opensourceprojects.dev

A broadsheet for software that doesn't ask for your email

SSH keys you can't export, guarded by the Secure Enclave
GitHub RepoImpressions3

Project Description

View on GitHub

SSH Keys You Can't Export, Guarded by the Secure Enclave

If you've ever kept an SSH private key on disk and hoped file permissions would be enough, you've probably had the same quiet worry most of us do: malware or a determined attacker can just copy it. Secretive takes a different approach. It stores and manages your SSH keys inside the Secure Enclave on your Mac, where they simply can't be exported.

What It Does

Secretive is a macOS app for protecting and managing SSH keys using the Secure Enclave. Instead of leaving your private key as a file on disk guarded by permissions, Secretive generates and stores the key material in the Secure Enclave itself. Because of how the hardware works, that key material can't be exported—by design. The app handles the signing operations for you, so your normal SSH workflow keeps working while the private key never leaves the protected hardware.

For Macs without a Secure Enclave, Secretive also supports Smart Cards, such as a YubiKey, and can use those for signing instead. The project is open source, has an auditable build process, and is localized into many languages by volunteers. It was inspired by the earlier sekey project.

Why It's Cool

The key literally cannot leave the machine. This is the core idea, and it's a good one. The most common SSH setup is a key on disk with proper permissions. That's fine most of the time, but it's not hard for malicious users or malware to copy your private key. With the Secure Enclave, export is impossible by design—so even if someone gets access to your filesystem, there's no private key file to steal.

You get strong access controls for free. If your Mac has a Secure Enclave, it also supports things like Touch ID and Apple Watch authentication. You can configure your keys so that they require Touch ID (or Watch) before they're accessed. That means a key grab requires your physical presence, not just a shell on your machine.

You'll know when your keys are used. Secretive notifies you whenever your keys are accessed. It's a small thing, but it means you're never caught off guard by an unexpected signing operation.

There's a fallback for older hardware. Not every Mac has a Secure Enclave. Rather than leaving those users out, Secretive lets you configure a Smart Card like a YubiKey and use it for signing too. Same idea—hardware-backed keys—just a different piece of hardware.

The build process is auditable. Starting with Secretive 3.0, builds are attested using GitHub Artifact Attestation, and those attestations are viewable in the build log and on the main attestation page. For a tool that touches your SSH keys, that kind of transparency matters.

One thing worth understanding before you dive in: Secretive still relies on Keychain APIs to store and access keys, and Keychain restricts reads to the app (specifically the bundle ID) that created them. If you build from source, be consistent about the bundle ID you use, or Keychain won't be able to find your keys.

How to Try It

Getting started is straightforward. You have two options:

Direct download: Grab the latest release from the Releases Page.

Homebrew: If you'd rather use Homebrew, it's a one-liner:

brew install secretive

Once installed, you can generate keys in the app, configure them to require Touch ID or Apple Watch authentication, and point your SSH client at them. There's a FAQ in the repo if you hit questions along the way.

One important caveat before you commit: because secrets in the Secure Enclave aren't exportable, they can't be backed up, and you won't be able to transfer them to a new machine. If you get a new Mac, you'll just create a new set of secrets specific to that machine. That's the tradeoff for the security guarantee—and it's worth knowing up front.

You can find the full project at github.com/maxgoedjen/secretive.

Final Thoughts

Secretive is a focused tool that solves one problem well: keeping SSH private keys out of reach of anything that can read your filesystem. It's best suited for macOS users who want hardware-backed key storage without giving up their existing SSH workflow, and who are comfortable with the fact that their keys are tied to a single machine. The no-export design is both the selling point and the constraint—if you need portable, backup-able keys, this isn't the tool for you. But if you'd rather your private keys be impossible to copy in the first place, it's a clean and honest implementation of that idea.


Follow @githubprojects for more developer tools and open source projects.

Back to Projects
Project ID: 44bfc012-9381-4ce3-9ad2-2efafa5dcf7dLast updated: September 29, 2026 at 11:08 AM