Glossary/macOS Keychain & security

Secure Enclave

The Secure Enclave is a dedicated, isolated coprocessor built into Apple silicon and recent Intel Macs with a T2 chip, used to handle the most sensitive cryptographic operations, such as Touch ID matching, independently of the main processor and operating system.

Why it matters

Because it runs its own separate, minimal operating system, data the Secure Enclave protects generally cannot be extracted even if the main macOS system is compromised, which is a stronger guarantee than software-only encryption.

Does every Mac have a Secure Enclave?

Every Apple silicon Mac does, and most Intel Macs with a T2 chip, but older Intel Macs without one do not.

Does the Secure Enclave protect my API keys specifically?

Indirectly, yes, since the Keychain that stores them relies on protections the Secure Enclave provides.

Related

Looking for a different way to manage your keys? See the best Claude Code API key manager alternatives, or browse every term in the glossary.