One tap, or just walk away.
Lock on demand from your Apple devices, or automatically when you leave.
brew install --cask PangMo5/tap/amado
One tap when you want it. Automatic when you leave.
One tap, everywhere
The same paired Macs are available across the iPhone app, Home Screen, Control Center, and Apple Watch.
Pair by scanning the QR code on your Mac, then lock any saved Mac with one tap.
Send the lock action from your wrist through the paired iPhone.
Put a Mac on the Home Screen or add Lock Mac directly to Control Center.
No tap required
Bluetooth proximity is a primary Amado experience: the Mac watches for your iPhone to leave and locks without a button press.
Proximity sensing runs on the Mac. The Amado iPhone app does not need to remain open.
Choose the RSSI threshold, grace period, and smoothing that fit your desk and environment.
Use the same iCloud account on Mac and iPhone so macOS can recognize the phone across Bluetooth address rotation.
Local first
Bonjour finds the Mac automatically on your LAN. Off-network, Amado can use an HTTPS tunnel you choose and operate.
No cloud hop, account, or hosted Amado service. A valid command goes straight to the Mac agent.
Use Cloudflare Tunnel, Tailscale Funnel, ngrok, or another HTTPS tunnel with a stable hostname.
The client tries LAN first, then remote. With neither available it reports the failure instead of silently queuing.
A narrow, authenticated capability
QR pairing provisions a 256-bit secret. Every command carries an HMAC, fresh timestamp, and one-time nonce.
The pairing secret is kept out of config.toml and stored in the macOS Keychain.
HMAC-SHA256 authenticates commands. Timestamp and nonce checks reject stale or duplicated requests.
The tunnel-facing HTTP server binds only to 127.0.0.1, not directly to the LAN.
One tap when you want it. Automatic when you leave.
brew install --cask PangMo5/tap/amado