# What macOS Input Monitoring Permissions Are Required for OpenLogi?

> Discover the macOS Input Monitoring permissions needed for OpenLogi. Learn which permissions the Agent and CLI require for Logitech HID++ device access and UI functionality.

- Repository: [Xuan Zhang/OpenLogi](https://github.com/AprilNEA/OpenLogi)
- Tags: how-to-guide
- Published: 2026-09-12

---

**OpenLogi requires macOS Input Monitoring permissions for both the Agent and CLI components to access Logitech HID++ devices, with the Agent additionally requiring Accessibility permissions to install event taps for the Actions Ring UI.**

OpenLogi is an open-source tool by AprilNEA for controlling Logitech devices on macOS. To interact with the HID (Human Interface Device) layer and provide per-application button remapping, the application must obtain specific **macOS Input Monitoring** permissions through the Transparency, Consent, and Control (TCC) framework.

## Why OpenLogi Needs Input Monitoring Permissions

The **Input Monitoring** permission grants processes access to low-level input events from the HID layer. According to the OpenLogi source code in [`crates/openlogi-hid/src/permissions.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-hid/src/permissions.rs), the application wraps `IOHIDCheckAccess` and `IOHIDRequestAccess` to verify and request access to HID devices.

When either permission is missing, OpenLogi emits clear error messages such as: *"Failed to open device: Input Monitoring is NOT granted to this process"*. This occurs because the agent cannot open HID++ devices without explicit user consent through System Settings.

## Permission Requirements by Component

OpenLogi consists of two distinct components with different permission requirements based on their functionality and bundle identifiers.

### OpenLogi Agent (org.openlogi.agent)

The OpenLogi Agent, located at `/Applications/OpenLogi.app/Contents/Library/LoginItems/OpenLogi Agent.app` with bundle identifier `org.openlogi.agent`, requires two permissions:

- **Input Monitoring** – Grants the agent access to the HID layer to open HID++ devices and listen to low-level input events.
- **Accessibility** – Allows the agent to install the event-tap that drives the Actions Ring UI and synthesize input for per-app button remapping and DPI changes.

### OpenLogi CLI (openlogi)

The `openlogi` binary embedded within the GUI at `…/Contents/MacOS/openlogi` uses bundle identifier `openlogi`. It requires **Input Monitoring** only when falling back to direct HID access, such as when running `openlogi list` or hardware-diagnostic sub-commands. If the agent is unavailable, the CLI must communicate directly with devices, necessitating Input Monitoring permissions.

## How to Grant macOS Input Monitoring Permissions

Granting permissions requires navigating to System Settings and adding the specific bundle identifiers to the allowed lists.

First, verify the current permission status by running the CLI:

```bash
openlogi list

```

If permissions are missing, open System Settings directly to the Input Monitoring pane:

```bash
open "x-apple.systempreferences:com.apple.preference.security?Privacy_InputMonitoring"

```

Add the OpenLogi Agent to the allowed list:

1. Click the "+" button
2. Navigate to `OpenLogi Agent.app` (found in `/Applications/OpenLogi.app/Contents/Library/LoginItems/`)
3. Check the box next to it

For the Agent component, also grant Accessibility permissions:

```bash
open "x-apple.systempreferences:com.apple.preference.security?Privacy_Accessibility"

```

Finally, restart the agent so the new grants take effect:

```bash
pkill -f OpenLogiAgent

```

## Technical Implementation in the OpenLogi Source Code

The permission model is implemented across several Rust crates in the AprilNEA/OpenLogi repository.

### Permission Checking in openlogi-permissions

The [`crates/openlogi-permissions/src/macos.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-permissions/src/macos.rs) file implements the TCC checks for Input Monitoring and Accessibility. The core function verifies status before attempting HID operations:

```rust
// crates/openlogi-permissions/src/macos.rs
/// Returns the current Input Monitoring status.
pub fn input_monitoring_granted() -> bool {
    // Calls `IOHIDCheckAccess` (macOS TCC) under the hood.
}

```

The underlying HID permissions are managed in [`crates/openlogi-hid/src/permissions.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-hid/src/permissions.rs), which provides wrappers around `IOHIDCheckAccess` and `IOHIDRequestAccess`.

### Agent Startup Flow

In [`crates/openlogi-agent/src/startup.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-agent/src/startup.rs), the agent requests Input Monitoring before starting the HID inventory. If the grant is missing, the agent invokes `IOHIDRequestAccess` to trigger the system dialog.

### Relaunch Handling

Once the user grants permissions, the agent must restart to load the new entitlements. The [`crates/openlogi-agent/src/binary_watch/relaunch.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-agent/src/binary_watch/relaunch.rs) file handles this relaunch sequence, scheduling a restart after the permission grant is detected.

### User-Facing Error Messages

The CLI provides clear feedback when permissions are missing. In [`crates/openlogi-cli/src/cmd/list.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-cli/src/cmd/list.rs), the code displays user-facing messages explaining which specific permissions are required and how to grant them.

## Summary

- OpenLogi requires **macOS Input Monitoring** permissions to access Logitech HID++ devices through the TCC framework.
- The **OpenLogi Agent** (`org.openlogi.agent`) requires both Input Monitoring and Accessibility permissions.
- The **OpenLogi CLI** (`openlogi`) requires Input Monitoring only when accessing devices directly without the agent.
- Permissions must be granted to specific bundle identifiers in **System Settings → Privacy & Security**.
- The source code implements permission checks in [`crates/openlogi-permissions/src/macos.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-permissions/src/macos.rs) and handles relaunches via [`crates/openlogi-agent/src/binary_watch/relaunch.rs`](https://github.com/AprilNEA/OpenLogi/blob/main/crates/openlogi-agent/src/binary_watch/relaunch.rs).

## Frequently Asked Questions

### What error messages indicate missing Input Monitoring permissions?

When Input Monitoring permissions are missing, OpenLogi displays the error: *"Failed to open device: Input Monitoring is NOT granted to this process"*. The CLI commands such as `openlogi list` will fail with clear messaging directing you to System Settings to enable the permission for the specific bundle identifier.

### Why does the OpenLogi Agent need Accessibility permissions in addition to Input Monitoring?

The Agent requires **Accessibility** permissions to install the event-tap that drives the Actions Ring UI. According to the source code in [`.claude/skills/openlogi-macos-permissions/SKILL.md`](https://github.com/AprilNEA/OpenLogi/blob/main/.claude/skills/openlogi-macos-permissions/SKILL.md), this permission allows the agent to synthesize input events for per-application button remapping and DPI changes, functionality that requires both monitoring and injection capabilities.

### Can I use OpenLogi CLI without granting permissions to the Agent?

Yes, but with limitations. The CLI (`openlogi` binary with identifier `openlogi`) can function independently for hardware diagnostics and device listing, but it requires **Input Monitoring** permissions when falling back to direct HID access without the Agent. Granting permissions only to the CLI binary will not enable full functionality if the Agent lacks its required Input Monitoring and Accessibility grants.

### How do I verify that permissions are correctly granted to the right bundle?

Verify permissions by running `openlogi list` from the terminal. If the command executes without TCC errors and lists your Logitech devices, Input Monitoring is properly granted. macOS applies TCC grants to signed bundle identities, so ensure you see `org.openlogi.agent` and `openlogi` specifically listed in System Settings → Privacy & Security → Input Monitoring, not just your terminal application.