# FaceGate on macOS: an app locker that gates launches behind on-device face recognition

> FaceGate is an MIT-licensed SwiftUI menu bar agent that intercepts app launches on macOS 14 and above and asks for a face, Touch ID or a Keychain-stored PIN. It is a convenience layer against casual physical access, and the README says so itself.

**dweep-desai/FaceGate-Mac** — World's first Face Authentication enabled MacOS App-locker, completely free and open-source. Unlock your Mac apps using Face , TouchID or password. Completely local and encrypted - your data never leaves your Mac

- Repository: https://github.com/dweep-desai/FaceGate-Mac
- Website: https://dweep-desai.github.io/FaceGate-web/
- Stars: 486 · Forks: 27
- Language: Swift
- License: MIT
- Published: 2026-09-17 · Updated: 2026-09-17 · Language: en
- Canonical page: https://hysenlabs.com/projects/dweep-desai-facegate-mac

## The gap FaceGate fills: macOS locks the whole session, not one app

macOS gives you a login password, a screensaver lock and Touch ID for sudo, but no way to say "this one app needs a fresh check before it opens." The README states that gap plainly: "macOS natively lacks the ability to restrict individual applications." If you step away from an unlocked Mac, everything on screen is reachable, including your password manager, your mail client and your terminal history.

The project targets a single user on a single machine. FaceGate is a menu bar agent with no Dock icon, so it stays out of the way until a locked app is launched. The README frames the threat model as "a convenience layer against casual physical access, not a defense against targeted attacks using high-fidelity spoofing." That sentence is the most important one in the repository, and it should shape who installs this. If your concern is a roommate, a coworker at the next desk, or someone who picks up your laptop while you fetch coffee, the design fits. If your concern is a motivated adversary with a good 3D-printed mask, it does not, and the author says as much.

## How FaceGate intercepts launches and where the biometric data lives

The mechanism is application-level, not kernel-level. FaceGate watches for launches of apps you have added to its lock list and blocks access until an authentication method succeeds. The README describes this as intercepting launches "in real-time" and preventing access until authenticated.

Authentication has three paths. Face recognition runs a software face-embedding pipeline on the Apple Neural Engine, entirely on the Mac. Touch ID delegates to macOS. The password path is a PIN whose SHA-256 hash is salted with a random 32-byte value and stored in the macOS Keychain. Face embeddings themselves are AES-256-GCM encrypted and stored locally, with the encryption keys held in the Keychain. The README states the app is fully offline and makes no network requests except a daily Sparkle automatic update check, which is the one outbound call you should know about before installing.

Liveness detection is done with head-pose challenges: the app asks you to turn left, turn right or tilt. That defeats a printed photo or a held-up phone screen. It does not defeat a mask, which is exactly the limitation the 2D FaceTime camera imposes and the README acknowledges.

Several controls sit on top of the auth path. Per-app session timers can count from the last unlock or from when the app loses focus, and can be set to lock immediately or stay unlocked indefinitely. Lock-on-Sleep locks everything when the Mac sleeps or the screen locks. A FaceUnlock Schedule disables face recognition during chosen hours and falls back to Touch ID or password, which is a sensible answer to bad lighting or a public space. Sensitivity is tunable, with a default similarity threshold of 0.65. Up to three faces can be enrolled, covering alternate looks or a second person.

## Installing FaceGate on macOS 14 and locking your first app

The README lists three install routes. The recommended one is a shell script that fetches the latest release, installs to /Applications and strips the Gatekeeper quarantine flag. It runs as a pipe from curl to bash, so read install.sh before you run it if that pattern bothers you.

```bash
curl -fsSL https://raw.githubusercontent.com/dweep-desai/FaceGate-Mac/main/install.sh | bash
```

The manual route exists because FaceGate is not Apple-notarized. Downloading the .dmg and double-clicking will not work until you clear the quarantine attribute yourself.

```bash
xattr -cr /Applications/FaceGate.app
```

Homebrew users get a cask, followed by the same quarantine step.

```bash
brew install --cask dweep-desai/tap/facegate
xattr -cr /Applications/FaceGate.app
```

Requirements are macOS 14.0 (Sonoma) or later, a built-in or external camera for face unlock, and optionally a Touch ID Mac for the fallback. The README notes external USB webcams are supported, which matters on a desktop Mac with no built-in camera.

Building from source uses XcodeGen rather than a checked-in project file.

```bash
git clone https://github.com/dweep-desai/FaceGate-Mac.git
cd FaceGate-Mac
brew install xcodegen
xcodegen generate
open FaceGate.xcodeproj
```

After that, build with Cmd+B or Cmd+R. The README warns you may need to update the signing configuration for your development team. A Makefile in the repository wraps the same steps with targets named generate, build, archive, export, dmg and install, and the release DMG is produced with create-dmg against non-app-assets/dmg_background.png.

Once running, the agent lives in the menu bar. The README says the menu bar popup shows which apps are locked or unlocked and lets you lock them directly. The first real use is to enroll a face, then add one app to the lock list, then quit and relaunch that app to confirm the prompt appears. If you cannot see the camera, the Auto-Optimization feature raises display brightness and triggers Center Stage.

## What FaceGate cannot do, and the cases where it is the wrong tool

The README's own security note is the first limitation: the built-in 2D FaceTime camera has no depth sensing, so liveness detection rests on head-pose challenges, which are weaker than the structured-light or depth sensors on Face ID hardware. A high-fidelity spoof is out of scope by design.

