fieldnote-ops/keyringseam
macOS Keychain credential provider that replaces the local-file provider and uses a signed, notarized universal helper.
KeyringSeam is a macOS credential provider for the DeepSeek Harness ctx.credentials seam. The v0.2.0-rc.1 candidate replaces the legacy file-Keychain helper with a Broker app that is Developer ID-signed and notarized, stores managed values in a private Data Protection Keychain access group, and asks for explicit device-owner authentication before get, set or unset. README-verified behavior includes persistent stdin/stdout framing with an empty child environment, no secret-bearing argv, bounded requests/responses, serialized operations and lifecycle disposal; same-user attack tests show an independent Security.framework reader returns errSecMissingEntitlement (-34018) and /usr/bin/security cannot read the group. The README explicitly defers the 3-machine/24-hour external acceptance round and claims no independent security review or independent-user adoption yet.
Install
dsh plugin --profile web add github:fieldnote-ops/keyringseam#v0.2.0-rc.1GitHub install per README (EN primary with 简体中文 edition): dsh plugin --profile web add github:fieldnote-ops/keyringseam#v0.2.0-rc.1 (public release candidate; the v0.1.3 tag is the legacy storage-only release). macOS-only: installs a Developer ID-signed, notarized Broker app storing values in a private Data Protection Keychain access group. Independent project by FIELD NOTE, not affiliated with DeepSeek or Apple.
Compatibility
macOS; DeepSeek Harness ctx.credentials seam; Data Protection Keychain with private access group TU8DF2JWHF.org.fieldnote.keyringseam.broker; device-owner authentication required.
Details
- Repo: fieldnote-ops/keyringseam
- Category: Models & Providers
- Stars: 0
- Version: git github:fieldnote-ops/keyringseam#v0.2.0-rc.1 (v0.1.3 = legacy storage-only release)
- Last push: 2026-08-15
- First seen: 2026-08-14
Recent updates
v0.2.0-rc.1 is a public release candidate (notarization/stapling/Gatekeeper/quarantine acceptance passed per README); external acceptance round intentionally deferred.
FAQ
- What does this replace?
- The legacy file-Keychain helper for dsh's ctx.credentials seam — v0.2.0-rc.1 is a signed/notarized Broker app; the v0.1.3 tag remains the legacy storage-only release.
- Is it macOS-only?
- Yes — it uses macOS Keychain primitives (Data Protection Keychain, private access group, device-owner authentication) and a Developer ID-signed Broker app.
- What security claims does the README make?
- It documents verified behaviors (empty child environment, no secret-bearing argv, errSecMissingEntitlement for same-user readers) and explicitly claims no independent security review yet.
Alternatives
revive/dsh-git-credentials · Yuuz12/dsh-webui-auth