Check the common questions below first — most issues are covered. If yours isn't, use the form at the bottom and we'll reply within 24 hours.
KeyStack uses macOS LocalAuthentication to unlock the vault. If Touch ID doesn't appear, check System Settings → Touch ID & Password and make sure Touch ID is enrolled. On Macs without Touch ID, KeyStack will fall back to your login password. If you're on a Mac connected to an external keyboard, the Touch ID prompt may appear on the built-in sensor rather than the keyboard.
No — this is intentional. KeyStack locks automatically on focus loss to prevent secrets from being visible if you step away from your desk or share your screen. One authentication unlocks the vault for the current session; switching apps resets it. This matches the security model described in the App Store listing.
KeyStack scans for files named .env, .env.local, .env.development, .env.staging, .env.production, and .env.test in the folder you select. Files with different names (e.g. .env.custom or environment.env) won't be picked up automatically. If your files aren't being found, confirm the exact filenames in Finder first. The app is sandboxed — you must grant access to the folder via the system file picker; it cannot access directories you haven't explicitly opened.
If a variable already exists in the project with the same key, the import flags it as a duplicate and skips it to avoid overwriting. Review the import preview screen — duplicates are highlighted in red. To overwrite an existing value, delete the variable first and then re-import.
Go to System Settings → Notifications → KeyStack and make sure notifications are allowed. KeyStack requests notification permission the first time you set a rotation interval — if you declined that prompt, you'll need to re-enable it manually in System Settings. Notifications are delivered by macOS; if Do Not Focus is active, they may be queued.
Open the KeyStack menu bar item and click Activate beside a project. KeyStack writes the environment and filename saved in that project's Export Settings, then shows a live countdown until deletion. Click Deactivate to remove the file immediately. You can set a global timeout in Settings and override it for an individual project from the gear button beside that project.
KeyStack removes active exports when the Mac sleeps, the display sleeps, or the screen locks. If you quit normally while a project is active, KeyStack asks whether to deactivate before quitting. If the app is force-quit, crashes, or the Mac loses power, the plaintext file can remain until KeyStack launches again and cleans it up. You can review each activation and deactivation in Settings → View Activity Log.
Enable the shortcut in KeyStack Settings, then check System Settings → Privacy & Security → Input Monitoring and make sure KeyStack is allowed. macOS controls that permission, and KeyStack cannot confirm from inside the app whether it was granted. The shortcut re-activates the most recently used project with its remembered environment, filename, and timeout.
KeyStack does not sync through iCloud or a KeyStack server. To move the vault, create an encrypted, password-protected whole-vault backup, transfer that file yourself, and restore it on the other Mac. The backup is never transmitted by KeyStack. This is manual transfer, not ongoing multi-Mac sync.
KeyStack requires macOS Sonoma (14.0) or later. It runs on macOS Sequoia (15) as well. It is not compatible with macOS Ventura (13) or earlier.
App Store purchases are handled by Apple. Visit reportaproblem.apple.com to request a refund — Apple processes these directly and NerdSnipe Inc. is not involved in the transaction. Refund decisions are made by Apple.
Include your macOS version and a description of what happened. We respond within 24 hours on weekdays. You can also email us directly at hello@nerdsnipe.cc.