fido2lock
Lock your Mac when you remove your FIDO2 security key.
fido2lock is a small menu-bar app. It watches for your enrolled security keys, and when you pull one out, it locks the screen, at once or after a delay you set. Unlock as usual, with your password or Touch ID. Without the key, your Mac works as before.
How it works
- Enroll your key once with Set Up…. It takes a touch, and the PIN if the key has one.
- While the key is in, fido2lock is armed. The menu bar icon shows a closed padlock.
- Pull the key out, and the screen locks.
Details
- Works with any FIDO2 key, for example YubiKey, Token2, or Google Titan.
- Enroll backup keys. Any enrolled key arms the lock, and an unknown key does nothing.
- Pause Until the Key Is Back lets you move the key to another port without locking.
- An optional delay of up to 60 s. Put an enrolled key back in time, and nothing locks.
- Handles sleep: a key that reconnects on wake does not lock the screen.
- Checks keys without a touch or PIN, and never opens them exclusively, so browsers and other key tools keep working.
- Uses no CPU while idle: it wakes only when a key comes or goes.
- A single binary under 1 MiB, written in Rust. Apache-2.0.
Install
You need macOS 13 or later on a Mac with Apple silicon, and a FIDO2 security key. Download the .dmg or .pkg from the latest release. The app is self-signed, not notarized by Apple, so macOS can refuse to open it the first time. If it does, click Done, open System Settings > Privacy & Security, and click "Open Anyway" under Security. Confirm with your password, then open it again. Then choose "Set Up…" in its menu.
Verify a download
GitHub Actions builds every release from its tag and signs SLSA Build Level 3 provenance for it:
gh attestation verify fido2lock-<version>.dmg --repo BJMCox/fido2lock \
--signer-workflow BJMCox/fido2lock/.github/workflows/build.yml
The release notes link each installer's VirusTotal scan.