Glossary/Processes you will see
secd
Also: keychain and passwords
Quick answer
secd is the macOS process that manages the keychain items in your user account: the passwords, passkeys, keys and certificates kept in iCloud Keychain or Local Items. Every app that saves or fills in a password asks secd for it, and secd keeps those items in sync with your other devices when iCloud Keychain is on.
secd runs under your own account, which is why Activity Monitor shows your name in its User column. It works next to securityd, an older process that runs as root. securityd looks after the file-based keychains, login and System, that the Mac has used since its early versions. secd looks after the newer keychain that iCloud Keychain, passkeys and items protected by Touch ID depend on. The Passwords app shows your saved passwords and passkeys, and Keychain Access lists both kinds of keychain.
Most of the time secd is idle. It gets busy when there is real work: the first sync on a new Mac or after you turn on iCloud Keychain, a change to your Apple Account password while your devices reconnect, a large import of passwords, or an app that asks for the same item again and again. The last one is the usual reason it stays near the top of the CPU list.
Why secd is using so much CPU
Sync is the common reason. When a Mac joins iCloud Keychain, secd downloads, decrypts and merges every item your other devices hold, and it does the same work again whenever many items change at once. A keychain with thousands of passwords, keys and certificates takes longer, and the work can come back in waves while your devices catch up with each other.
A spike that never ends usually means a loop. An app asks secd for an item, gets an error or a refusal, and asks again, many times a second. Password managers, browsers, VPN clients and developer tools that store sign-in tokens are the usual suspects, often right after the app was updated.
What to do about it
After a new Mac, a new sign-in or a password change, leave the Mac awake and let the sync finish. It ends on its own. For a loop, quit apps one at a time, starting with the ones that store passwords or tokens, and watch secd in Activity Monitor. If it drops when one app quits, update that app, or sign out of it and back in.
If you cannot find the app, open System Settings → [your name] → iCloud → Passwords, turn off Sync this Mac, restart, and turn it on again. Your passwords stay in iCloud and on your other devices. Quitting secd in Activity Monitor only helps for a moment: macOS starts it again straight away.
How to see what secd is doing
A sync that is working gets quieter. A loop looks the same every few minutes. Activity Monitor and Terminal can show you which one you have.
- Open Activity Monitor, click the CPU tab, choose View → All Processes, and type
secin the search field. You will see secd under your own name and securityd under root. - Watch secd's % CPU for a few minutes. A figure that falls toward zero is a sync finishing. One that stays up, or rises and falls on a steady rhythm, is a loop.
- Click the Network tab and type
clouddin the search field. cloudd carries iCloud's sync traffic. If secd is busy while cloudd is sending and receiving, the keychain is probably syncing. If secd is busy and cloudd is quiet, look for an app on your Mac instead. - For the detail, open Terminal and run
log stream --predicate 'process == "secd"'. Lines that repeat with the same app or item in them point at the app to look at. Press Control-C to stop.
Normal secd use vs a problem
Normal: secd sits near zero and wakes for a moment when an app saves or fills in a password. It works for longer on a new Mac, after you turn on iCloud Keychain, and after you change your Apple Account password.
Worth looking into: it stays busy for hours while you are doing nothing, the fans come on, or apps are slow to fill in passwords. These are the usual causes:
- The first iCloud Keychain sync on a new or restored Mac, which can take a while with a large keychain.
- A large import, such as passwords brought into the Passwords app from another password manager or a browser.
- An app that asks for the same keychain item in a loop, often a password manager, browser, VPN client or developer tool after an update.
- Years of old items, such as certificates and keys from apps you no longer use, that make every search and sync longer.
Where the keychain lives
Both kinds of keychain are in your user Library, in ~/Library/Keychains. The login keychain is the file login.keychain-db, and the keychain secd manages is in a folder there with a long ID as its name.
Do not delete or move these files to fix a CPU problem. Items that exist only on this Mac, such as passwords saved by apps that do not sync them, would be lost. To find and remove old items, use Keychain Access, which you can open by searching for it in Spotlight, and the Passwords app.
Questions people ask
What is secd on Mac?
The macOS process that manages keychain items in your user account, such as passwords and passkeys, and syncs them with iCloud Keychain. Every app that saves or fills in a password goes through it.
Why is secd using high CPU?
Briefly, because iCloud Keychain is syncing after a new Mac, a new sign-in or a password change. For hours, because an app keeps asking it for the same item. Quitting apps that store passwords or tokens one at a time shows which one it is.
What is the difference between secd and securityd?
Both are part of macOS's keychain. securityd runs as root and handles the older file-based keychains, login and System. secd runs as you and handles the keychain that iCloud Keychain and passkeys use.
Is secd a virus?
No. It is part of macOS, lives at /usr/libexec/secd on the sealed part of the disk that only Apple's updates can change, and is started by launchd under your own account. Every Mac runs it.
Why does my Mac keep asking for my keychain password?
Usually because the login keychain's password no longer matches your Mac login password, often after the login password was reset. That keychain belongs to securityd, not secd. Apple's fix, Reset Default Keychains in Keychain Access → Settings, deletes the passwords saved in the login keychain, so Apple recommends it only when Apple Support advises it.
Related
Looking for something better than Activity Monitor? See the best Activity Monitor alternatives for Mac, or browse every term in the glossary.