QtPass on macOS
QtPass runs on macOS, and the .dmg for every release is
built on GitHub's macOS runners. Two things make it more work than it
should be: the app is not signed, so macOS refuses it once, and the
Homebrew cask is disabled for the same reason. Here is how to install
it anyway, how to get GnuPG asking for your passphrase properly, and
what would fix the signing for good.
Install QtPass 1.8.2 on macOS
-
Download
QtPass-1.8.2.dmg
from the
releases page; the
.ascnext to it is a GnuPG signature you can verify the download with. - Open the image and drag QtPass to your Applications folder.
-
Launch it once. macOS refuses, because the download carries the
quarantine flag and the app is unsigned. Either remove the flag:
or open System Settings → Privacy & Security right after the refused launch and click Open Anyway. On macOS 15 and later, right-click → Open no longer bypasses Gatekeeper for unsigned apps.xattr -d com.apple.quarantine /Applications/QtPass.app
brew install --cask qtpass does not work since 1
September 2026; Homebrew disables every cask whose app fails the
Gatekeeper check. The formula is not broken, the app is just not
signed (why).
GnuPG and the passphrase dialog
QtPass needs gpg; pass and git
are optional. Homebrew's GnuPG works, but without a graphical pinentry
you get no passphrase prompt in a GUI app. Install both and tell the
agent to use it:
brew install gnupg pinentry-mac
echo "pinentry-program $(brew --prefix)/bin/pinentry-mac" \
>> ~/.gnupg/gpg-agent.conf
gpgconf --kill gpg-agent
In QtPass, Configuration → Programs should show
the Homebrew gpg: /opt/homebrew/bin/gpg on
Apple silicon, /usr/local/bin/gpg on Intel. Fill it in
when autodetection picks nothing. The
FAQ has more on
pinentry, and a note on
QR codes on macOS.
Build from source
brew install qt pass pinentry-mac
git clone https://github.com/IJHack/QtPass.git
cd QtPass
qmake6 && make && macdeployqt QtPass.app
A locally built app has no quarantine flag, so it opens without the detour above.
Why QtPass is not signed
Signing and notarizing a macOS app needs a paid Apple Developer Program membership, about 99 euro per year. QtPass is maintained by volunteers in their spare time; none of us use macOS any more (I have not touched a MacBook in five years) and none of us have that membership. QtPass started life as a macOS-only app, so there is some irony here.
The build side is solved: GitHub Actions already produce the
.dmg. What is missing is a Developer ID certificate to
sign it with and an account to notarize it against.
How you can help
Best option: you or your company already have an Apple Developer ID. Then you can sign and notarize our releases. It is a one-time setup: a Developer ID Application certificate and an app-specific password go into the GitHub Actions secrets, and from then on every release is signed and notarized automatically. Say hello in #1542.
Otherwise: fund the account. 100 euro covers one year of the Apple Developer Program. Two ways to do that:
- Sponsor the maintainer on GitHub Sponsors.
- Donate a minimum of 100 euro to Stichting Aid to Ukraine. It is a Dutch ANBI charity (tax-deductible in the Netherlands, RSIN 866916556) that brings vehicles, medical supplies and IT equipment to Kharkiv. Send proof of the donation to help@qtpass.org and I will pay Apple out of my own pocket. Honestly, this is the option I prefer.
As soon as the year is covered I will enrol, put signing and
notarization into the release pipeline, publish a notarized 1.8.x
.dmg, and ask Homebrew to re-enable the cask.
Status
- August 2025
- Homebrew announces that casks failing the Gatekeeper check will be disabled.
- 16 June 2026
- Stefan reports it in #1542; thank you.
- 1 September 2026
-
The cask is disabled:
disable! date: "2026-09-01", because: :fails_gatekeeper_check. - 13 September 2026
- QtPass 1.8.0 ships, unsigned
.dmg. - 18 September 2026
-
QtPass 1.8.2 ships, unsigned
.dmg. No sponsor yet.
The other platforms are unaffected; see downloads. Thanks to everyone who keeps QtPass running on a platform its maintainers no longer use.