{"repo":"maxgoedjen/secretive","free":true,"listed":false,"github":"https://github.com/maxgoedjen/secretive","clone":"git clone https://github.com/maxgoedjen/secretive.git","description":"Protect your SSH keys with your Mac's Secure Enclave","language":"Swift","stars":8775,"topics":["ssh","mac","secure-enclave","security"],"license":"MIT","category":"security-tools","readme_excerpt":"Secretive Secretive is an app for protecting and managing SSH keys with the Secure Enclave. Why? Safer Storage The most common setup for SSH keys is just keeping them on disk, guarded by proper permissions. This is fine in most cases, but it's not super hard for malicious users or malware to copy your private key. If you protect your keys with the Secure Enclave, it's impossible to export them, by design. Access Control If your Mac has a Secure Enclave, it also has support for strong access controls like Touch ID, or authentication with Apple Watch. You can configure your keys so that they require Touch ID (or Watch) authentication before they're accessed. Notifications Secretive also notifies you whenever your keys are accessed, so you're never caught off guard. Support for Smart Cards Too! For Macs without Secure Enclaves, you can configure a Smart Card (such as a YubiKey) and use it for signing as well. Getting Started Installation Direct Download You can download the latest release over on the Releases Page Using Homebrew brew install secretive FAQ There's a FAQ here. Auditable Build Process Builds are produced by GitHub Actions with an auditable build and release generation process. Starting with Secretive 3.0, builds are attested using GitHub Artifact Attestation. Attestations are viewable in the build log for a build, and also on the main attestation page. A Note Around Code Signing and Keychains While Secretive uses the Secure Enclave to protect keys, it still relies ","default_branch":null,"files":null,"tree":[],"storefront":"/r/maxgoedjen","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/maxgoedjen/secretive/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}