release · August 29, 2026

Keychain 3.0.4: A Quieter, More Careful Agent

Keychain 3.0.2 through 3.0.4 harden agent state validation after reboot, fix legacy command-line translation, and quiet down shell startup.

Since the Keychain 3.0.1 announcement, three focused maintenance releases have shipped: 3.0.2, 3.0.3, and 3.0.4. Together they tighten the parts of Keychain that matter most in daily use: trusting the right agent after a reboot, keeping legacy 2.x invocations working, and making shell startup quieter.

Improved Live Agent Detection

The headline fix in 3.0.4 addresses a subtle but real reliability problem. Keychain records the PID and socket of your ssh-agent in a pidfile under ~/.keychain/ so that future shells, cron jobs, and background tasks can reconnect. After a reboot, that pidfile still exists — but the agent it points to is gone.

Previously, Keychain checked whether the recorded PID was a live process. On a busy system, PIDs get recycled: a new, unrelated process can inherit the same number. Combined with an orphaned socket file that survived the reboot, a stale pidfile could look valid, and Keychain would try to load keys into an agent that wasn't really there.

3.0.4 raises the bar. A recorded PID must now belong to a running ssh-agent process (matched by name, not just liveness), and its socket must respond to ssh-add -l like a real agent. If either check fails, Keychain rejects the stale reference and selects or starts a valid agent. No more "why didn't keychain find my agent?" surprises after a reboot. (Fixes #246 and #247.)

Legacy 2.x Invocations, Fixed

Keychain 3 has maintained a compatibility layer so that traditional 2.x command lines keep working:

A traditional 2.x-style invocation
$ eval `keychain --eval --quiet id_rsa`

3.0.2 corrects a translation bug where options that take values — such as --timeout 180 — could be regrouped and misinterpreted when the legacy parser re-ordered arguments. Your existing shell snippets now translate faithfully. (Fixes #236.)

3.0.2 also adds validation for fixed lists of values. keychain env --shell now rejects unsupported output formats and lists the valid choices instead of silently falling back. (Fixes #234.)

Quieter Shell Startup

--quiet now passes OpenSSH's native -q option to ssh-add, suppressing the per-key Identity added reports while preserving passphrase prompts and error messages. For a shell startup line like:

Quiet automatic shell startup
$ eval "$(keychain add --eval --quiet id_ed25519)"

the output is clean: no success chatter, just the environment you need. (Fixes #237.)

3.0.3: Correctness for Edge Cases

3.0.3 restored --clear to its original behavior: an SSH-only wipe followed by a full reload of the requested key set, without flushing GnuPG's passphrase cache. And --ignore-missing now exits cleanly when every requested key is absent — no agent started, no pidfile written, no output. (Fixes #243 and #242.)

A Friendlier Hostname Override

3.0.4 adds --hostname as an alias for --host, making the per-host pidfile override easier to discover:

Override the hostname for pidfile naming
$ keychain add --hostname buildbox-01 id_ed25519

Get Keychain 3.0.4

Download keychain-3.0.4.pyz and its SHA256 checksum from the Keychain 3.0.4 release page. If you're already on 3.x, the upgrade is a drop-in replacement:

Upgrade to Keychain 3.0.4
$ chmod +x keychain-3.0.4.pyz
$ sudo install -m 755 keychain-3.0.4.pyz /usr/local/bin/keychain
$ keychain inspect

Please report any problems on the GitHub issue tracker.