diff options
| author | Hyun Kim <hyun@balancehero.com> | 2026-01-06 17:55:12 +0700 |
|---|---|---|
| committer | Hyun Kim <hyun@balancehero.com> | 2026-01-06 17:55:12 +0700 |
| commit | 2c75ecaafd30d6cf0cc34ca47ccc9d7109ffcefd (patch) | |
| tree | 21c9bdb3a749796b504f60bf08b8605f355e39a9 /README.md | |
Initial commit: Touch ID Keychain CLI tool
- Touch ID authentication for all commands
- Secure password input (no echo)
- macOS Keychain storage with encryption
π€ Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 113 |
1 files changed, 113 insertions, 0 deletions
diff --git a/README.md b/README.md new file mode 100644 index 0000000..96ffdab --- /dev/null +++ b/README.md @@ -0,0 +1,113 @@ +# keychain-fingerprint + +Touch ID μΈμ¦μΌλ‘ macOS Keychain λΉλ°λ²νΈμ μμ νκ³ νΈλ¦¬νκ² μ κ·Όνλ CLI λꡬ + +## Why? + +macOS Keychainμ μ μ₯λ λΉλ°λ²νΈμ μ κ·Όν λ λ κ°μ§ λΆνΈν¨μ΄ μμ΅λλ€: + +### λ¬Έμ 1: 보μ vs νΈμμ± λλ λ§ + +`security find-generic-password` λͺ
λ Ήμ΄λ‘ λΉλ°λ²νΈμ μ κ·Όνλ©΄: + +``` +"security"κ° ν€μ²΄μΈμ "myapp"μ μ μ₯λ κΈ°λ° μ 보λ₯Ό μ¬μ©νλ €κ³ ν©λλ€. +[κ±°λΆ] [νμ©] [νμ νμ©] +``` + +- **"νμ©"**: λ§€λ² Mac λΉλ°λ²νΈλ₯Ό μ
λ ₯ν΄μΌ ν¨ β λ²κ±°λ‘μ +- **"νμ νμ©"**: μ΄ν μ΄λ€ μ±μμλ λΉλ°λ²νΈ μμ΄ μ κ·Ό κ°λ₯ β 보μ μ·¨μ½ + +### λ¬Έμ 2: λΉλ°λ²νΈ μ
λ ₯μ λΆνΈν¨ + +Mac λΉλ°λ²νΈλ λ³΄ν΅ κΈΈκ³ λ³΅μ‘ν΄μ λ§€λ² μ
λ ₯νκΈ° λ²κ±°λ‘μ΅λλ€. + +### ν΄κ²°μ±
: Touch ID + +μ΄ λꡬλ **Touch ID**λ‘ μΈμ¦νμ¬: +- **λΉ λ₯΄κ³ νΈλ¦¬ν¨**: μκ°λ½ ν λ²μΌλ‘ μΈμ¦ (λΉλ°λ²νΈ μ
λ ₯ λΆνμ) +- **보μ μ μ§**: λ€λ₯Έ μ±μμ μ κ·Ό μ μ¬μ ν Mac λΉλ°λ²νΈ νμ + +## Installation + +```bash +# Clone +git clone https://github.com/dss99911/keychain-fingerprint.git +cd keychain-fingerprint + +# Compile +swiftc -o keychain-fingerprint main.swift -framework LocalAuthentication -framework Security + +# Install (optional) +sudo cp keychain-fingerprint /usr/local/bin/ +``` + +## Usage + +```bash +# Save password (Touch ID β secure input) +keychain-fingerprint set myapp user@example.com + +# Get password (Touch ID β stdout) +keychain-fingerprint get myapp user@example.com + +# List saved items (Touch ID) +keychain-fingerprint list + +# Delete password (Touch ID) +keychain-fingerprint delete myapp user@example.com +``` + +### Shell Variable (Recommended) + +```bash +# Capture password in variable (not displayed on screen) +PASSWORD=$(keychain-fingerprint get myapp user@example.com) + +# Use the password +echo "Using password..." + +# Clear the variable when done +unset PASSWORD +``` + +## Security + +| Access Method | Authentication Required | +|---------------|------------------------| +| This app | Touch ID | +| Other apps / `security` command | Mac password | + +### How it works + +``` +βββββββββββββββββββββββββββββββββββββββββββ +β keychain-fingerprint β +βββββββββββββββββββββββββββββββββββββββββββ€ +β 1. Touch ID authentication β +β 2. Access Keychain (auto-authorized) β +βββββββββββββββββββββββββββββββββββββββββββ + +βββββββββββββββββββββββββββββββββββββββββββ +β Other apps / terminal β +βββββββββββββββββββββββββββββββββββββββββββ€ +β Keychain access β Mac password prompt β +βββββββββββββββββββββββββββββββββββββββββββ +``` + +### Features + +- All commands require Touch ID +- Passwords stored encrypted in macOS Keychain +- Password input is hidden (no echo) +- Passwords only output to stdout (for variable capture) +- Device-only access (`kSecAttrAccessibleWhenUnlockedThisDeviceOnly`) + +## Requirements + +- macOS with Touch ID +- Xcode Command Line Tools (`xcode-select --install`) + +## License + +MIT |
