Mac Keeps Asking for Your Keychain Password
Short answer
macOS unlocks your login keychain automatically using your account password. When the two stop matching — usually after a password change made elsewhere — the keychain stays locked and every app asks for it. Fix it in Keychain Access → Edit → Change Password for Keychain "login", entering the old keychain password and your current account password.
On this page
Every few minutes an app asks for the password to the keychain called “login”. You type your account password. It is rejected, or it works and the prompt comes back an hour later.
The prompt is accurate and it is telling you something specific: the password protecting your keychain is no longer the password you log in with. macOS normally unlocks the keychain for you at login using your account password, and when those two values differ it cannot, so every app that wants a stored credential has to ask you directly.
How the two drift apart
| Cause | What happened |
|---|---|
| Password reset via Apple Account or FileVault recovery | The account password changed; the keychain’s did not |
| An administrator reset your password | Same mismatch, done by someone else |
| Restored from a backup or migrated Macs | The keychain came from a different account state |
| Changed the password on another Mac | iCloud updated the account, not the local keychain |
| Keychain file corruption | The file is damaged rather than mismatched |
The first row covers most cases. Resetting a forgotten password through Apple’s recovery route deliberately does not change the keychain password, because macOS cannot decrypt the keychain without the old one. The design is correct; the experience afterwards is not.
The fix, if you remember the old password
This keeps all your saved passwords, so try it first.
- Open Keychain Access — Applications → Utilities → Keychain Access. On recent macOS versions it is still there even though password management has moved into System Settings.
- Select the login keychain in the sidebar.
- From the menu bar, choose Edit → Change Password for Keychain “login”.
- Enter the old keychain password — your previous account password.
- Enter your current account password as the new one, twice.
Log out and back in. The keychain now unlocks automatically again, and the prompts stop.
If the old password is rejected, you have either misremembered it or the keychain is corrupted rather than mismatched. Try any earlier passwords you might have used before moving on.
If you cannot remember the old password
There is no recovery path. The keychain is encrypted with that password and nobody, including Apple, can open it without one of them. The only option is to start a new keychain.
This deletes every password stored only in the login keychain — saved Wi-Fi networks, app credentials, certificates, and any website logins not synced to iCloud. Before doing it, open Keychain Access and look through the login keychain for anything irreplaceable. You can view an individual password by double-clicking an entry and ticking the option to show it, which requires the keychain password — so this only works while you still have some access.
To start fresh, use the reset option in Keychain Access preferences, which creates a new empty login keychain and archives the old one rather than destroying it outright. The archived file stays on disk, so if the old password comes back to you later it is still openable.
Afterwards, expect to re-enter Wi-Fi passwords and sign back into several apps over the following days. Finding a saved Wi-Fi password is worth reading before the reset rather than after, since the keychain is where those live.
What iCloud Keychain does and does not cover
iCloud Keychain syncs website logins, passkeys, credit cards and Wi-Fi passwords across your Apple devices, and it is stored separately from the local login keychain.
The practical consequence is important: if iCloud Keychain is on, a local keychain reset loses far less than it otherwise would, because your website passwords are still on your iPhone and in iCloud. App-specific credentials, certificates and developer keys are generally local only, and those do not come back.
Check its status under System Settings → Apple Account → iCloud, in the passwords and keychain section. Turning it on before any reset is sensible, and it is also the reason the prompts sometimes appear on a Mac where nothing obviously changed — a sync that needs re-authentication can trigger them.
Prompts that are not a mismatch
A few variations mean something slightly different.
- “Keychain not found” or a keychain the apps cannot see. The login keychain file is missing or unreadable. Keychain Access’s first aid or a reset is the route.
- Prompts only from one app. That app is asking for a credential it does not have permission to read. Click Always Allow when it appears, and only for an app you recognise.
- Prompts after waking from sleep. Check whether a setting locks the keychain after a period of inactivity, in the keychain’s settings within Keychain Access. Some managed or work Macs set this deliberately.
- Prompts on a work-managed Mac. The configuration may be enforced by your organisation’s device management, in which case local changes get reverted and the IT desk is the correct answer.
Realistic expectations
Where you remember the old password, the change-password route takes two minutes and nothing is lost. That is the majority of cases, because most people arrive here days after resetting a forgotten login password and can still recall what it used to be.
The honest limit is the other case. A forgotten keychain password with iCloud Keychain switched off means those credentials are gone, and no utility, service or paid tool recovers them. Encryption that could be bypassed would not be worth having. Reset, re-enter what you must, and turn iCloud Keychain on so the next time this happens it costs you an afternoon rather than an archive.