What macOS Input Monitoring Permissions Are Required for OpenLogi?

OpenLogi requires macOS Input Monitoring permissions for both the Agent and CLI components to access Logitech HID++ devices, with the Agent additionally requiring Accessibility permissions to install event taps for the Actions Ring UI.

OpenLogi is an open-source tool by AprilNEA for controlling Logitech devices on macOS. To interact with the HID (Human Interface Device) layer and provide per-application button remapping, the application must obtain specific macOS Input Monitoring permissions through the Transparency, Consent, and Control (TCC) framework.

Why OpenLogi Needs Input Monitoring Permissions

The Input Monitoring permission grants processes access to low-level input events from the HID layer. According to the OpenLogi source code in crates/openlogi-hid/src/permissions.rs, the application wraps IOHIDCheckAccess and IOHIDRequestAccess to verify and request access to HID devices.

When either permission is missing, OpenLogi emits clear error messages such as: "Failed to open device: Input Monitoring is NOT granted to this process". This occurs because the agent cannot open HID++ devices without explicit user consent through System Settings.

Permission Requirements by Component

OpenLogi consists of two distinct components with different permission requirements based on their functionality and bundle identifiers.

OpenLogi Agent (org.openlogi.agent)

The OpenLogi Agent, located at /Applications/OpenLogi.app/Contents/Library/LoginItems/OpenLogi Agent.app with bundle identifier org.openlogi.agent, requires two permissions:

  • Input Monitoring – Grants the agent access to the HID layer to open HID++ devices and listen to low-level input events.
  • Accessibility – Allows the agent to install the event-tap that drives the Actions Ring UI and synthesize input for per-app button remapping and DPI changes.

OpenLogi CLI (openlogi)

The openlogi binary embedded within the GUI at …/Contents/MacOS/openlogi uses bundle identifier openlogi. It requires Input Monitoring only when falling back to direct HID access, such as when running openlogi list or hardware-diagnostic sub-commands. If the agent is unavailable, the CLI must communicate directly with devices, necessitating Input Monitoring permissions.

How to Grant macOS Input Monitoring Permissions

Granting permissions requires navigating to System Settings and adding the specific bundle identifiers to the allowed lists.

First, verify the current permission status by running the CLI:

openlogi list

If permissions are missing, open System Settings directly to the Input Monitoring pane:

open "x-apple.systempreferences:com.apple.preference.security?Privacy_InputMonitoring"

Add the OpenLogi Agent to the allowed list:

  1. Click the "+" button
  2. Navigate to OpenLogi Agent.app (found in /Applications/OpenLogi.app/Contents/Library/LoginItems/)
  3. Check the box next to it

For the Agent component, also grant Accessibility permissions:

open "x-apple.systempreferences:com.apple.preference.security?Privacy_Accessibility"

Finally, restart the agent so the new grants take effect:

pkill -f OpenLogiAgent

Technical Implementation in the OpenLogi Source Code

The permission model is implemented across several Rust crates in the AprilNEA/OpenLogi repository.

Permission Checking in openlogi-permissions

The crates/openlogi-permissions/src/macos.rs file implements the TCC checks for Input Monitoring and Accessibility. The core function verifies status before attempting HID operations:

// crates/openlogi-permissions/src/macos.rs
/// Returns the current Input Monitoring status.
pub fn input_monitoring_granted() -> bool {
    // Calls `IOHIDCheckAccess` (macOS TCC) under the hood.
}

The underlying HID permissions are managed in crates/openlogi-hid/src/permissions.rs, which provides wrappers around IOHIDCheckAccess and IOHIDRequestAccess.

Agent Startup Flow

In crates/openlogi-agent/src/startup.rs, the agent requests Input Monitoring before starting the HID inventory. If the grant is missing, the agent invokes IOHIDRequestAccess to trigger the system dialog.

Relaunch Handling

Once the user grants permissions, the agent must restart to load the new entitlements. The crates/openlogi-agent/src/binary_watch/relaunch.rs file handles this relaunch sequence, scheduling a restart after the permission grant is detected.

User-Facing Error Messages

The CLI provides clear feedback when permissions are missing. In crates/openlogi-cli/src/cmd/list.rs, the code displays user-facing messages explaining which specific permissions are required and how to grant them.

Summary

  • OpenLogi requires macOS Input Monitoring permissions to access Logitech HID++ devices through the TCC framework.
  • The OpenLogi Agent (org.openlogi.agent) requires both Input Monitoring and Accessibility permissions.
  • The OpenLogi CLI (openlogi) requires Input Monitoring only when accessing devices directly without the agent.
  • Permissions must be granted to specific bundle identifiers in System Settings → Privacy & Security.
  • The source code implements permission checks in crates/openlogi-permissions/src/macos.rs and handles relaunches via crates/openlogi-agent/src/binary_watch/relaunch.rs.

Frequently Asked Questions

What error messages indicate missing Input Monitoring permissions?

When Input Monitoring permissions are missing, OpenLogi displays the error: "Failed to open device: Input Monitoring is NOT granted to this process". The CLI commands such as openlogi list will fail with clear messaging directing you to System Settings to enable the permission for the specific bundle identifier.

Why does the OpenLogi Agent need Accessibility permissions in addition to Input Monitoring?

The Agent requires Accessibility permissions to install the event-tap that drives the Actions Ring UI. According to the source code in .claude/skills/openlogi-macos-permissions/SKILL.md, this permission allows the agent to synthesize input events for per-application button remapping and DPI changes, functionality that requires both monitoring and injection capabilities.

Can I use OpenLogi CLI without granting permissions to the Agent?

Yes, but with limitations. The CLI (openlogi binary with identifier openlogi) can function independently for hardware diagnostics and device listing, but it requires Input Monitoring permissions when falling back to direct HID access without the Agent. Granting permissions only to the CLI binary will not enable full functionality if the Agent lacks its required Input Monitoring and Accessibility grants.

How do I verify that permissions are correctly granted to the right bundle?

Verify permissions by running openlogi list from the terminal. If the command executes without TCC errors and lists your Logitech devices, Input Monitoring is properly granted. macOS applies TCC grants to signed bundle identities, so ensure you see org.openlogi.agent and openlogi specifically listed in System Settings → Privacy & Security → Input Monitoring, not just your terminal application.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →