# OpenHaystack: building Find My tags without Apple hardware

> OpenHaystack is a macOS app and firmware pair that turns a BBC micro:bit or another BLE board into a tag tracked by Apple's Find My network. It is experimental, Mac-only, and its default firmware broadcasts a fixed key.

**seemoo-lab/openhaystack** — Build your own 'AirTags' 🏷 today! Framework for tracking personal Bluetooth devices via Apple's massive Find My network.

- Repository: https://github.com/seemoo-lab/openhaystack
- Website: https://owlink.org
- Stars: 13,714 · Forks: 691
- Language: Swift
- License: AGPL-3.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/seemoo-lab-openhaystack

## What OpenHaystack solves, and for whom

Apple's Find My network locates AirTags and certified accessories through nearby iPhones, which upload encrypted location reports to Apple's servers. That pipeline is closed: you cannot enroll an arbitrary Bluetooth board into it. OpenHaystack is the result of reverse-engineering work at the Secure Mobile Networking Lab at TU Darmstadt, which disclosed a specification of the closed parts of offline finding and published a security and privacy analysis. The project packages that knowledge into two pieces: a macOS application that creates key pairs and displays reported locations, and firmware that makes a Bluetooth device broadcast beacons iPhones will accept.

The audience is narrow and technical. You need a Mac, a Bluetooth-capable board such as a BBC micro:bit, and tolerance for experimental software. The README states plainly that the code is untested and incomplete. This is a tool for people who want to understand or demonstrate offline finding, or who want a self-built tag on a specific piece of hardware, not a consumer tracking product.

## The key pair, the beacon, and the report

The mechanism has three stages, and the README names them pairing, losing, and finding. Pairing generates a public-private key pair on the elliptic curve P-224. The private key stays on the Mac, stored in the keychain. The public key is what gets deployed to the accessory.

In the losing stage, the accessory broadcasts that public key as a Bluetooth Low Energy advertisement. The firmware directory holds the images that do this. According to the README, nearby iPhones cannot distinguish these accessories from a genuine Apple device or a certified accessory, which is exactly why the reports come back.

In the finding stage, a nearby iPhone picks up the advertisement and uploads an encrypted location report to Apple's servers. The Mac app downloads those reports through a private API and decrypts them with the private key from the keychain. The app then shows the last reported location of each accessory on a map. The README notes it can take up to 30 minutes before the first report appears, and that clicking an item shows when the last update arrived. The reload button refreshes the reports.

## Installing OpenHaystack and deploying a first tag

The install is unusual because the app depends on a custom Apple Mail plugin. That plugin inherits Apple Mail's entitlements, which is how the app reaches the private API that downloads location reports. The README says the plugin does not access other private data such as emails.

Start by downloading a precompiled binary from the GitHub releases page, or build the app from source in Xcode. Opening the app prompts you to install the Mail plugin into ~/Library/Mail/Bundle.

```bash
sudo spctl --master-disable
```

That command disables Gatekeeper so the plugin can run. Open Apple Mail, go to Preferences, then General, then Manage Plug-Ins, and tick the box next to OpenHaystackMail.mailbundle. If the Manage Plug-Ins button is missing, the README gives this fallback.

```bash
sudo defaults write "/Library/Preferences/com.apple.mail" EnableBundles 1
```

Allow access, restart Mail, then turn Gatekeeper back on.

```bash
sudo spctl --master-enable
```

With the plugin active, create an accessory in the app by entering a name and optionally picking an icon and color. The app generates the key pair and stores the private key in the keychain. Connect a supported device over USB and press Deploy next to the accessory, choosing the matching target. Alternatively, right-click the accessory to copy the advertising public key and flash it yourself. Expect up to 30 minutes before the first location report shows on the map.

## The fixed public key is the real limitation

The disclaimer is the most important paragraph in the repository. Accessories running the project's firmware broadcast a fixed public key, so they are trackable by other devices in proximity. A genuine AirTag rotates its advertised key; an OpenHaystack tag does not, at least not in this release. The README says this might change in a future release, which is a statement about intent rather than a shipped feature.

