Skip to content
Passwords and Keychain Access

Passwords and Keychain Access

Every Mac already has an encrypted, syncing, biometric-unlocked password manager. Most people meet it as a Safari popup and never open it.

What it does

Passwords is the app Apple split out of System Settings in macOS 15. It holds passwords, passkeys, verification codes, Wi-Fi networks and sign-in-with-Apple entries, autofills them in Safari and in any app that adopts the system autofill API, and unlocks with Touch ID. Shared groups let a household or a team hold a set of credentials together, and the security recommendations flag reused, weak and breached passwords against Apple’s own breach data.

Keychain Access is the older utility and still the honest view of the store. It shows every keychain on the machine, not only the login one — certificates, private keys, secure notes, certificate trust settings, and the System keychain that holds machine-wide items. Anything that is not a website login lives here, and nowhere else.

# read a stored password, prompting for authorisation
security find-generic-password -s "some-service" -w

# store one, scriptably
security add-generic-password -s "some-service" -a "$USER" -w "secret"

# what certificates does this machine trust
security find-certificate -a -p /Library/Keychains/System.keychain

The two are the same store

Passwords and Keychain Access read the same keychain database; Passwords simply hides everything that is not a login. iCloud Keychain is what syncs it, end-to-end encrypted, to every device on the Apple ID — and it is the reason the credential store survives a machine being replaced.

The limits follow from that. It syncs to Apple devices and Windows (through the iCloud app and a browser extension), and nowhere else. There is no Linux client, no self-hosted server, and no export format worth the name.

The equivalent elsewhere

On a Linux desktop the same job belongs to the Secret Service API: GNOME Keyring or KWallet holds the secrets, Seahorse (“Passwords and Keys”) is the GUI, and secret-tool from libsecret is the command line. On Ubuntu it is already running — gnome-keyring-daemon is what unlocks with the login password and what git, ssh and Docker store credentials in.

sudo apt install libsecret-tools seahorse

secret-tool store --label='some-service' service some-service username "$USER"
secret-tool lookup service some-service username "$USER"
secret-tool search --all service some-service

The shape matches security closely enough that a script can abstract over both: a lookup by attributes, unlocked by the desktop session, with the GUI as an afterthought.

Notes

  • A keychain item’s ACL decides which binaries may read it without prompting. A prompt naming an application you do not recognise is worth reading rather than clicking through.
  • Local Items / iCloud keychain entries cannot be exported in bulk by design. Migrating to another manager means Passwords’ own CSV export, which is plaintext — delete the file afterwards, and not to the Trash.
  • Touch ID unlocking is a convenience over the login password, not a separate secret. The account password remains the thing protecting the login keychain.

Alternative to

AlternativeTypeTrade-off
BitwardenOpen sourceEvery platform, self-hostable, and an actual export story
1PasswordFreemiumMore polish and better sharing, and the most Mac-native of the third-party options
KeePassXCOpen sourceA local database file you sync yourself
Proton PassFreemiumAudited, and bundled with Proton VPN
passOpen sourceGPG files in a Git repository, for people who want exactly that

Install

Nothing to install. Passwords is in /System/Applications on macOS 15 and later; Keychain Access is in /System/Applications/Utilities, on every version.

open -a Passwords
open -a "Keychain Access"

Links

This post is licensed under CC BY 4.0 by the author.
Last updated on