Skip to content

Repository files navigation

Stillhands: lock your keyboard, trackpad and mouse. Your screen stays on.

A tiny, open-source keyboard lock and mouse lock for macOS.

MIT license macOS 13+ CI

Stillhands menu, light mode Stillhands menu, dark mode

Why

Sometimes you want your Mac to keep showing something while nobody can touch it:

  • a toddler watching a video, or a video call with the grandparents
  • the cat walking across the keyboard
  • wiping the keyboard and trackpad clean (turn on Black out screens so smudges show up)
  • a presentation, recipe or dashboard that has to stay put
  • an AI coding agent working while you grab a drink, with its progress on screen for everyone to see

Stillhands is a keyboard lock, mouse lock and trackpad lock in one. Press your shortcut and input stops. The screen stays awake and visible. Press the same shortcut again and everything works again.

Screen Locks Unlock
Stillhands Stays on and visible (black-out optional) Keyboard, clicks & scrolling, pointer: pick any Your own shortcut
Keyboard Lock (App Store) Blacked out Keyboard, mouse, trackpad Fixed ⌘⇧⎋
KeyboardCleanTool Darkened Keyboard, optionally trackpad & mouse Hold a mouse button

deadkeys and KeyClean are good too, but they only lock the keyboard.

Leave your AI agents working in plain sight

Running Claude Code, Codex, Cursor, Aider or another AI coding agent? Lock your Mac and go get a coffee. The screen stays on and the Mac stays awake, so your agents keep working and their progress stays visible. Anyone walking past sees what you're working on and that the work is moving along (not that you're slacking off). Nobody can type into your terminal, approve a prompt or close a window while you're away.

For longer breaks, set Auto-unlock after to 60 min or Off in the ✋ menu, and leave Black out screens off so the agents' output stays readable.

Install

With Homebrew:

brew install --cask fukislim/tap/stillhands

Then open Stillhands and grant Accessibility access when asked (System Settings › Privacy & Security › Accessibility). Stillhands needs it to block input.

Or manually:

  1. Download Stillhands-x.y.z.zip from Releases, unzip it, and move Stillhands.app to /Applications.
  2. Open it. The build is ad-hoc signed, not notarized, so macOS blocks the first launch:
    • macOS 15 and later: open System Settings › Privacy & Security, scroll down and click Open Anyway.
    • macOS 13–14: right-click the app, choose Open, then confirm.
    • Or in Terminal: xattr -dr com.apple.quarantine /Applications/Stillhands.app
  3. Grant Accessibility access when asked (System Settings › Privacy & Security › Accessibility). Stillhands needs it to block input.

A ✋ appears in your menu bar. It changes while locked (a crossed-out hand, by default), and is dimmed until Accessibility access is granted.

Use

  • Lock: press your shortcut, or click ✋ (one or two fingers) › Lock Now.
  • Unlock: press the same shortcut again. With Require Touch ID on, a Touch ID prompt follows: touch the sensor to unlock.
  • Quick options: the ✋ menu toggles what gets locked, black-out and the auto-unlock timer with one click.
  • Menu bar icon: pick a style right in the ✋ menu, from a basic row (hand, spread hand, padlock, eye) and a funky row (alien, genie lamp, cat, Eye of Horus). Each option previews its unlocked and locked look side by side.
  • Settings… (⌘,) opens the full window: record or randomize the shortcut, open at login.
  • Forgot it? The safety timer unlocks on its own (30 minutes by default).
  • Who touched it? With Photo when touched on, the webcam takes a photo when someone types, clicks or moves the pointer while locked. When you unlock, the banner says how often it was touched, and the ✋ menu offers Show Photos of Last Lock….

On first launch Stillhands picks a random shortcut such as ⌃⌥⇧J. It's shown next to Lock Now in the menu. Remember it: it is never shown on screen while locked, and the menu hides it while locked too.

Input locked banner

Settings window, light mode Settings window, dark mode

Settings

These are all the settings there are. The shortcut and Open at login live in Settings…; everything else is in the ✋ menu (and most of it in Settings too).

Setting Default What it does
Keyboard On Blocks every key, including media, volume and brightness keys. Your shortcut still works.
Clicks & scrolling On Blocks mouse buttons, taps, scrolling and trackpad gestures.
Pointer movement On Freezes the cursor where it is.
Black out screens Off Also covers every display with black while locked.
Photo when touched Off Takes a webcam photo when someone touches the Mac while locked: on the first touch, then at most every 30 s, up to 20 per lock. Saved to ~/Pictures/Stillhands/<day>/<time>.jpg and deleted after 3 months.
Shortcut Random Record your own (at least two modifier keys) or roll a new one with 🎲.
Require Touch ID Off After the shortcut, unlocking also needs your fingerprint. Without a usable sensor (lid closed, keyboard without Touch ID) the shortcut alone unlocks.
Auto-unlock after 30 min Safety net: unlocks by itself, also without Touch ID. Off / 5 / 15 / 30 / 60 min.
Menu bar icon Hand Basic: Hand, Spread Hand, Padlock, Eye. Funky: Alien, Genie Lamp, Cat, Eye of Horus.
Open at login Off Starts Stillhands when you log in.

