⚠️ Before submitting, please verify the following: ⚠️
Bug description
On every startup, the Nextcloud desktop client modifies a keychain item that does not belong to it: the generic password Claude Code-credentials (account = my macOS username), created by Claude Code (Anthropic's CLI).
After Nextcloud starts, that item's partition list becomes teamid:NKUJUXUJ3B (Nextcloud's team ID, confirmed with codesign -dv /Applications/Nextcloud.app) instead of apple-tool:. From then on, every other app that reads the item, including /usr/bin/security (which Claude Code uses), is blocked by the partition-list check. macOS shows a "security wants to access key 'Claude Code-credentials'" dialog that can't be dismissed: Allow, Always Allow and Deny all just make it come back.
Evidence
I ran a watcher that logged the item's partition_id and modification date every 5–15 s across a reboot:
| Time |
Event |
| 12:17:22 |
Nextcloud.app starts |
| 12:17:33 |
Nextcloud rewrites its own items (svce="Nextcloud", acct="<user>:https://<server>/:0" and <user>_app-password:…); mdat updated |
| 12:17:37 |
Claude Code-credentials (acct="<user>") gets a new mdat, and its partition_id changes from apple-tool: to teamid:NKUJUXUJ3B |
| 12:17:41 |
First Claude process starts |
No Claude process was running when the item was modified, and no other keychain items were affected. My guess is that a keychain update/write query matches on the account name only (the macOS username, which equals my Nextcloud username) and not on the service, so it hits the first generic password with that account.
Other Claude Code users with Nextcloud installed report the same symptom:
Steps to reproduce
- On macOS, have a generic keychain password created by another tool whose account equals your macOS username (in my case the same as the Nextcloud username), e.g. log in to Claude Code, or:
security add-generic-password -s "Test-item" -a "$USER" -w x
- Check its partition_id (should be
apple-tool:):
security dump-keychain -a ~/Library/Keychains/login.keychain-db | grep -A20 '"svce"<blob>="Test-item"' | grep -A2 partition_id
- Reboot (Nextcloud starts at login).
- The item's partition_id is now
teamid:NKUJUXUJ3B, and reading it with /usr/bin/security triggers a keychain password dialog.
(Observed with the Claude Code item across several reboots; the generic test item in step 1 is my suggested minimal repro.)
Expected behavior
Nextcloud should only read and write its own keychain items (match on service and account), and never change the access control / partition list of other apps' items.
Which files are affected by this bug
None (not a file sync issue; affects macOS login keychain item "Claude Code-credentials")
Operating system
macOS
Which version of the operating system you are running.
macOS 27.0.1
Installation method
Official Installer for macOS 13 and later
Nextcloud Server version
34.0.4
Nextcloud Desktop Client version
34.0.4
Did this occur after an update or on a clean installation?
Minor version update (i.e. 33.0.0 → 33.0.1)
Are you using the Nextcloud Server Encryption module?
No
Are you using an external user-backend?
Nextcloud Server logs
Additional info
Workaround (has to be repeated after every Nextcloud start):
security set-generic-password-partition-list -S apple-tool:,apple:,teamid:NKUJUXUJ3B -s "Claude Code-credentials" -a "$USER"
Command used to check the partition list:
security dump-keychain -a ~/Library/Keychains/login.keychain-db | awk '/"svce"<blob>="Claude Code-credentials"/{f=1} f&&/partition_id/{getline; getline; print; exit}'
Claude Code version: 2.1.286
Bug description
On every startup, the Nextcloud desktop client modifies a keychain item that does not belong to it: the generic password
Claude Code-credentials(account = my macOS username), created by Claude Code (Anthropic's CLI).After Nextcloud starts, that item's partition list becomes
teamid:NKUJUXUJ3B(Nextcloud's team ID, confirmed withcodesign -dv /Applications/Nextcloud.app) instead ofapple-tool:. From then on, every other app that reads the item, including/usr/bin/security(which Claude Code uses), is blocked by the partition-list check. macOS shows a "security wants to access key 'Claude Code-credentials'" dialog that can't be dismissed: Allow, Always Allow and Deny all just make it come back.Evidence
I ran a watcher that logged the item's partition_id and modification date every 5–15 s across a reboot:
svce="Nextcloud",acct="<user>:https://<server>/:0"and<user>_app-password:…); mdat updatedClaude Code-credentials(acct="<user>") gets a new mdat, and its partition_id changes fromapple-tool:toteamid:NKUJUXUJ3BNo Claude process was running when the item was modified, and no other keychain items were affected. My guess is that a keychain update/write query matches on the account name only (the macOS username, which equals my Nextcloud username) and not on the service, so it hits the first generic password with that account.
Other Claude Code users with Nextcloud installed report the same symptom:
Steps to reproduce
security add-generic-password -s "Test-item" -a "$USER" -w xapple-tool:):security dump-keychain -a ~/Library/Keychains/login.keychain-db | grep -A20 '"svce"<blob>="Test-item"' | grep -A2 partition_idteamid:NKUJUXUJ3B, and reading it with/usr/bin/securitytriggers a keychain password dialog.(Observed with the Claude Code item across several reboots; the generic test item in step 1 is my suggested minimal repro.)
Expected behavior
Nextcloud should only read and write its own keychain items (match on service and account), and never change the access control / partition list of other apps' items.
Which files are affected by this bug
None (not a file sync issue; affects macOS login keychain item "Claude Code-credentials")
Operating system
macOS
Which version of the operating system you are running.
macOS 27.0.1
Installation method
Official Installer for macOS 13 and later
Nextcloud Server version
34.0.4
Nextcloud Desktop Client version
34.0.4
Did this occur after an update or on a clean installation?
Minor version update (i.e. 33.0.0 → 33.0.1)
Are you using the Nextcloud Server Encryption module?
No
Are you using an external user-backend?
Nextcloud Server logs
Additional info
Workaround (has to be repeated after every Nextcloud start):
Command used to check the partition list:
Claude Code version: 2.1.286