From ab4518c5dbf1c0a4e478aa6a2a67c1d84071663b Mon Sep 17 00:00:00 2001 From: Mohamed Elkmeshi Date: Fri, 14 Aug 2026 21:10:10 +0200 Subject: [PATCH] docs: document macOS 26 (Tahoe) key export via export-findmy On macOS 26 the local `python -m findmy decrypt` path is blocked: the BeaconStoreKey is guarded by an Apple-only keychain access-group entitlement, so accessory keys can't be read locally (issue #177). Add a README section pointing macOS 26 users to iCloud Keychain escrow export via export-findmy, which produces FindMy.py-compatible JSON with no second Mac and without disabling SIP. Also gitignore local key/session artifacts (devices/, account.json, ani_libs.bin) so users following the instructions don't accidentally commit private key material. --- .gitignore | 6 ++++++ README.md | 24 ++++++++++++++++++++++++ 2 files changed, 30 insertions(+) diff --git a/.gitignore b/.gitignore index f206d95..7a19c2e 100644 --- a/.gitignore +++ b/.gitignore @@ -165,3 +165,9 @@ airtag.plist DO_NOT_COMMIT* .direnv/ accessories/ + +# Local FindMy artifacts — never commit (device keys, saved sessions, +# downloaded anisette libraries) +devices/ +account.json +ani_libs.bin diff --git a/README.md b/README.md index fc1e713..900b36c 100644 --- a/README.md +++ b/README.md @@ -60,6 +60,30 @@ For usage examples, see the [examples](examples) directory. We are also building out a CLI. Try `python -m findmy` to see the current state of it. Documentation can be found [here](http://docs.mikealmel.ooo/FindMy.py/). +## 🍎 Getting accessory keys on macOS 26 (Tahoe) + +On macOS 26, the built-in `python -m findmy decrypt` can no longer read your +accessory keys: the `BeaconStoreKey` is locked behind an Apple-only keychain +entitlement, so the local decrypt path is blocked (see +[issue #177](https://github.com/malmeloo/FindMy.py/issues/177)). + +Instead, export your keys from **iCloud Keychain** with +[`export-findmy`](https://github.com/stek29/export-findmy), which writes +FindMy.py-compatible JSON directly — no second Mac and no disabling SIP: + +1. Build it (`cargo build --release`; needs `protoc` and `openssl`). macOS 26 + support — native system anisette plus a Mac device profile — currently lives + in [this PR](https://github.com/stek29/export-findmy/pull/1); until it is + merged, build from that branch. +2. Copy `device-profile.template.toml` to `.local/device-profile.toml` and fill + the `[software]` section with your Mac's real identity + (`sysctl -n hw.model`, `sw_vers`). +3. Run `export-findmy --apple-id you@example.com --device-profile + .local/device-profile.toml`, sign in, and pick your Mac's escrow bottle + (its passcode is your Mac login password). +4. Copy the exported AirTag `.json` into `devices/` and query it, e.g. + `python3 examples/airtag.py devices/your_airtag.json`. + ## 🤝 Contributing Want to contribute code? That's great! For new features, please open an