A native macOS quick-access window for Proton Pass. Press a keystroke from any app, search your logins, and fill or copy a username, password or one-time code, or open the item's site in your browser. The same idea as 1Password's Quick Access, built for Proton Pass, which ships an Electron desktop app and no native quick-access of its own.
It also answers System AutoFill, the password menu built into macOS, so your Proton Pass logins appear in Safari and native apps the way iCloud Passwords does.
Not affiliated with or endorsed by Proton AG.
This is a free, open-source side project, and it will stay that way.
If the app is useful to you and you'd like to help with the running costs, the Apple Developer Program membership among them, you can sponsor through GitHub Sponsors. It's entirely optional and changes nothing about the app, which is and remains completely free and fully open source.
Prefer not to sponsor? You can also sign up for Proton with my referral link. You get 2 weeks of a paid plan, and I get a small reward if you subscribe.
| Search | Item detail |
|---|---|
![]() |
![]() |
The app does not reimplement Proton's authentication or cryptography. It drives
the official pass-cli, the
Proton-maintained command-line client, and wraps it in a native macOS UI. Two
front ends sit on top of it: the panel you summon yourself, and the credential
provider macOS loads when something asks for a password. Only the app ever runs
pass-cli.
┌───────────────────────────┐ ┌───────────────────────────┐
│ Floating panel (NSPanel) │ │ AutoFill extension │
│ hotkey ▸ search ▸ pick │ │ sandboxed, asks the app │
└─────────────┬─────────────┘ └─────────────┬─────────────┘
│ │ socket in the shared
│ metadata only │ container, both ends
│ (titles, URLs, │ check the signature
│ usernames) │
┌─────────────▼───────────────────────────────▼───────────┐
│ PassCLIClient (actor over pass-cli) │
│ vault list, item list, item view │
└─────────────┬───────────────────────────────────────────┘
│ secrets fetched just-in-time, never cached
┌─────────────▼───────────────────────────────────────────┐
│ pass-cli ▸ Proton Pass servers │
└─────────────────────────────────────────────────────────┘
- Answers macOS System AutoFill. Click the key icon in any login field and pick Pass Quick Access: no keystrokes, no Accessibility access, and it reaches native apps and not only browsers. One-time codes too, on macOS 15 and later. Off until you turn it on. Details below.
- Floating search panel summoned by a global hotkey (default ⌥⇧Space, configurable). It opens over any app without pulling you out of it, and dismisses when it loses focus.
- Search that matches Proton Pass: the same substring, diacritic-insensitive, multi-word matching as the official client, over titles, usernames, emails, URLs, notes and custom fields. Matches are ranked by relevance, so a hit in the title comes before one buried in a URL or note; with no query, items fall back to most recently modified or alphabetical order.
- Fill or copy, each action shown only when the item has that field:
- Fill Login (types the username, a Tab, then the password), or Fill Username, Fill Password and Fill One-Time Code on their own
- Copy Username, Copy Password, Copy One-Time Code
- Open in Browser, with a chooser when an item has several URLs
- Autofill into the app you came from: rather than copy, the app types the login into the focused field of whatever was frontmost, in any browser or app, by sending real keystrokes. Pick whether choosing an item fills, copies, or both under Settings → Autofill. Filling needs macOS Accessibility access; System AutoFill does not, and is the better route where macOS offers it.
- Knows the page you're on: open the panel over a browser and the item for the current tab is selected for you; when several match the same site, the list is filtered to those. Safari and Chromium browsers are read over Automation; Firefox, Zen and web apps are opt-in, since reading them turns on their accessibility engine.
- Keyboard driven: arrows to move, Page Up/Down and Home/End to jump,
→to open an item,←to step back,escto close. ⌘↩ fills the login, the ⌘C family copies. - Resume: reopen within 30 seconds of an action and you land back on the same item, to grab another field.
- Optional Touch ID lock with a configurable timeout, falling back to your Mac password.
- Stays signed in: when your Proton Pass session expires, the panel offers a one-click sign-in that opens Proton's web login in your browser, then reloads itself and the SSH agent once you're back. Optionally save a Personal Access Token (in the Keychain, behind Touch ID) to reconnect without the browser, reusing your next Touch ID. Set it up under Settings → Account.
