How to sign Git commits with GPG on macOS
GNU Privacy Guard (GPG) lets you sign Git commits with a cryptographic key. Git hosting services can then mark the commit as verified.
The setup has a few moving parts on macOS. Here is the sequence that works for my configuration.
Install and configure GPG#
- Install GPG and
pinentry-macwith Homebrew:
brew install gnupg pinentry-macpinentry-mac lets you enter the key passphrase in a macOS window instead of Terminal.
- Create the GPG configuration directory with private permissions:
mkdir -p ~/.gnupgchmod 700 ~/.gnupg- Add
pinentry-macto the GPG agent configuration:
echo "pinentry-program $(which pinentry-mac)" >> ~/.gnupg/gpg-agent.conf- Add this line to the startup file for your shell:
export GPG_TTY=$(tty)For Zsh, use ~/.zshrc. For Bash, use ~/.bash_profile or ~/.bashrc, depending on how you start the shell.
- Reload the startup file. This example reloads
~/.zshrc:
source ~/.zshrc- Stop the current GPG agent. GPG will start it again when needed:
gpgconf --kill gpg-agentCreate a signing key#
- Start the interactive key generator:
gpg --full-generate-keyChoose a supported key type and size. Set an expiration period that fits how you plan to manage the key.
Use an email address that you have verified on GitHub. GitHub uses this address when it verifies a commit signature.
- List your secret keys with their long IDs:
gpg --list-secret-keys --keyid-format=longThe output includes a line similar to this one:
sec rsa4096/YOUR_LONG_KEY_ID 2026-08-21 [SC]Copy the value after the slash. The remaining examples use YOUR_LONG_KEY_ID as a placeholder.
- Export the public key:
gpg --armor --export YOUR_LONG_KEY_ID- Configure Git to use the key and sign commits by default:
git config --global user.signingkey YOUR_LONG_KEY_IDgit config --global commit.gpgsign true- Create a signed test commit:
git commit -S -m "Test signed commit" --allow-emptyThe pinentry-mac window asks for your passphrase. Enter it and select OK.
Add the public key to GitHub#
- Copy the public key:
gpg --armor --export YOUR_LONG_KEY_ID | pbcopyThen sign in to GitHub. Open Settings > SSH and GPG keys and add the copied public key.
GitHub can now verify commits that use this key and a verified email address from your account.
For more detail, see the official guides for creating a GPG key, configuring Git with that key, and configuring GPG Agent.