The second limitation is distribution. FaceGate is not Apple-notarized. Every install path ends with xattr -cr /Applications/FaceGate.app, a command that removes the quarantine attribute from the bundle. That is a deliberate trade by the author, and it means the app cannot be installed through normal managed-deployment channels without an exception. On a corporate Mac, that alone may rule it out.

Third, the offline claim has one exception: a daily Sparkle automatic update check. If your environment requires zero egress, that check is a network request you have to account for.

The fourth is scope. This locks applications. It does not encrypt files, it does not sandbox anything, and it does not stop someone who already has your unlocked session from reading data through a path you did not lock. Locking Safari does nothing if the same credentials are reachable from a terminal. Uninstall protection makes the app bundle immutable and requires admin privileges to remove, which raises the effort for a casual user but is not a security boundary against an admin.

Finally, the emergency kill hotkey and the requirement to authenticate before quitting or changing settings are both documented, but the README does not describe what happens to already-unlocked apps when the agent is killed. That is worth testing yourself before you rely on it.

## How FaceGate differs from session-level lockers and screen-time tools

The obvious comparison is macOS's own screen lock and the various third-party lockers that gate the whole session. Those tools answer a different question. They protect everything at once, which is simple and hard to bypass, but it means you cannot hand someone your Mac to check a browser tab without unlocking your mail client too. FaceGate inverts that: per-app granularity, chosen by you, at the cost of being an application-level control rather than a system one.

The README also positions FaceGate against existing Mac app lockers, claiming none of them use face recognition and that FaceGate is more feature-rich. That claim is the author's, and the README does not enumerate which lockers were compared or on what basis, so treat it as positioning rather than a benchmark.

The more interesting difference is the biometric path. A password-only app locker asks for something you know. FaceGate asks for something you are, processed locally on the Neural Engine, with Touch ID and a PIN as fallbacks. That is a genuinely different interaction: you sit down, the camera sees you, the app opens. The cost is that face recognition is the weakest of the three methods on this hardware, which is presumably why the FaceUnlock Schedule exists and why the sensitivity threshold is adjustable.

## Maintenance, upgrade cost and what the MIT licence means here

The repository is not archived, and the last push was on 2026-09-04, so the project is being worked on. Recent releases are v1.2.1 on 2026-08-20, v1.2.0 on 2026-06-28 and v1.1.1 on 2026-06-24. That is a steady cadence through mid-2026, with patch releases between minor ones.

Upgrade cost is low for users and moderate for anyone building from source. Users get updates through the Sparkle check or by reinstalling. Because the app is not notarized, every fresh install needs the quarantine attribute cleared again, and the Homebrew cask README block shows exactly that: the cask install is followed by xattr -cr. Expect that step after each upgrade from a downloaded DMG.

For contributors, the source build depends on XcodeGen reading project.yml. There is no checked-in .xcodeproj, so a contributor needs xcodegen installed and a signing configuration for their team. The Makefile's generate target runs xcodegen generate, and build, archive, export and dmg chain from it. Swift 5.9 or later is required per the README badges.

The licence is MIT, which permits commercial use, modification and redistribution provided the copyright notice and permission notice are preserved. That is a permissive licence, not a copyleft one, so derivative works can be closed. This is a description of the licence text, not legal advice; if you plan to redistribute FaceGate inside a product, have your own counsel read LICENSE.

## Conclusion

Adopt FaceGate if you want a free, local, source-auditable way to put a face check in front of a few apps on a personal Mac running macOS 14 or later, and if you accept that the built-in 2D camera cannot defeat a determined spoof. Skip it if you need notarized distribution, managed deployment across a fleet, or protection against a targeted attacker with your hardware in hand. Before trusting it with anything that matters, read SECURITY.md, confirm which authentication method each locked app falls back to when face recognition is disabled by the FaceUnlock Schedule, and check the release notes for the version you install.

## FAQ

### Can you use Face ID on a MacBook with FaceGate?

FaceGate does not use Apple's Face ID hardware. It runs a software face-embedding pipeline on the Apple Neural Engine using the built-in or an external camera, and the README notes the built-in 2D FaceTime camera lacks depth sensing.

### How do I enable face unlock with FaceGate?

Install FaceGate on macOS 14.0 or later, enroll up to three faces, then add the apps you want to lock. The README states face recognition runs entirely on-device via the Apple Neural Engine, with Touch ID and a Keychain-stored PIN as fallbacks.

### Does macOS have facial recognition without FaceGate?

The README states that macOS natively lacks the ability to restrict individual applications, which is the gap FaceGate addresses. FaceGate adds application-level locking with on-device face recognition on top of the system.

### Does an iMac have Face ID for use with FaceGate?

The README does not claim Face ID hardware on any Mac. FaceGate requires a built-in or external camera for face unlock, and the README notes external USB webcams are supported, which covers desktop Macs without a built-in camera.

## Sources

- [dweep-desai/FaceGate-Mac on GitHub](https://github.com/dweep-desai/FaceGate-Mac)
- [License: MIT](https://github.com/dweep-desai/FaceGate-Mac/blob/main/LICENSE)
- [Project website](https://dweep-desai.github.io/FaceGate-web/)
- [README](https://github.com/dweep-desai/FaceGate-Mac/blob/main/README.md)
- [Releases](https://github.com/dweep-desai/FaceGate-Mac/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/dweep-desai-facegate-mac