That single design choice rules out several uses. Do not attach one of these to anything you would not want a stranger to correlate over time. Do not treat it as equivalent to an AirTag for theft recovery or for tracking a person without their knowledge. The project is also Mac-only: the app requires macOS 11 (Big Sur), and the Mail plugin trick is specific to Apple's desktop mail client. There is an openhaystack-mobile directory in the repository, but the README does not document a shipped Android or iOS workflow, so anyone expecting a phone-based setup should treat that as unverified. Finally, the code is described as untested and incomplete, and the project is not affiliated with or endorsed by Apple.

## OpenHaystack against rolling your own BLE tracker

The obvious alternative is a plain BLE beacon plus your own scanning infrastructure. That approach gives you full control: you choose the advertising interval, you can rotate addresses, and you are not depending on an undocumented Apple API or a Mail plugin that Gatekeeper is designed to block. The cost is coverage. Your tags are only found where your own scanners or volunteer receivers exist.

OpenHaystack trades that control for reach. It borrows Apple's network of iPhones, so a tag can be located anywhere a passing iPhone has connectivity, without cellular coverage on the tag itself. The price is the fixed key, the Mac dependency, and the risk that Apple changes the private API the Mail plugin relies on. If your requirement is a predictable, auditable beacon you operate yourself, OpenHaystack is the wrong tool. If your requirement is worldwide findability from a board you flashed yourself, it is close to the only open option.

## Maintenance, licence, and what a fork inherits

The last push to the repository was on 2026-08-17, so the project is not dormant. The most recent tagged release listed is v0.5.3 from 2023-10-09, which means the release cadence and the commit cadence are not the same thing. Anyone pinning to a release should check whether the tagged build runs on their macOS version before assuming the current main branch behaves the same way.

The repository carries a Makefile with three targets: install-hooks, app-autoformat, and a default that does nothing. install-hooks copies .pre-commit into .git/hooks/pre-commit. app-autoformat runs swift-format and clang-format over the OpenHaystack directory. There is no build or test target in the Makefile, so Xcode is the build path.

The licence is AGPL-3.0. That matters if you plan to modify the app or firmware and distribute it, or run a modified version as a network service. The AGPL's network clause is broader than the GPL's, and the repository's own history includes a CVE directory for CVE-2020-9986, the vulnerability in Apple's implementation that the lab disclosed. Consult your own counsel before shipping anything derived from this code; nothing here is legal advice.

## Conclusion

Adopt OpenHaystack if you have a Mac running macOS 11 or later, a supported BLE board, and you accept that the shipped firmware advertises a static public key, so anyone nearby with the right tooling can follow the tag. Skip it if you need Windows, Linux, Android, or a device that rotates its address, and skip it for anything safety-critical. Before you start, verify that your board appears in the firmware directory, that you can disable and re-enable Gatekeeper with sudo spctl, and that you are willing to build from source if the v0.5.3 release from 2023-10-09 does not run on your macOS version.

## FAQ

### What is OpenHaystack?

OpenHaystack is a framework for tracking personal Bluetooth devices through Apple's Find My network. It consists of a macOS application that generates key pairs and displays locations, plus firmware that makes a Bluetooth device broadcast beacons iPhones can pick up.

### How does OpenHaystack work without internet on the tag?

The tag itself only broadcasts a BLE advertisement containing its public key. A nearby iPhone receives it and uploads an encrypted location report to Apple's servers when that phone has connectivity, and the Mac app later downloads and decrypts those reports.

### Does OpenHaystack have anti-stalking protections like an AirTag?

No. The README states that accessories using the project's firmware broadcast a fixed public key and are therefore trackable by other devices in proximity, and it notes this might change in a future release.

### How long can an OpenHaystack tag be tracked?

The README does not give a tracking duration. It only notes that it can take up to 30 minutes before the first location report appears in the app, and that clicking an item shows when the last update was received.

## Sources

- [License: AGPL-3.0](https://github.com/seemoo-lab/openhaystack/blob/main/LICENSE)
- [Project website](https://owlink.org)
- [README](https://github.com/seemoo-lab/openhaystack/blob/main/README.md)
- [Releases](https://github.com/seemoo-lab/openhaystack/releases)
- [seemoo-lab/openhaystack on GitHub](https://github.com/seemoo-lab/openhaystack)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/seemoo-lab-openhaystack
