CLI tool
malmeloo/FindMy.py avatar
malmeloo/FindMy.py

FindMy.py: querying Apple's Find My network from Python without a Mac

🍏 + 🎯 + 🐍 = Query Apple's FindMy Network with Python!

3,278 stars150 forksPythonMIT

At a glance

What is it?
FindMy.py is an MIT-licensed Python library that fetches and decrypts Apple Find My location reports for AirTags, iDevices and OpenHaystack tags. It is a library first and a CLI second, and the README is honest that the CLI is still being built out.
Who is it for?
Adopt FindMy.py if you are building Python tooling that needs to fetch and decrypt Find My location reports on Linux, Windows or macOS, and you are comfortable with the anisette dependency. Do not adopt it if you need a finished command line application, since the README says the CLI is still being built out.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 15 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem FindMy.py solves: fragmented Find My code

Apple's Find My network is closed. Location reports are encrypted, the keys live on your devices, and the official path to reading them runs through Apple hardware. Before FindMy.py, anyone wanting to read those reports in Python had to assemble code from several unrelated repositories written by different authors. The README states the situation plainly: the scene is fragmented, and that makes integration hard.

FindMy.py packages that work into one library. The target audience is developers writing Python tools that need device locations: home automation integrations, self-hosted dashboards, research scripts that track OpenHaystack tags. It is not aimed at end users who want a desktop app. The README positions it as a library, with examples in the examples directory, and notes that a CLI exists but is still being built out. That distinction matters when you evaluate it: the API is the product, the CLI is a preview.

How the fetch and decrypt path actually works

The README lists the capabilities in order: sign in to an Apple account, fetch location reports, decrypt them, and optionally scan for nearby FindMy devices over Bluetooth. Those steps map to separate parts of the package.

Apple account sign-in supports two second-factor paths, SMS and trusted device, so you do not need to be sitting in front of a Mac. The README credits Pypush for the breakthrough that made Mac-less operation possible. Anonymous authentication is handled through anisette, which appears as a runtime dependency in pyproject.toml, and the credits name anisette-v3-server as the upstream work. That dependency is the part most likely to surprise you in production: the library calls out to anisette tooling rather than implementing Apple's attestation itself.

Once authenticated, the library fetches encrypted location reports and decrypts them using accessory keys. You can import existing keys or generate new ones for custom tags. The scanner path is separate and uses bleak, the Bluetooth dependency in pyproject.toml, to decode nearby devices and their status bytes. Both async and sync APIs are offered, which the README lists as a feature; aiohttp is the async HTTP dependency, so the async surface is the one built on aiohttp sessions and the sync API is the convenience layer.

Installing FindMy.py and running a first fetch

The package is published on PyPI as findmy. The README gives one install command, and pyproject.toml constrains Python to >=3.10,<3.15, so check your interpreter before you start.

bash
pip install findmy

After installation, the README points to the examples directory rather than walking through a script inline. The first example you should read is examples/_login.py, which covers the account sign-in flow including the second-factor step. The other examples split by task: examples/airtag.py for accessory keys, examples/fetch_reports.py and examples/fetch_reports_async.py for the two API styles, and examples/scanner.py for nearby device scanning.

The README also mentions a preliminary CLI. Running the module directly prints its current state, which is the fastest way to see what is implemented.

bash
python -m findmy

Expect that output to be sparse. The README describes the CLI as something being built out, so treat anything it prints as a work in progress rather than a stable interface. For real work, import the library and follow the examples.

Where FindMy.py is the wrong tool

The README does not document rollback, rate limits, or what happens when Apple changes its authentication endpoints. That silence is the main risk. A library that depends on reverse-engineered Apple protocols inherits the fragility of those protocols, and nothing in the repository description promises stability across Apple-side changes.

The anisette dependency is a second constraint. It is listed as a normal runtime dependency, but it exists because the library needs Apple attestation data it cannot generate alone. If your deployment environment cannot reach or run anisette tooling, the sign-in path is where you will fail, and the README does not offer an alternative.

Finally, this is not a tracking product. It reads reports for accessories whose keys you hold. If you want a supported, Apple-sanctioned way to locate devices, use Apple's own tools. FindMy.py is for people who have already decided to work outside that path.

FindMy.py compared with OpenHaystack and the projects it credits

The README's credits section is effectively a map of the alternatives. OpenHaystack, from seemo-lab, is the research project that showed how to build custom Find My accessories and is cited alongside a paper. FindMy.py supports OpenHaystack tags as a feature, so the relationship is complementary rather than competitive: OpenHaystack covers the tag side and its research, while FindMy.py provides a Python library that also handles official Apple accessories and account sign-in.

The other named projects are closer to building blocks. biemster's FindMy is described as the main basis of this project, so choosing between them is largely choosing between a maintained library and its ancestor. Pypush provided the Mac-less authentication breakthrough, and GrandSlam handles SMS 2FA. If you need a different language, none of these give you Python, which is the specific gap FindMy.py fills. The README also links a page of derivative projects in the documentation for anyone comparing further.

Licence, maintenance and upgrade cost

FindMy.py is MIT licensed, with the licence text in LICENSE.md and declared through license-files in pyproject.toml. MIT is permissive: you can use the library in closed products, but you carry the obligation to include the licence notice, and the authors provide no warranty. The README's credits section names several upstream projects, each with its own licence, so if you redistribute a bundle you should check those separately. None of this is legal advice.

On maintenance, the repository is not archived, and the last push was on 2026-09-15, nine days before this writing. Releases are frequent: v0.10.2 on 2026-09-14, v0.10.1 on 2026-06-01, and v0.10.0 on 2026-05-04. The version sits at 0.x, so minor releases can carry breaking changes, and the release cadence suggests you should pin a version rather than float. The dependency list is short but includes cryptography, aiohttp, bleak and anisette, each with its own upgrade treadmill. Budget for reading release notes before bumping.

Editorial conclusion

Adopt FindMy.py if you are building Python tooling that needs to fetch and decrypt Find My location reports on Linux, Windows or macOS, and you are comfortable with the anisette dependency. Do not adopt it if you need a finished command line application, since the README says the CLI is still being built out. Before committing, check that your Python version falls inside the >=3.10,<3.15 range in pyproject.toml and read examples/_login.py to confirm the 2FA flow matches the account you intend to sign in with.

Frequently asked questions

How do I install FindMy.py?

Install it from PyPI with pip install findmy. The package requires Python >=3.10 and <3.15 according to pyproject.toml. The README points to the examples directory for usage.

Does FindMy.py need a Mac to work?

No. The README lists cross-platform operation with no Mac needed as a feature, and credits Pypush for the breakthrough that made this possible. Account sign-in supports SMS and trusted device second factors.

What can FindMy.py do with AirTags and OpenHaystack tags?

It fetches and decrypts location reports for official accessories such as AirTags and iDevices, and for custom AirTags built with OpenHaystack. It also scans for nearby FindMy devices and decodes their public keys and status bytes.

Does FindMy.py have a command line interface?

The README says a CLI is being built out and suggests running python -m findmy to see its current state. It is not presented as a finished tool, so the library API is the stable surface.

Official sources

  1. License: MIT
  2. malmeloo/FindMy.py on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/malmeloo-findmy-py.svg)](https://hysenlabs.com/projects/malmeloo-findmy-py)