Guides/Troubleshooting

Fix “CryptoKit error 3” at startup

This error means Debrify found a device key, but that key cannot open the encrypted data saved beside it. Reset the key and data together — or start with a fresh LiveContainer container without deleting the old one.

Where to find it
Startup error CryptoKit error 3
Full messagePlatformException(device_secret_failed … CryptoKitError error 3.)
Common afterA LiveContainer reinstall or new certificate · a macOS update and Keychain prompt

What the error means

CryptoKit error 3 is an authentication failure. Debrify encrypts account credentials with a key kept by the device. The error appears when the saved key and encrypted app data no longer belong together.

This can happen after LiveContainer is reinstalled or signed with a new developer certificate, or after only one half of Debrify's macOS data is cleared. Reinstalling or downgrading Debrify by itself may not help because Keychain data can survive the app.

Do not clear only the Keychain or only the app data. A reset must clear both together. It signs you out and removes the affected Debrify setup.

iPhone or iPad using LiveContainer

Safest: make a fresh container

This leaves the old container untouched, so try it before deleting anything.

  1. Force-close LiveContainer.
  2. Reopen LiveContainer, but do not launch Debrify.
  3. Long-press Debrify and open Settings.
  4. Under Container, tap New Data Folder.
  5. Name it Debrify Fresh.
  6. Open the new container and tap Set as Default Container.
  7. Launch Debrify with the new container and set it up again.

LiveContainer gives its containers separate Keychain access. A new container therefore starts with a matching empty data store and device key. Your old container remains available in case you need it later.

If you must reuse the current container

  1. Force-close LiveContainer, reopen it, then long-press Debrify and open Settings.
  2. Under Container, open the container Debrify currently uses.
  3. Tap Delete Data and confirm.
  4. On that same screen, tap Clean Up Keychain and confirm.
  5. Launch Debrify and set it up again.
Use the cleanup inside the Debrify container. Do not use LiveContainer's global Settings › Data Management › Clean Up Keychain; the global action can sign you out of other apps.

If a fresh container also fails

Open LiveContainer › Settings › JIT-Less Mode Diagnose › Entitlement File. The Keychain access-groups check should pass. If it does not, reinstall or re-sign LiveContainer with the required entitlements, import its current certificate again, and then create another fresh Debrify container. LiveContainer documents its per-container Keychain separation on its official project page.

macOS

These steps perform a complete Debrify reset. If the current setup matters, move the container aside as a backup before deleting the Keychain item.

1. Move the app data aside

  1. Quit Debrify completely with ⌘ Q.
  2. In Finder, choose Go › Go to Folder…, or press ⇧ ⌘ G.
  3. Enter ~/Library/Containers/com.example.torrentSearchApp.
  4. Move that folder to the Desktop and name it something like Debrify old data.

2. Remove the matching Keychain item

  1. Press ⌘ Space, search for Keychain Access, and open it.
  2. In the sidebar, select the login keychain, then All Items or Passwords.
  3. Search for com.debrify.app.profile-device-secret.
  4. Double-click a result and verify that Account is device-key-v1 and its service is com.debrify.app.profile-device-secret.
  5. Close the details, right-click that item, choose Delete, and confirm with the Mac login password if asked.
  6. Search again and remove any additional items with the same account and service.

3. Start clean

  1. Install the current Debrify build again if it was removed.
  2. Open Debrify. It creates a fresh data store and matching device key.
  3. Reconnect services or restore a backup made before the failure.

If macOS only keeps asking for a password

The Keychain prompt wants the Mac login Keychain password, not a Debrify password or Apple ID password. If that password is rejected, open Keychain Access and check whether the login keychain can be unlocked. A Mac password change can leave the login Keychain using the previous password.

If Debrify already shows CryptoKit error 3, allowing the prompt again will not repair the mismatched encrypted data; use the paired reset above.

Before the next reinstall

Once Debrify opens again, make an encrypted backup under Settings › Data & Backup. It is the simplest way to recover services, addons, playlists and preferences after a future signing or container change.