Plays a sound and shows a notification whenever your YubiKey is waiting for a touch on macOS. One ding = one touch owed.
Useful when the key is plugged in out of sight (iMac rear ports, docks). A rebase that re-signs five commits dings after each touch until all five are done.
brew install onyb/tap/ykding
brew services start ykdingThen ykding test plays both alerts so you know the sounds. If no banner
appears, allow notifications for Script Editor in System Settings →
Notifications.
ykding has zero dependencies. It only uses tools that ship with macOS
(log, afplay, osascript).
-
Glass ding + banner for FIDO2 touches (
sk-ssh-*keys, git commit signing, SSH auth). Any FIDO2 security key triggers this, not just YubiKeys. -
Ping ding + banner for OpenPGP touches (gpg on the YubiKey).
-
When git signing triggered the touch, the banner shows the repo and the commit subject:
-
When an SSH connection triggered the touch, the banner shows the destination and the remote command, e.g.
git@github.com: git-upload-pack onyb/ykding.git. Cloning a repo with five private submodules, each ding tells you which fetch wants the touch.
Naming who is asking makes every tap an informed one: a touch request you did not initiate shows up as a banner for something you do not recognize, instead of training you to tap whenever the key blinks.
| Command | What it does |
|---|---|
ykding test |
Play both alerts once |
ykding status |
Show daemon state and recent touches |
ykding run |
Run in the foreground (what brew services runs) |
ykding version |
Print the version |
The background service is managed by Homebrew: brew services stop ykding to pause it, brew upgrade ykding to update. Logs go to
$(brew --prefix)/var/log/ykding.log, one line per touch request.
While a YubiKey waits for a touch, macOS logs telltale messages: the kernel
for FIDO2, usbsmartcardreaderd for OpenPGP. ykding tails log stream
for those. The messages are a heuristic, not an API; tested on macOS 26
(Intel). Open an issue if your macOS logs differently.
For commit context, it inspects the ssh-keygen -Y sign process git
spawned: its working directory gives the repo, and the message being signed
is read from the git dir (rebase-merge/message, MERGE_MSG, or
COMMIT_EDITMSG). For SSH context, the ssh-sk-helper process is alive
exactly while the key waits for a touch; its parent is the ssh client, and
the destination plus any remote command are read off its command line.
All best-effort; if anything fails (or the key lives in ssh-agent, whose
requests carry no destination) you get a plain "Touch your YubiKey"
banner.
- noperator/yknotify: the detection heuristic (which log messages signal a touch request) is ported from here.