PayloadKit

FileVault Recovery Key Redirection Payload

com.apple.security.FDERecoveryRedirect

The payload that configures FileVault recovery key redirection.

macOS 10.9+ · deprecated 10.13
Apple schemaexclusive

Not available with User Enrollment · Only one instance per profile · macOS: device channel only

Configuration Keys (2)

KeyTypeTitle
RedirectURLrequired

The URL to which the device sends FDE recovery keys instead of to Apple. The URL must begin with https://.

stringRedirect URL
EncryptCertPayloadUUIDrequired

The UUID of a payload within the same profile that contains a certificate used to encrypt the recovery key when the device sends it to the redirected URL. The referenced payload must be of type 'com.apple.security.pkcs1'.

stringEncryption Certificate Payload UUID