Fix “CryptoKit error 3” at startup
This error means Debrify found a device key, but that key cannot open the encrypted data saved beside it. Reset the key and data together — or start with a fresh LiveContainer container without deleting the old one.
What the error means
CryptoKit error 3 is an authentication failure. Debrify encrypts account credentials with a key kept by the device. The error appears when the saved key and encrypted app data no longer belong together.
This can happen after LiveContainer is reinstalled or signed with a new developer certificate, or after only one half of Debrify's macOS data is cleared. Reinstalling or downgrading Debrify by itself may not help because Keychain data can survive the app.
iPhone or iPad using LiveContainer
Safest: make a fresh container
This leaves the old container untouched, so try it before deleting anything.
- Force-close LiveContainer.
- Reopen LiveContainer, but do not launch Debrify.
- Long-press Debrify and open Settings.
- Under Container, tap New Data Folder.
- Name it Debrify Fresh.
- Open the new container and tap Set as Default Container.
- Launch Debrify with the new container and set it up again.
LiveContainer gives its containers separate Keychain access. A new container therefore starts with a matching empty data store and device key. Your old container remains available in case you need it later.
If you must reuse the current container
- Force-close LiveContainer, reopen it, then long-press Debrify and open Settings.
- Under Container, open the container Debrify currently uses.
- Tap Delete Data and confirm.
- On that same screen, tap Clean Up Keychain and confirm.
- Launch Debrify and set it up again.
If a fresh container also fails
Open LiveContainer › Settings › JIT-Less Mode Diagnose › Entitlement File. The Keychain access-groups check should pass. If it does not, reinstall or re-sign LiveContainer with the required entitlements, import its current certificate again, and then create another fresh Debrify container. LiveContainer documents its per-container Keychain separation on its official project page.
macOS
These steps perform a complete Debrify reset. If the current setup matters, move the container aside as a backup before deleting the Keychain item.
1. Move the app data aside
- Quit Debrify completely with ⌘ Q.
- In Finder, choose Go › Go to Folder…, or press ⇧ ⌘ G.
- Enter
~/Library/Containers/com.example.torrentSearchApp. - Move that folder to the Desktop and name it something like Debrify old data.
2. Remove the matching Keychain item
- Press ⌘ Space, search for Keychain Access, and open it.
- In the sidebar, select the login keychain, then All Items or Passwords.
- Search for
com.debrify.app.profile-device-secret. - Double-click a result and verify that Account is
device-key-v1and its service iscom.debrify.app.profile-device-secret. - Close the details, right-click that item, choose Delete, and confirm with the Mac login password if asked.
- Search again and remove any additional items with the same account and service.
3. Start clean
- Install the current Debrify build again if it was removed.
- Open Debrify. It creates a fresh data store and matching device key.
- Reconnect services or restore a backup made before the failure.
If macOS only keeps asking for a password
The Keychain prompt wants the Mac login Keychain password, not a Debrify password or Apple ID password. If that password is rejected, open Keychain Access and check whether the login keychain can be unlocked. A Mac password change can leave the login Keychain using the previous password.
If Debrify already shows CryptoKit error 3, allowing the prompt again will not repair the mismatched encrypted data; use the paired reset above.
Before the next reinstall
Once Debrify opens again, make an encrypted backup under Settings › Data & Backup. It is the simplest way to recover services, addons, playlists and preferences after a future signing or container change.