fieldnote-ops/keyringseam

macOS Keychain credential provider that replaces the local-file provider and uses a signed, notarized universal helper.

KeyringSeam is a macOS credential provider for the DeepSeek Harness ctx.credentials seam. The v0.2.0-rc.1 candidate replaces the legacy file-Keychain helper with a Broker app that is Developer ID-signed and notarized, stores managed values in a private Data Protection Keychain access group, and asks for explicit device-owner authentication before get, set or unset. README-verified behavior includes persistent stdin/stdout framing with an empty child environment, no secret-bearing argv, bounded requests/responses, serialized operations and lifecycle disposal; same-user attack tests show an independent Security.framework reader returns errSecMissingEntitlement (-34018) and /usr/bin/security cannot read the group. The README explicitly defers the 3-machine/24-hour external acceptance round and claims no independent security review or independent-user adoption yet.

Models & Providers ★ 0 updated 2026-08-15
View on GitHub ↗

Install

dsh plugin --profile web add github:fieldnote-ops/keyringseam#v0.2.0-rc.1

GitHub install per README (EN primary with 简体中文 edition): dsh plugin --profile web add github:fieldnote-ops/keyringseam#v0.2.0-rc.1 (public release candidate; the v0.1.3 tag is the legacy storage-only release). macOS-only: installs a Developer ID-signed, notarized Broker app storing values in a private Data Protection Keychain access group. Independent project by FIELD NOTE, not affiliated with DeepSeek or Apple.

Compatibility

macOS; DeepSeek Harness ctx.credentials seam; Data Protection Keychain with private access group TU8DF2JWHF.org.fieldnote.keyringseam.broker; device-owner authentication required.

Details

Recent updates

v0.2.0-rc.1 is a public release candidate (notarization/stapling/Gatekeeper/quarantine acceptance passed per README); external acceptance round intentionally deferred.

FAQ

What does this replace?
The legacy file-Keychain helper for dsh's ctx.credentials seam — v0.2.0-rc.1 is a signed/notarized Broker app; the v0.1.3 tag remains the legacy storage-only release.
Is it macOS-only?
Yes — it uses macOS Keychain primitives (Data Protection Keychain, private access group, device-owner authentication) and a Developer ID-signed Broker app.
What security claims does the README make?
It documents verified behaviors (empty child environment, no secret-bearing argv, errSecMissingEntitlement for same-user readers) and explicitly claims no independent security review yet.

Alternatives

revive/dsh-git-credentials · Yuuz12/dsh-webui-auth

More plugins in Models & Providers

Browse more in Models & Providers

Guides for Models & Providers plugins