Repository navigation
Developer-ID-signed secrets CLI, macOS arm64. The signature is load-bearing: it is what lets the binary reach the biometric Keychain and the Secure Enclave envelope key — a source build cannot (-34018). Source: the secrets-vault crate (this repo hosts the v1 lineage plus binary releases). Ships as Secrets.app with its Developer ID provisioning profile embedded (the keychain entitlement requires it). Install: brew install --cask quantum-encoding/tap/secrets.