Skip to content

docs: document macOS 26 (Tahoe) key export via export-findmy - #260

Open
MElkmeshi wants to merge 1 commit into
malmeloo:mainfrom
MElkmeshi:docs/macos-26-export-keys
Open

MElkmeshi wants to merge 1 commit into
malmeloo:mainfrom
MElkmeshi:docs/macos-26-export-keys

Conversation

@MElkmeshi

Copy link
Copy Markdown

What

Adds a README section for macOS 26 (Tahoe) users explaining how to obtain accessory keys, since the built-in python -m findmy decrypt no longer works there.

Why

On macOS 26, the BeaconStoreKey needed to decrypt local accessory records is guarded by an Apple-only keychain access-group entitlement (com.apple.icloud.searchpartyuseragent), so python -m findmy decrypt fails — the docs currently describe it as a dead end (#177). The iCloud Keychain escrow route works today, with no second Mac and without disabling SIP.

Changes

Notes

Verified end-to-end on macOS 26.5.2 (Apple Silicon): exported an AirTag's keys via the escrow route and fetched a live location with examples/airtag.py.

On macOS 26 the local `python -m findmy decrypt` path is blocked: the
BeaconStoreKey is guarded by an Apple-only keychain access-group
entitlement, so accessory keys can't be read locally (issue malmeloo#177).

Add a README section pointing macOS 26 users to iCloud Keychain escrow
export via export-findmy, which produces FindMy.py-compatible JSON with
no second Mac and without disabling SIP. Also gitignore local key/session
artifacts (devices/, account.json, ani_libs.bin) so users following the
instructions don't accidentally commit private key material.
@malmeloo

Copy link
Copy Markdown
Owner

I appreciate your PR, but this method is still a bit experimental and bound to change in the future. This functionality will be built into FindMy.py directly at some point, hopefully soon.

Let's reconsider this in a few weeks or so. By that point I expect I will at least have a full CI pipeline implemented with releases. That way people won't have to compile it manually. Then we add it to the docs, I'll publish an announcement and we'll see if it breaks or not. If all works fine it will then be integrated into FindMy.py.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants