release · August 29, 2026
Keychain 3.0.4: A Quieter, More Careful Agent
Keychain 3.0.2 through 3.0.4 harden agent state validation after reboot, fix legacy command-line translation, and quiet down shell startup.
Since the Keychain 3.0.1 announcement, three focused maintenance releases have shipped: 3.0.2, 3.0.3, and 3.0.4. Together they tighten the parts of Keychain that matter most in daily use: trusting the right agent after a reboot, keeping legacy 2.x invocations working, and making shell startup quieter.
Improved Live Agent Detection
The headline fix in 3.0.4 addresses a subtle but real reliability problem. Keychain records the PID and socket of your ssh-agent in a pidfile under ~/.keychain/ so that future shells, cron jobs, and background tasks can reconnect. After a reboot, that pidfile still exists — but the agent it points to is gone.
Previously, Keychain checked whether the recorded PID was a live process. On a busy system, PIDs get recycled: a new, unrelated process can inherit the same number. Combined with an orphaned socket file that survived the reboot, a stale pidfile could look valid, and Keychain would try to load keys into an agent that wasn't really there.
3.0.4 raises the bar. A recorded PID must now belong to a running ssh-agent process (matched by name, not just liveness), and its socket must respond to ssh-add -l like a real agent. If either check fails, Keychain rejects the stale reference and selects or starts a valid agent. No more "why didn't keychain find my agent?" surprises after a reboot. (Fixes #246 and #247.)
Legacy 2.x Invocations, Fixed
Keychain 3 has maintained a compatibility layer so that traditional 2.x command lines keep working:
$ eval `keychain --eval --quiet id_rsa`
3.0.2 corrects a translation bug where options that take values — such as --timeout 180 — could be regrouped and misinterpreted when the legacy parser re-ordered arguments. Your existing shell snippets now translate faithfully. (Fixes #236.)
3.0.2 also adds validation for fixed lists of values. keychain env --shell now rejects unsupported output formats and lists the valid choices instead of silently falling back. (Fixes #234.)
Quieter Shell Startup
--quiet now passes OpenSSH's native -q option to ssh-add, suppressing the per-key Identity added reports while preserving passphrase prompts and error messages. For a shell startup line like:
$ eval "$(keychain add --eval --quiet id_ed25519)"
the output is clean: no success chatter, just the environment you need. (Fixes #237.)
3.0.3: Correctness for Edge Cases
3.0.3 restored --clear to its original behavior: an SSH-only wipe followed by a full reload of the requested key set, without flushing GnuPG's passphrase cache. And --ignore-missing now exits cleanly when every requested key is absent — no agent started, no pidfile written, no output. (Fixes #243 and #242.)
A Friendlier Hostname Override
3.0.4 adds --hostname as an alias for --host, making the per-host pidfile override easier to discover:
$ keychain add --hostname buildbox-01 id_ed25519
Get Keychain 3.0.4
Download keychain-3.0.4.pyz and its SHA256 checksum from the Keychain 3.0.4 release page. If you're already on 3.x, the upgrade is a drop-in replacement:
$ chmod +x keychain-3.0.4.pyz
$ sudo install -m 755 keychain-3.0.4.pyz /usr/local/bin/keychain
$ keychain inspect
Please report any problems on the GitHub issue tracker.