KeyRotate support

Help for the Mac app. KeyRotate needs macOS 14 or later.

KeyRotate has a full Help book built in, under the Help menu or ⌘?. It is searchable, works offline and matches the version you have installed. Start there. The notes below cover the questions that come up most.

A rotation failed

Nothing is lost. The previous key is still stored and still works, and the message says what the vendor refused. KeyRotate verifies a replacement before it stores it, so a failure leaves the old key in place rather than a broken one.

Cloudflare needs a token with the API Tokens Write permission, which only its "Create additional tokens" template grants. Some vendors need an organisation-level admin key; store it as an Admin key and select it on the key that needs it.

The old key still works after rotating

That is deliberate. KeyRotate never revokes the previous key, because anything still holding it would break the moment it did. Update the files and services that use the key, confirm they are working, then revoke the old key at the vendor. The Check-up lists keys with a previous value still valid so none is forgotten.

"This target has no saved file access"

The macOS permission for that file is gone, usually because the file moved or was restored from a backup. Remove the target and add it again to re-grant access.

"The variable is not in this file"

The file no longer contains the variable name KeyRotate is looking for. Check the key's Environment variable field, or the per-target override. If you meant to add it, use "Not found — add it to this file" in Find & update.

"…is in a file git would commit"

The file is inside a git repository and no rule covers it. "Add to .gitignore" asks for the repository folder once and appends a rule for exactly that file.

If git already has the file, ignoring it changes nothing: the key is in the history of every clone. KeyRotate says "committed" and offers to rotate instead. After rotating, update the files and revoke the old key at the vendor, because the old value stays in the history.

"Cannot tell whether git would commit it" means the file was granted on its own, so KeyRotate can see the repository but cannot read its settings. Use "Grant repository folder…" once and the check becomes real from then on.

Expiry says "Not read yet"

Only some vendors publish an expiry date, and most of those need an admin key to read it. Where a vendor publishes nothing, KeyRotate says so rather than claiming the key never expires.

FrontierStack pairing fails

FrontierStack needs its HTTPS control listener running: open Remote Control & Lock there, then pair again. A pairing code lasts five minutes and works once.

Moving to another Mac

Settings ▸ Backup exports an encrypted archive holding your keys and their settings, sealed with a passphrase you choose. Restore it on the other Mac with the same passphrase. There is no recovery without that passphrase, by us or anyone, so store it somewhere safe.

File targets point at paths on the Mac that made the backup. On a different Mac, re-grant them from the Targets screen.

Subscription and billing

KeyRotate is sold through the App Store. Payment, renewal, cancellation and refunds are handled by Apple in your Apple Account settings, not by us. Your stored keys stay readable and exportable if the subscription lapses.

Contacting us

Tell us what you did, what happened, which vendor was involved and your macOS version. The exact wording of an error message helps a great deal.

Never include a key value, a password, a token or an admin credential in a support message. We never need one, and sending it means rotating it.

Contact support