- Website icons are off by default; items show a locally generated monogram. You can opt in to fetching favicons, with a clear notice of what that shares. Favicons are never fetched for local or private addresses, including hostnames that resolve to one, so the feature stays off your local network.
Pass Quick Access answers the password menu built into macOS, the one Safari and native apps already show. Click the key icon in a login field, pick Pass Quick Access, and your Proton Pass logins are there, next to iCloud Passwords. Proton Pass ships no native AutoFill on the Mac, so until now the only way into that menu was to keep your logins somewhere else.
It is a different thing from the app typing for you:
- Nothing is typed. Filling from the panel synthesises keystrokes into whatever has focus, which needs Accessibility access and a guess about which field you meant. Here macOS asks for the credential and fills the field itself, so there is no guessing and no Accessibility permission.
- It reaches native apps, not only browsers.
- Secrets are still read just in time. The bundled extension is sandboxed
and reads nothing itself. It asks the app over a socket in a shared container,
and only the app ever runs
pass-cli, so the password is fetched at the moment you pick the item. Both ends verify the other's code signature before a byte is exchanged. - One-time codes too, on macOS 15 and later, where the system asks for verification codes the same way.
- Turn on Answer macOS AutoFill in Settings → Autofill → System.
- In System Settings → General → AutoFill & Passwords, turn Pass Quick Access on under "AutoFill from". Turn Apple's own Passwords off there too if you'd rather not be offered both.
- Click the key icon in any password field and pick Pass Quick Access. Your logins for that site come first, the rest of the vault below.
Two switches because macOS owns the second one. The app cannot register itself as a provider, and it cannot unregister itself either: to stop offering AutoFill, use System Settings rather than the app.
For a row to carry your username before you have picked this app, macOS needs a list of them. That is off by default and has its own switch, because it is the one thing in the app that writes outside its own memory: turning it on saves each login's website and username, and an opaque reference to the item, into the password database macOS manages. Never a password, never a one-time code, never anything else from the item. Turning it off removes what was written. With it off AutoFill still works, you just pick Pass Quick Access and search.
- Where it works: Safari and native apps. Chrome, Firefox and the rest don't use the system provider, so there you summon the panel with the hotkey and let the app type, exactly as before. The two live side by side, and turning one on takes nothing away from the other.
- Two Touch ID prompts? macOS has its own Use Touch ID for autofilling passwords under Touch ID & Password, on by default, and it asks in addition to this app's optional lock. Turn off whichever of the two you'd rather not answer; both are yours to set.
- No passkeys. Providing one means holding the credential's private key and
signing the WebAuthn challenge, and
pass-cliexposes neither, so the app stays out of the passkey picker rather than appearing there and failing. - macOS 27.0: some sign-in forms crash Safari when a password manager fills them, 1Password included. It is a defect in Safari's own form filling rather than in any extension, it is reported to Apple, and nothing a credential provider sends can prevent it.
- The app has to be running, since the extension cannot read a vault by itself. See Open at login.
An optional SSH agent serves your Proton Pass SSH keys to git and ssh, the
way 1Password's does, and asks for Touch ID before a signature, naming the app
that requested it. It is off by default; turn it on under Settings → SSH.
It does not hold keys or sign anything itself. pass-cli already ships an SSH
agent that stores the keys and does the signing; this app runs a thin proxy
in front of it that adds the native confirmation. Private keys never enter the
app, consistent with the security model below. One approval covers further
signatures from the same program on the same key for five minutes by default
(Settings → SSH → Trusted Apps, anything from every signature to eight hours),
you can mark an app trusted for a key so it stops asking, and non-interactive
BatchMode probes are denied without a prompt. The window matters more than it
sounds: background tools such as an editor's automatic fetch sign every couple of
minutes on their own.
