Security Considerations for Palmier Pro: Keychain Storage, Localhost Binding, and Code Signing

Palmier Pro stores API keys in the macOS Keychain, binds its MCP server exclusively to localhost, uses TLS-encrypted URLSession for external calls, and distributes signed binaries with explicit entitlements.

Palmier Pro is a native macOS video editor optimized for Apple Silicon that integrates generative AI features through user-provided API keys. Because the application handles sensitive credentials and runs a local HTTP server for MCP (Model Context Protocol) integration, the codebase implements strict security measures following Apple's platform best practices. This article examines the concrete security considerations for Palmier Pro based on its actual implementation in the palmier-io/palmier-pro repository.

Secure Storage of Secrets in macOS Keychain

KeychainStore Implementation

Palmier Pro never writes API keys to disk in plain text. Instead, the app uses a thin wrapper called KeychainStore located in Sources/PalmierPro/Utilities/KeychainStore.swift to persist secrets in the macOS Keychain.

The wrapper performs four critical operations:

  • Derives a service identifier from the app's bundle identifier (Bundle.main.bundleIdentifier ?? "io.palmier.pro") to create a unique Keychain entry.
  • Writes using SecItemAdd when the key does not exist, or updates via SecItemUpdate for existing entries.
  • Reads with SecItemCopyMatching, returning a trimmed UTF-8 string.
  • Deletes with SecItemDelete when the user removes their credentials.

Required Entitlements

Even for non-sandboxed applications, macOS requires the appropriate access-group entitlement for Keychain use. The scripts/PalmierPro.entitlements file declares keychain-access-groups and the application identifier (com.apple.application-identifier set to MMFLRC7562.io.palmier.pro), ensuring the app can read and write its own secrets. The team identifier (MMFLRC7562) is also explicitly listed, enabling proper Keychain access group validation.

Local MCP Server Security

Loopback Interface Binding

The MCP (Model Context Protocol) server must only be reachable from the same machine to prevent remote code execution. In Sources/PalmierPro/Agent/MCP/MCPHTTPServer.swift at line 73, the server explicitly binds to 127.0.0.1 on a hard-coded port (MCPService.port). All URLs are constructed using this localhost address, as seen in Sources/PalmierPro/Help/MCPInstructionsPane.swift at line 5, ensuring the server accepts connections only from local processes.

This design limits the attack surface to processes already running on the user's Mac, preventing external network exposure.

Network Transport Security

URLSession and TLS

All outbound network communication uses URLSession, Apple's TLS-enabled HTTP client. In Sources/PalmierPro/Generation/GenerationBackend.swift (line 39) and Sources/PalmierPro/Generation/GenerationService.swift (line 196), the app uploads data and downloads model files over HTTPS. URLSession automatically validates server certificates and runs in a sandbox-compatible manner, ensuring encrypted transmission for all AI service interactions.

Code Signing and Distribution Integrity

Developer ID and Entitlements

The application is distributed as a signed DMG under a Developer ID certificate. The scripts/PalmierPro.entitlements file (lines 9-12) lists both the application identifier (MMFLRC7562.io.palmier.pro) and the team identifier (MMFLRC7562), which enables macOS Gatekeeper verification. The appcast.xml file contains signed download URLs that ensure the binary originates from Palmier, Inc. and has not been tampered with during distribution.

Data Residency and Privacy

Palmier Pro's core editing engine operates completely offline. Only the optional generative-AI features communicate with external services, and these are guarded behind user-provided keys that reside exclusively in the Keychain. No background telemetry ships with the application, ensuring video files remain on-device unless the user explicitly invokes cloud-based models.

Practical Code Examples

Saving an API Key to Keychain

import PalmierPro

let apiKey = "sk-abcd1234..."               // obtained from the user
AnthropicKeychain.save(apiKey)            // wrapper uses KeychainStore under the hood

This implementation forwards to KeychainStore.save as defined in Sources/PalmierPro/Agent/Clients/AnthropicClient.swift.

Loading a Stored API Key

if let savedKey = AnthropicKeychain.load() {
    print("Loaded Anthropic key: \(savedKey)")
} else {
    print("No key stored")
}

The AnthropicKeychain.load method delegates to KeychainStore.load with the appropriate service identifier.

Deleting Stored Credentials

AnthropicKeychain.delete()

This triggers KeychainStore.delete to remove the item from the macOS Keychain.

Constructing the Local MCP Server URL

let mcpURL = "http://127.0.0.1:\(MCPService.port)"
print("Connect your agent to:", mcpURL)

As implemented in Sources/PalmierPro/Agent/MCP/MCPHTTPServer.swift, this URL ensures connections remain local to the machine.

Summary

  • Keychain Storage: All API keys are stored in the macOS Keychain via KeychainStore.swift, never written to disk in plain text, and protected by the keychain-access-groups entitlement.
  • Local-Only Networking: The MCP server binds exclusively to 127.0.0.1 (line 73 in MCPHTTPServer.swift), preventing remote access.
  • Encrypted Transport: External API calls use URLSession with TLS encryption (GenerationBackend.swift and GenerationService.swift).
  • Code Integrity: The app is distributed as a signed binary with explicit entitlements declaring the team and application identifiers (MMFLRC7562).

Frequently Asked Questions

How does Palmier Pro store API keys securely?

Palmier Pro uses the KeychainStore wrapper in Sources/PalmierPro/Utilities/KeychainStore.swift to persist API keys in the macOS Keychain using SecItemAdd and SecItemUpdate. The app declares the keychain-access-groups entitlement in scripts/PalmierPro.entitlements, ensuring only the application can access its stored secrets.

Can the MCP server be accessed from other computers on my network?

No. The MCP server in Sources/PalmierPro/Agent/MCP/MCPHTTPServer.swift explicitly binds to 127.0.0.1 (localhost), hard-coded at line 73. This prevents external network hosts from connecting to the server, restricting access to local processes only.

Does Palmier Pro send my video files to cloud servers?

No. The core video editing functionality operates entirely offline. Only the optional generative-AI features transmit data, and only when you provide an API key. These keys remain in the Keychain, and video content is never uploaded without explicit user action.

How does the application prevent tampered binaries from running?

The application is distributed as a Developer ID-signed DMG, with the signature verified through appcast.xml. The scripts/PalmierPro.entitlements file contains the application identifier and team ID (MMFLRC7562), enabling macOS Gatekeeper to validate the binary's integrity before execution.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →