Docs · Security model

What VibeLock blocks — and what it doesn't

This page is written from VibeLock's source code (version 0.1.1), not from marketing copy. If something here and the app ever disagree, the app is wrong — tell us.

The threat model in one paragraph

VibeLock is built for the "I walked away from my unlocked Mac for ten minutes" situation: a colleague, a stranger in a café or a curious kid sits down at your keyboard while Claude Code, Codex or a build is still running. It stops that person from typing, clicking, quitting things or opening other apps, while the apps you chose stay readable on screen. It is a strong deterrent against casual, opportunistic misuse. It is not a replacement for the macOS login screen against a determined attacker with time, tools or remote access. For that, use the real lock screen (⌃⌘Q).

How the lock works

  • Input firewall. On lock, VibeLock installs a session-wide event tap (CGEventTap at the session level, inserted at the head) that sees these event types before any app does: key down, key up, modifier changes (flagsChanged), left/right/other mouse button down and up, left/right mouse drags, and scroll wheel / trackpad scrolling.
  • Hide everything else. Every regular app that is not on your Visible While Locked list is hidden. A sweep re-runs every 2 seconds, and any blocked app that launches, activates or unhides (Dock click, open -a, a notification click) is hidden again immediately.
  • Cover the desktop. An opaque backdrop sits just above the desktop-icon layer, so your wallpaper and desktop files aren't readable. Allowed app windows sit above it.
  • Cover fullscreen Spaces. macOS can't hide a fullscreen window without tearing down its Space, so VibeLock leaves those windows untouched and instead raises a near-opaque shield whenever the visible Space shows a blocked app's window.
  • Keep the display awake. While locked, VibeLock holds a macOS "no display sleep" power assertion. It is released on unlock.
  • Self-healing. macOS silently disables event taps it considers slow. VibeLock re-enables its tap immediately when that happens, and checks again every 2 seconds.

What is blocked while locked

InputWhat happens
Any key press (letters, numbers, F-keys, Esc, arrows…)Swallowed. The first key press raises the unlock shield.
Modifier keys on their own (⌘, ⌥, ⌃, ⇧, Fn/Globe)Swallowed.
System shortcuts such as ⌘Tab, ⌘`, ⌘H, ⌘W, ⌃←/→ (Spaces), ⌃↑ (Mission Control)Swallowed along with all other key presses, before macOS or any app acts on them.
⌘Space and ⌘⌥Space (Spotlight / Finder search — can preview files)Always blocked, even while the unlock shield is open.
⌘⌥Esc (Force Quit window — could be used to kill VibeLock)Always blocked, even while the unlock shield is open.
⌘Q (quit the frontmost app)Always blocked, even for apps you marked accessible, so nobody quits your running agents.
Quitting VibeLock itselfRefused while locked (the menu only offers "Unlock…").
Clicks — left, right and other mouse buttonsSwallowed. The first click raises the unlock shield.
Drags and scrolling (mouse wheel and two-finger trackpad scroll)Swallowed.
Hidden apps trying to come backRe-hidden immediately.

While the unlock shield is open

The shield is a full-screen, 98%-opaque window on every display, so what's behind it can't be read. Keys and clicks are let through to the shield so you can type your password — except ⌘Tab, ⌘` and ⌃←/→/↑ (Spaces and Mission Control), which stay blocked so focus can't be moved away from the shield, plus the always-blocked ⌘Space, ⌘⌥Esc and ⌘Q. Pressing Esc dismisses the shield and returns to the watch-only view (unless a blocked app's fullscreen window is on that Space, in which case the shield stays).

If you use the "Accessible While Locked" tier

This list is empty by default. If you add apps to it, key presses reach an accessible app when it is frontmost, clicks and scrolls reach windows owned by accessible apps, and ⌘Tab / ⌘` are allowed so you can switch between them. Clicks on everything else are swallowed silently; a click on the menu bar or any key press in a non-accessible app brings up the unlock shield. Be careful: an accessible terminal gives anyone at your keyboard a shell.

What is not blocked — honest limits

Some of these are hard limits of what any app can do on macOS; some are simply event types VibeLock doesn't intercept. Items marked "likely" depend on your Mac model and macOS version.

