Amado app icon

Amado

One tap. Walk away. Close the lid.
Lock on demand, lock on departure, or keep your MacBook running closed.

brew install --cask PangMo5/tap/amado

Version 2.0.3 · macOS 15, iOS 18, watchOS 11 · Free & open source

⌚️WatchOne tap
relay
📱iPhoneAuthenticates
LAN · HTTPS
💻MacLocked

One tap when you want it. Automatic when you leave.

One tap, everywhere

Lock the moment you ask.

The same paired Macs are available across the iPhone app, Home Screen, Control Center, and Apple Watch. Stable device IDs keep every pairing linked independently of its displayed name.

📱

iPhone app

See whether each Mac is locked or unlocked, pull to refresh, and lock any saved Mac with one tap.

⌚️

Apple Watch

Send the action from your wrist and see whether the Mac was already locked or became locked.

Widget and Control

Control Center reports progress and the result; the Home Screen widget can also refresh the Mac's current status.

No tap required

Walk away. Your Mac closes up.

Smart Bluetooth detection learns a conservative nearby signal, follows departure trends, and locks without a button press.

🚶

No phone app needed

Proximity sensing runs on the Mac. The Amado iPhone app does not need to remain open.

📶

Smart, or fully manual

Choose Conservative, Balanced, or Fast and let Amado filter spikes and sudden signal loss, or switch to Manual for direct control over the RSSI threshold, confirmation delay, and smoothing window.

⏸️

Pause on your schedule

Pause from the menu bar for 15 minutes to four hours, or choose an exact resume time in Settings. Monitoring resumes automatically.

Caffeinate

Close the lid. Keep the Mac running.

Continue downloads, servers, remote sessions, and long-running work with the built-in display closed. You choose the login-session policy explicitly.

🔒

Stay awake and lock

The recommended awake policy locks on the physical lid-close transition and sleeps every display while the Mac itself keeps running.

🔓

Keep explicitly unlocked

After one context-sensitive confirmation, leave the login session unlocked in a controlled environment and choose whether Auto-lock stays on. Anyone with physical access or access through already-enabled remote-control software may be able to use the session and its data.

☕️

Narrow, fail-safe helper

Install the code-signing-pinned Power Helper explicitly, then approve it as an administrator. Awake policies unlock only when the current helper is ready; if Amado disconnects, normal sleep is restored automatically.

A closed Mac can consume battery and trap heat. Use a hard, stable, well-ventilated surface—never a bag, bedding, or another enclosed space. The unlocked policy deliberately reduces physical and remote-session security. Read the Caffeinate and safety guide ›

Local first

Fast nearby. Reachable away.

Bonjour finds the Mac automatically on your LAN. Off-network, Amado can use an HTTPS tunnel you choose and operate.

⚡️

Direct on LAN

No cloud hop, account, or hosted Amado service. A valid command goes straight to the Mac agent.

🌐

Bring your own tunnel

Use Cloudflare Tunnel, Tailscale Funnel, ngrok, or another HTTPS tunnel with a stable hostname.

↩️

Clear fallback

The client tries LAN first, then remote. With neither available it reports the failure instead of silently queuing.

A narrow, authenticated capability

It can lock. It cannot unlock.

QR pairing provisions a 256-bit secret. Every command and response is signed, fresh, and bound to the original request.

🔑

Keychain on Mac

The pairing secret is kept out of config.toml and stored in the macOS Keychain.

🛡️

Replay resistant

HMAC-SHA256 authenticates both directions. Timestamp and nonce checks reject stale, duplicated, or mismatched messages.

🏠

Loopback remote listener

The tunnel-facing HTTP server binds only to 127.0.0.1, not directly to the LAN.

Get Amado.

One tap. Walk away. Close the lid.

brew install --cask PangMo5/tap/amado