- Store an SSH key in Proton Pass. SSH keys live under Custom item (the
"Other" type) in the Proton Pass apps.
pass-cli ssh-agent debug --vault-name <name>lists which of your items are usable as SSH keys. - Enable the agent in Settings → SSH. The app starts the upstream
pass-cliagent for you (it fetches your keys from Proton, so the status reaches Running after a few seconds). - Point SSH at the proxy. Flip on Configure ~/.ssh/config automatically and
the app writes the entry for you (and removes it when you turn it back off):
For most people that's all you need:
Host * IdentityAgent ~/.ssh/pass-quick-access-agent.socksshandgitread~/.ssh/config. Some tools ignore it and only look at theSSH_AUTH_SOCKenvironment variable (ssh-add, some GUI clients, certain scripts). If you use those, also enable Set SSH_AUTH_SOCK for new programs: it publishes the proxy socket to your login session vialaunchctl, so they pick it up too. It applies to programs launched afterwards, so quit and reopen a terminal (or app) for it to take effect. - Use
gitandsshnormally. A signature pops a Touch ID prompt naming the app and key. Check the keys are served with:SSH_AUTH_SOCK=~/.ssh/pass-quick-access-agent.sock ssh-add -l
The workflow is the same one you already know:
- Move (or recreate) your SSH keys as Proton Pass items, and register the public keys with your servers / GitHub as usual.
- Let the app write its
~/.ssh/configentry (step 3 above), then remove 1Password's ownIdentityAgentline and turn off its SSH agent. The app only manages its own block, so anything another tool added is yours to clean up. - Gotcha shared by every agent: an explicit on-disk
IdentityFilefor a host takes precedence over the agent, sosshuses the file (and prompts for its passphrase) instead of asking the agent. Remove theIdentityFilelines for the hosts you want served from Proton Pass.
Pass Quick Access lives in the menu bar, and while it isn't running there is no hotkey, no SSH agent and no AutoFill: the credential-provider extension is sandboxed and cannot read a vault by itself. Turn on Settings → General → Open at login and macOS starts it for you. If a password prompt finds the app closed, the extension asks macOS to start it and tries again.
- Secrets are never persisted or indexed. The in-memory index holds only
titles, URLs, usernames and the presence of a password or one-time code, never
the secret values. Passwords and codes are read fresh from
pass-cliat the moment you copy them, handed to the pasteboard, and the pasteboard entry is marked concealed and cleared after 30 seconds. System AutoFill's optional suggestion list stores a website, a username and an item reference, never a secret, and is off until you turn it on (see SECURITY.md). - Authentication lives in
pass-cli. The app holds no Proton credentials and relies on the CLI's existing session. - The trust boundary is that session. Anyone who can run code as your user
can already read everything through
pass-clidirectly, so the app is careful not to be a weaker link: nothing is written to disk unless you turn on the AutoFill suggestion list, and signed release builds use the hardened runtime withoutget-task-allowso other processes can't attach. - An optional Touch ID lock guards casual access to an unlocked Mac. It is not a defense against local code execution.
Download PassQuickAccess.zip from the
latest release,
unzip it, and move the app to /Applications. From then on it tells you when a
new version is out and installs it only when you pick "Update Now".
You'll also need pass-cli installed and logged in (see Requirements).
- macOS 14 or later
pass-cliinstalled and logged in (pass-cli login). The CLI requires a paid Proton Pass plan.- XcodeGen, to build from source
xcodegen generate
xcodebuild -scheme PassQuickAccess -destination 'platform=macOS' -derivedDataPath build build
open build/Build/Products/Debug/PassQuickAccess.appRun the tests with:
xcodebuild -scheme PassQuickAccess -destination 'platform=macOS' testPassQuickAccess.xcodeproj is generated from project.yml and is not checked
in. By default the project builds ad-hoc signed, which is enough to run it
locally; to sign with your own Apple Developer identity, copy
Config/Local.xcconfig.example to Config/Local.xcconfig and fill in your team.
Producing a release artifact is documented separately.
- The CLI is the only supported way in. There is no public Proton Pass API, so
the app is as capable as
pass-cliand no more. - Ordering uses the item's modification time. The official app also factors in
last-use time, which
pass-clidoes not expose. If you'd like it to, vote for this Proton feature request.
See CONTRIBUTING.md. Security reports go through SECURITY.md.
GNU General Public License v3.0. This is a community project and is not affiliated with or endorsed by Proton AG.




