Security · Tool

OS keychain

The secure store built into an operating system for passwords, tokens and keys, locked to the signed-in user, so desktop and mobile apps do not have to keep secrets in plain files.

Secrets · Free · updated

How it works

Each platform has one: Keychain on macOS and iOS, Credential Manager on Windows (protected by the Data Protection API, DPAPI), and the Secret Service API on Linux desktops, provided by GNOME Keyring or KDE Wallet. Android has the Keystore, which holds encryption keys, often inside secure hardware, rather than the secrets themselves. Entries are encrypted with keys tied to the user's login, so other accounts on the machine cannot read them, and macOS, iOS and Android also keep each app's entries apart from other apps.

Desktop apps use it for refresh tokens, API keys a user has pasted in, database passwords and encryption keys. Electron's safeStorage API and the Rust keyring crate (often used in Tauri apps) build on these platform stores, so an app does not have to handle each one itself. The alternative, a token in a plain config file, sits unencrypted on disk, where it can leak through backups, synced folders or a lost laptop.

The keychain protects secrets at rest on the user's own machine. It does not make a key that ships inside the app safe: anything compiled into an app can still be pulled out of the app itself.

OS keychain pricing

Free

Free; it is part of the operating system.

Approximate, checked September 2026.What the other tools cost

More in Security

Secrets

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.