Reference

Agent version and download URLs

Petros Amoiridis

Workbrew publishes the current Workbrew Agent version and every Workbrew Installer at fixed URLs. They are useful for anything that tracks Agent releases outside the Workbrew Console, such as a Jamf patch title, an AutoPkg recipe, or an internal packaging pipeline.

None of these endpoints needs authentication or an API key.

Endpoints

URLReturns
https://console.workbrew.com/downloads/version.jsonThe latest fully rolled out Agent version, as JSON
https://cdn.workbrew.com/agent/<version>/Workbrew-<version>.pkgThe macOS Workbrew Installer for an exact version
https://cdn.workbrew.com/agent/<version>/Workbrew-<version>.shThe Linux Workbrew Installer for an exact version
https://console.workbrew.com/downloads/macosThe macOS Workbrew Installer for the latest version
https://console.workbrew.com/downloads/linuxThe Linux Workbrew Installer for the latest version

Latest version

https://console.workbrew.com/downloads/version.json responds with a JSON object.

{"version":"1.11.5","published_at":"2026-09-28T18:30:04.134Z"}
FieldDescription
versionThe newest Agent version whose rollout has finished
published_atWhen that rollout finished, as an ISO 8601 UTC timestamp

published_at is not the build or release date. New Agent versions roll out in stages, and the timestamp records when the last stage completed. It is usually later than the matching release on GitHub.

The version reported here is the one Devices update to. There are two exceptions.

  • While a rollout is in progress, one Device per Workspace can receive the next version before it appears in version.json. An inventory check that compares Devices against version.json can briefly see that Device as newer than the latest version.
  • The Workbrew Agent needs macOS Sequoia (15) or later. Devices on an older macOS stay on the last Agent version that supports it and receive no further updates.

Installer for an exact version

The Workbrew Installer for a given version is always at the same path.

https://cdn.workbrew.com/agent/<version>/Workbrew-<version>.pkg

Replace both occurrences of <version> with a plain release number such as 1.11.5. Linux uses the same path with a .sh extension. This is the same URL the Agent downloads when it updates itself.

cdn.workbrew.com does not serve the file itself. It answers with a redirect to workbrew-console.nyc3.cdn.digitaloceanspaces.com, which is where the download comes from. A network or web filter that blocks cloud storage by category can block that host while allowing cdn.workbrew.com, so both have to be reachable. Network requirements lists both hosts.

Installer for the latest version

https://console.workbrew.com/downloads/macos and https://console.workbrew.com/downloads/linux redirect to the Workbrew Installer for the version that version.json reports. The redirect target is a signed, short-lived download URL on release-assets.githubusercontent.com.

These URLs have no version in them, so they cannot be pinned. A pipeline that needs a specific version, or needs the file name to match the version it recorded, should use the cdn.workbrew.com path instead.

Installer behavior on a Device that already has Workbrew

The Agent updates itself. It checks in with the Workbrew Console every 15 minutes, and when a newer version is available it downloads and runs the Workbrew Installer for that version. Automatic updates never move a Device to an older version.

The Workbrew Installer itself does not compare Agent versions. Installing it replaces the Agent with the version inside the package, even if that is older than the one already installed. The bundled Homebrew is the exception, because the installer only replaces Homebrew when the bundled copy is newer.

An MDM that pushes the Workbrew Installer on a schedule, or reinstalls it when its own version check does not match, therefore works against the built-in updater. Each push can roll the Agent back to the version the MDM holds, and the Agent then updates itself again. Pushing the installer from an MDM fits a first install, or a one-off catch-up for Devices that are behind.