Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
alphaonedev avatar

Macos Keychain

  • 54 installs
  • 6 repo stars
  • Updated March 13, 2026
  • alphaonedev/openclaw-graph

macos-keychain is a Claude skill that teaches an agent to manage the macOS Keychain via the security CLI, storing secrets, certificates, and codesigning identities.

About

This skill is a reference for managing the macOS Keychain through the security CLI. It documents storing and retrieving generic passwords and API keys, handling certificates for codesigning, and interacting with the Secure Enclave for hardware-backed keys. A developer uses it to keep secrets out of scripts and fetch them at runtime, or to manage signing identities.

  • Reference card for the macOS Keychain via the security CLI
  • Covers storing/retrieving secrets, certificates, codesigning, and Secure Enclave
  • Includes security add/find-generic-password and export commands plus Swift Security-framework snippets

Macos Keychain by the numbers

  • 54 all-time installs (skills.sh)
  • Ranked #1,278 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

macos-keychain capabilities & compatibility

Free; local security CLI, no external API keys required

Capabilities
secret storage · credential retrieval · certificate management · codesigning
Use cases
security audit
Platforms
macOS
Pricing
Free
From the docs

What macos-keychain says it does

This skill provides tools for managing macOS Keychain via the `security` CLI, handling secure storage of secrets like API keys, passwords, certificates, and codesigning, while interacting with the Sec
SKILL.md
Add a generic password: `security add-generic-password -a username -s service -w password -T ""`
SKILL.md
Avoid storing keys in code; fetch from Keychain at runtime.
SKILL.md
npx skills add https://github.com/alphaonedev/openclaw-graph --skill macos-keychain

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs54
repo stars6
Last updatedMarch 13, 2026
Repositoryalphaonedev/openclaw-graph

What it does

Reference for an agent to store and retrieve secrets, certificates, and codesigning identities in the macOS Keychain.

Who is it for?

Securely storing and retrieving API keys, passwords, and certificates on macOS, and managing codesigning identities

Skip if: Non-macOS secret storage or environments without the security CLI

When should I use this skill?

You need an agent to store or fetch a secret from Keychain, or manage a certificate for codesigning

By the numbers

  • Secure Enclave key example uses secp256r1 curve
  • certificate export produces P12 format for codesigning

Files

SKILL.mdMarkdownGitHub ↗

macos-keychain

Purpose

This skill provides tools for managing macOS Keychain via the security CLI, handling secure storage of secrets like API keys, passwords, certificates, and codesigning, while interacting with the Secure Enclave for enhanced security.

When to Use

Use this skill when your application needs to store or retrieve sensitive data on macOS, such as API keys in scripts, manage certificates for app signing, or handle hardware-backed secrets via Secure Enclave. Apply it in automation, CI/CD pipelines, or apps requiring macOS-specific security.

Key Capabilities

  • Store and retrieve generic passwords using Keychain services.
  • Manage certificates and identities for codesigning apps or verifying connections.
  • Interact with Secure Enclave for storing keys that require hardware protection.
  • Add, delete, or search items in Keychain with fine-grained access controls.
  • Handle API key storage with encryption, ensuring data is isolated per user or app.

Usage Patterns

Always run security commands via subprocess in scripts, prefixing with security and using flags for operations. For programmatic access, use the Security framework in Swift/Objective-C. Check for Keychain access prompts and handle user interactions. Use environment variables like $KEYCHAIN_ITEM_NAME for dynamic inputs to avoid hardcoding secrets.

Common Commands/API

Use the security CLI for most tasks; for apps, leverage Security framework APIs like SecItemAdd and SecItemCopyMatching.

  • Add a generic password:

security add-generic-password -a username -s service -w password -T "" This stores a password for a service; use $SERVICE_NAME for the service string.

  • Find a generic password:

security find-generic-password -a username -s service -w Output the password; pipe to a variable, e.g., in Bash: pass=$(security find-generic-password -s myapp -w).

  • Delete an item:

security delete-generic-password -a username -s service Removes the entry; confirm with -h for help on flags.

  • Add a certificate:

security add-certificate -k login.keychain cert.pem Imports a PEM certificate; specify keychain with -k.

  • For Secure Enclave, generate a key:

security create-key -t secp256r1 -a -p Creates a key pair; use in apps via SecKeyGeneratePair.

  • API example in Swift (Security framework):

let query: [String: Any] = [kSecClass as String: kSecClassGenericPassword] let status = SecItemCopyMatching(query as CFDictionary, nil) This queries for a generic password item.

  • Export a certificate:

security export -k login.keychain -t identities -o cert.p12 -P passphrase Exports to P12 format; use for codesigning.

Config formats: Keychain items use a dictionary-based query (e.g., in APIs, as [String: Any]), with keys like kSecAttrAccount for usernames. CLI outputs are plain text or plist; parse with plutil for structured data.

Integration Notes

Integrate by calling security commands from scripts using subprocess (e.g., in Python: subprocess.run(['security', 'add-generic-password', ...])). For apps, import Security.h and use functions like SecItemAdd; ensure entitlements include "keychain-access-groups". Use env vars for secrets, like $API_KEY passed to commands. Avoid storing keys in code; fetch from Keychain at runtime. For cross-app access, set the same access group in entitlements.

Error Handling

Check command exit codes; e.g., in Bash, use if [ $? -ne 0 ]; then echo "Error: Keychain operation failed"; fi. For CLI, parse stderr for messages like "SecKeychainItem not found". In Swift APIs, handle OSStatus errors (e.g., if SecItemAdd returns errSecDuplicateItem, log and retry). Use try-catch in Objective-C for framework calls. Common issues: permission denied (prompt user via UI) or item not found (return default value). Always sanitize outputs to prevent exposure of secrets.

Concrete Usage Examples

1. Store an API key in Keychain: In a Bash script, use: security add-generic-password -a myapp-user -s myapi -w $API_KEY -T "" Then retrieve it: apiKey=$(security find-generic-password -a myapp-user -s myapi -w) Use $API_KEY from env vars to avoid plaintext in scripts.

2. Manage a certificate for codesigning: Import a cert: security add-certificate -k login.keychain mycert.pem Verify: security find-certificate -c "My Cert Name" In a build script, export for signing: security export -k login.keychain -t identities -o signing.p12.

Graph Relationships

  • Related to: macos-filesystem (for certificate file handling), security-tools (for broader security operations), encryption-services (via Secure Enclave integration).
  • Clusters: macos (direct), secrets-management (via tags).
  • Tags connections: keychain (core), secrets (overlaps with vault tools), security (links to authentication skills).

Related skills

FAQ

How do you store and read a secret in the macOS Keychain?

Use security add-generic-password to store it and security find-generic-password -w to read it back into a shell variable.

Why fetch secrets from Keychain at runtime?

To avoid storing keys in code; the skill advises pulling secrets from Keychain at runtime so plaintext credentials stay out of scripts.

Securitysecretsappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.