  • The screen itself. By design, anyone can read what your visible apps show — including secrets printed in your terminal. Only allow apps whose contents you're happy for a passer-by to read.
  • Notification banners. They are drawn by macOS, not by the hidden apps, so previews can still appear on screen. Turn on a Focus / Do Not Disturb mode if that matters.
  • Pointer movement. The cursor still moves; clicks don't do anything.
  • Media, volume and brightness keys (likely). These arrive as system-defined events, which VibeLock's tap does not subscribe to, so expect them to keep working. The same goes for Touch Bar Control Strip buttons.
  • Trackpad gestures that switch Spaces (three- or four-finger swipes, Mission Control swipe up). An event tap can't block these. VibeLock's mitigation: if the swipe lands on a Space showing a blocked app, the opaque shield covers it; swiping back to a clean Space drops the shield again. Pinch/rotate gestures are also not intercepted.
  • The power button and the Touch ID button. A short press can sleep or lock the Mac (macOS handles it); a long press forces a shutdown. Both end up at the real macOS login screen, so your data stays behind your password — but a forced shutdown ends your running session.
  • Closing the lid. VibeLock keeps the display awake but does not override lid-close sleep.
  • Remote access. Anyone who can SSH or otherwise remotely control your Mac can simply end the VibeLock process. (That's also the documented emergency escape: from another device, ssh you@your-mac killall VibeLock releases the input block instantly.)
  • Other software on your Mac. Apps you already trusted with Accessibility or automation permissions run with your privileges; VibeLock doesn't police them.
  • Voice control. Siri voice activation and Voice Control don't go through the keyboard, so an input tap can't stop them. (A blocked app they open is re-hidden.)
  • System UI that isn't an app. Menu bar extras, Control Center and Notification Center aren't hidden — clicks on them are blocked like any other click.
  • During a Touch ID prompt the shield is lowered to a normal floating level for up to 45 seconds, so the system Touch ID dialog can never get stuck underneath it. While that prompt is up, the Dock and menu bar may be reachable; a blocked app opened from the Dock is hidden again by the same rules as above.
  • Displays connected after you lock may not get the desktop backdrop until the next lock.
  • Physical attacks in general — someone who can take the Mac, boot it into recovery or attach hardware is outside what any lock app can address. FileVault and your login password are what protect you there.

How unlock works

  1. Press any key or click (or choose Unlock… from the menu bar icon). The shield appears.
  2. Touch ID first, if your Mac has it: VibeLock asks macOS for a biometrics-only check (LocalAuthentication). VibeLock never sees your fingerprint — macOS only tells it "yes" or "no". A 45-second watchdog resets the prompt if it ever hangs.
  3. Password fallback: cancel or fail Touch ID and a password field appears in the shield. Type your normal Mac login password; it is checked locally against your macOS user account through OpenDirectory. It is never stored, logged or sent anywhere.
  4. Rate limit: after every 5 wrong passwords the field locks for 30 seconds.

On unlock, the event tap is removed, the shield and backdrop disappear, the display-sleep assertion is released and every app VibeLock hid is unhidden.

Permissions

VibeLock needs exactly one permission: Accessibility (System Settings → Privacy & Security → Accessibility). macOS requires it for any app that blocks keyboard and mouse events. VibeLock asks for it the first time you lock. It does not request Input Monitoring, Screen Recording, Full Disk Access, contacts, location or network permissions. On first run it also turns on Open at Login — you can switch that off in the menu.

What data it stores and sends

  • Sends: nothing. The app contains no networking code — no analytics, no license check, no update ping.
  • Stores in its macOS preferences: the bundle IDs of your Visible and Accessible apps, and whether the Open at Login choice has been made.
  • Logs to ~/Library/Logs/VibeLock.log on your Mac: lock/unlock times, which apps were hidden, and whether an unlock attempt succeeded or failed — never the password itself. Delete the file whenever you like.

The website is a separate matter — see the privacy policy.

When to use the real lock screen instead

If you're leaving the Mac for hours, in a place you don't trust, or the screen shows anything sensitive, press ⌃⌘Q. Your agents keep running behind the macOS lock screen too — see how to keep a Mac awake while it's locked. VibeLock is for the times you want to keep watching.