AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Ssh Keychain Unlock

skill-soulmachine-skills-ssh-keychain-unlock · by soulmachine

Use when Claude Code auth fails over SSH on macOS, keychain is locked in headless/remote sessions, or setting up Claude Code on a Mac for remote access

No reviews yet
0 installs
19 views
0.0% view→install

Install

$ agentstack add skill-soulmachine-skills-ssh-keychain-unlock

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-soulmachine-skills-ssh-keychain-unlock)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Ssh Keychain Unlock? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

SSH Keychain Unlock for Claude Code on macOS

Overview

Claude Code stores credentials in the macOS Keychain (Claude Code-credentials service). When accessing a Mac via SSH (no GUI session), the login keychain is locked, causing Claude Code to appear unauthenticated.

When to Use

  • Claude Code says it's not logged in when accessed via SSH
  • security show-keychain-info ~/Library/Keychains/login.keychain-db shows the keychain is locked
  • Setting up a Mac Mini or headless Mac for remote Claude Code usage

Solutions

Option 1: Interactive Unlock on SSH Login

Add to ~/.zshrc:

# Unlock macOS keychain for SSH sessions (needed for Claude Code auth)
if [[ -n "$SSH_CONNECTION" ]]; then
  security unlock-keychain ~/Library/Keychains/login.keychain-db 2>/dev/null
fi

Prompts for macOS login password each SSH session. Simple but requires manual input.

Option 2: Auto-Unlock at Boot (Headless)

For fully headless operation with no password prompt:

1. Create password file (~/.claude/.keychain-password, permissions 600):

echo 'YOUR_MACOS_PASSWORD' > ~/.claude/.keychain-password
chmod 600 ~/.claude/.keychain-password

2. Create unlock script (~/.claude/unlock-keychain.sh, permissions 700):

cat > ~/.claude/unlock-keychain.sh  ~/Library/LaunchAgents/com.claude.unlock-keychain.plist 

    Label
    com.claude.unlock-keychain
    ProgramArguments
    
        /bin/bash
        __HOME__/.claude/unlock-keychain.sh
    
    RunAtLoad
    

PLIST
# Fix path
sed -i '' "s|__HOME__|$HOME|g" ~/Library/LaunchAgents/com.claude.unlock-keychain.plist

4. Load the agent:

launchctl load ~/Library/LaunchAgents/com.claude.unlock-keychain.plist

Quick Reference

| Command | Purpose | |---------|---------| | security show-keychain-info ~/Library/Keychains/login.keychain-db | Check keychain lock status | | security unlock-keychain ~/Library/Keychains/login.keychain-db | Manually unlock (interactive) | | bash ~/.claude/unlock-keychain.sh | Test auto-unlock script | | launchctl load ~/Library/LaunchAgents/com.claude.unlock-keychain.plist | Load LaunchAgent | | launchctl unload ~/Library/LaunchAgents/com.claude.unlock-keychain.plist | Unload LaunchAgent |

Common Mistakes

  • Wrong permissions on password file - Must be 600 (owner-only). Others can read your macOS password otherwise.
  • Forgetting to load the LaunchAgent - Creating the plist isn't enough; run launchctl load to activate it.
  • Password file out of sync - If you change your macOS password, update ~/.claude/.keychain-password too.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.