Storage is not the same as a backup
This Mac only is the default. Records stay in this Mac's local Data Protection Keychain. Signing into your Apple Account on a new Mac does not synchronize those local-only records. If this is your only accessible copy and the Mac is lost, erased, or fails, Keyglass cannot retrieve them. Do not assume that copying the app, a repository, or its settings transfers your secrets, or that an untested system backup will restore them.
iCloud Keychain is an explicit choice in Keyglass Settings → Sync. It uses Apple's synchronization between compatible Macs. It is not a versioned backup: edits and deletions can propagate, and Keyglass has no restore-to-an-earlier-date feature. A change made offline may not yet be available on another Mac.
An export is a separate snapshot you deliberately retain. Keyglass does not create automatic backups. An export kept only on the same Mac does not protect against losing that Mac.
Prepare a copy while you still have access
- Unlock Keyglass and select a project and environment. Open Quick Open with Command-K and choose Export .env.
- Read the plaintext warning, confirm the export, choose a destination, and complete the fresh macOS authentication prompt. Cancelling authentication does not produce an export.
- Repeat for every environment you need. Keep track of which project and environment each file belongs to, without putting values in your notes.
- Keep the retained copy on storage you control and protect independently of this Mac, such as an encrypted removable volume. Check that you can unlock that storage independently before relying on it. Practice the import steps below with a disposable environment and synthetic values.
The .env file is plaintext, not an encrypted Keyglass backup. Keyglass restricts the written file to your macOS user (permissions 0600), but those permissions are not encryption and may change when copied. Choose protected storage before exporting; avoid shared or automatically synchronized folders. Never commit the file to Git, attach it to a support request, or paste its contents into email or chat. Remove temporary transfer copies after checking the import; keep any intentional backup protected and current. Deleting a file does not guarantee removal of copies already made elsewhere.
Each export contains only the selected environment's keys and values. It does not preserve project/environment structure, record identities, favorites, ordering, intentional absences, settings, or your license. Export remains available in restricted mode; import requires an active trial or license.
Replacing a Mac you still have
Keep the old Mac and its records intact until you have checked the new one. Install the official signed Keyglass app on a compatible Mac (macOS 26 or later).
For local-only storage, export each required environment on the old Mac, transfer the files using protected storage, and follow the reimport steps below. Verify every required environment on the new Mac before erasing the old one.
If you already use iCloud Keychain, sign into the same Apple Account on the new Mac and enable Passwords & Keychain synchronization in macOS. Apple requires two-factor authentication and may ask you to approve the Mac using another device or an earlier device passcode. Follow Apple's iCloud Keychain setup guide. Choose iCloud Keychain in Keyglass as well, during setup or in Settings → Sync, and allow time for records to arrive. Enabling sync requires an active trial or license.
Check that the expected projects, environments, and keys appear and that the values you need are usable through explicit reveal or secure copy. Keyglass completing a storage-mode migration is not proof that another Mac has received every record. Do not delete records on the old Mac as a cleanup step while using sync: deletions can reach the new Mac too. If a migration is interrupted, reopen Keyglass and use the offered retry; do not manually delete Keychain items.
Reimport an exported environment
- Unlock Keyglass on the destination Mac with an active trial or license. Create or select the project and target environment for this file.
- Open Quick Open with Command-K, choose Import .env, and select the UTF-8 export using Browse….
- Review the redacted preview and resolve invalid lines or duplicate input keys. Values are hidden in the preview. Existing keys default to Skip existing; choose Replace existing only when you intend to overwrite those values with this snapshot.
- Confirm the import and check its added, replaced, and skipped counts. Check the expected keys in the selected environment; explicitly reveal or securely copy individual values only when needed to verify them. Repeat for the other environment files.
Import accepts UTF-8 files up to 1 MiB (1,048,576 bytes). Check the size of each retained export before relying on it; a larger file cannot be imported as-is.
Import adds or replaces entries in the selected environment; it does not remove unrelated keys or recreate the whole workspace. If validation fails, fix the reported issues before retrying. If a write fails, Keyglass restores the previous state rather than leaving a partial import. Follow any recovery prompt before retrying.
If the Mac is already lost or unavailable
- Another Mac has the records: check that copy before making changes. You can use it to export the environments you need.
- iCloud Keychain was enabled: try the replacement-Mac setup above. Apple documents a secure iCloud Keychain recovery process, but access depends on your account and available recovery credentials. Keyglass cannot guarantee that every record synchronized or that Apple recovery will succeed. Do not reset encrypted data or delete Keychain items as a troubleshooting shortcut; consult Apple's guidance first.
- You retained an export: reimport it. Only values present when that export was created can be restored from that file.
- No accessible copy remains: Keyglass support cannot recover the values. Obtain replacement credentials from the services that issued them. If the lost Mac may have been accessed by someone else, revoke or rotate affected credentials with those services.
Keyglass has no hosted vault, master recovery password, or support-held copy of your secrets. Support can help diagnose a sanitized error or recover a license activation; restoring a license does not restore your data. Send only the safe context listed on the support page, never exports, secret values, license keys, or Keychain dumps.