Security & privacy

  • Random shortcut. You get a three-modifier combo such as ⌃⌥⇧J, which is hard to hit by accident (or by a curious kid). Combos that macOS already uses (screenshots, lock screen, Spotlight, Force Quit, …) are refused.
  • Never shown while locked. The "Input locked" banner doesn't reveal how to unlock.
  • No surprises with passwords. Stillhands refuses to lock while a password field is focused (see below).
  • Touch ID, if you want it. With Require Touch ID on, knowing the shortcut is not enough. The fingerprint check is done by macOS; Stillhands only hears yes or no. Quit is disabled while locked. Keep both Keyboard and Clicks & scrolling locked, though: with either one free, someone can still force-quit Stillhands, and input comes back.
  • Photos stay local. Photos are plain JPEGs in ~/Pictures/Stillhands, removed after 3 months. The camera light is on while a photo is taken.
  • Nothing leaves your Mac. No network access, no analytics. Accessibility access is used only to block input, Camera access only for Photo when touched.

Known limits

  • Password fields. While a password field has focus, macOS turns on Secure Input and hides keystrokes from all apps, including Stillhands. Stillhands therefore won't lock at that moment, because it couldn't see your unlock shortcut.
  • Touch ID prompt. With Black out screens on, the black-out lifts while the prompt is shown, so you can see it. While clicks and keys are locked, the prompt's Cancel button can't be used either; it closes by itself after 30 seconds and Stillhands stays locked. After too many failed fingers macOS locks Touch ID until you enter your password, so Stillhands stays locked until the safety timer.
  • Hardware buttons. The power / Touch ID button and a forced restart can't be blocked. That's also your last-resort escape.
  • Key labels use the US layout. On other layouts the shortcut is the same physical keys, but the label may show a different character.
  • Release builds are ad-hoc signed (no paid Apple Developer ID). Updating to a new release (also via brew upgrade) therefore asks for Accessibility again: remove Stillhands from the Accessibility list with − and add it again. Until you do, the ✋ in the menu bar is dimmed. With Photo when touched on, macOS asks for Camera access again too.
  • Fails open. If Stillhands quits or crashes while locked, input comes straight back.

Build from source

You need Swift 6 (Xcode or just the Command Line Tools). Releases are built on GitHub's macOS 15 runners with a macOS 13 deployment target, so the app runs on macOS 13 Ventura and later.

make signing
make check
make run
make docs
make icon
Command Does
make signing Once per machine: a local signing certificate in its own keychain file, so macOS keeps Accessibility access across rebuilds. Its random password goes into the git-ignored .env (see .env.example).
make check Build with warnings as errors, then the unit tests.
make test Unit tests only.
make run Builds dist/Stillhands.app (universal) and opens it.
make docs Re-renders the screenshots in docs/images.
make icon Re-draws the app icon, assets/logo.png and the README banners from assets/palm-down-hand.svg.
make clean Removes .build and dist.

make on its own lists all targets.

Sources/StillhandsCore   pure logic: shortcuts, reserved combos, the event policy (unit-tested)
Sources/Stillhands       the app: event tap, menu bar, settings window, HUD, black-out, docs renderer
scripts/                 build, signing, icon, screenshot and Homebrew cask scripts

How it works: a single CGEventTap sees every input event. The pure EventPolicy decides whether to pass it, block it or toggle the lock. While locked, a display-sleep assertion keeps the screen awake.

Releasing

Pushing to the prod branch publishes a release. GitHub Actions tests and builds the app, then creates the GitHub Release v<version> with the zip attached. The version comes from CFBundleShortVersionString in Resources/Info.plist; if that version is already released, the run is skipped. So to ship: bump the version (and CHANGELOG.md) on main, then git push origin main:prod.

The same run updates the Homebrew cask in fukislim/homebrew-tap (generated by scripts/make-cask.sh). It pushes with an SSH deploy key that can write only to the tap: the public key is a deploy key on fukislim/homebrew-tap, and the private key is the secret HOMEBREW_TAP_DEPLOY_KEY in this repository. Without the secret the tap step is skipped.

Contributing

Issues and pull requests are welcome. Stillhands is deliberately small: new settings need a very good reason. Run make check before opening a PR.

License

MIT. The hand in the logo is the "palm down hand" from Twemoji (© Twitter, Inc. and other contributors), licensed under CC BY 4.0 and recoloured.

About

Keyboard, mouse and trackpad lock for macOS. Lock input with one shortcut while your screen stays on, so your AI agents keep working in plain sight while you step away.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages