mac or AutoFirma, both free. If an e-government site asks for the signature, AutoFirma.
Are there DNIe drivers for Mac?
The reader needs none if it is CCID: macOS natively supports USB readers that conform to CCID. What the Police publish for Mac is not a driver but a PKCS#11 module, libpkcs11-dnie, which lets Firefox read the card.
Does the DNIe work in Safari and Chrome on a Mac?
Not on its own. Safari and Chrome take certificates from the macOS keychain, and the official DNIe software does not put them there. It works if an app publishes the DNIe into the keychain, such as DNIe for Mac with DNIe Pro. The guide to the DNIe in Safari, Chrome and Edge explains how.
Does the DNIe work on macOS Tahoe?
Yes. As of 16 September 2026, the Police's downloads page lists macOS 26 Tahoe for the libpkcs11-dnie 1.6.8 module, and DNIe for Mac requires macOS 13 or later. The open AutoFirma 1.9.2 issues on Tahoe are covered in the AutoFirma on Mac guide.
Can I use the DNIe on a Mac without a reader?
No. The Mac has no NFC reader that apps can use, so you need a USB contact reader. DNIeRemote, the Police app that turns an Android phone with NFC into a reader for the DNIe 3.0, only publishes its desktop component for Windows and Linux as of 16 September 2026.
How do I uninstall the DNIe software from my Mac?
Official module: delete the /Library/Libpkcs11-dnie folder, as its installation manual says, and in Firefox, open "Manage security devices", select the module and click "Unload". DNIe for Mac: drag the app to the Trash; if you have the annual subscription and don't want it to renew, cancel it in the App Store, from your name > Account Settings > Subscriptions.
Have an FNMT software certificate in a .p12 or .pfx file? Follow the digital certificate guide for Mac to import it into Keychain Access. It is different from the DNIe, whose private key stays on the card; the DNIe app does not manage software certificates.