How to sign Git commits with GPG on macOS

#gpg#macos#git

GNU Privacy Guard (GPG) lets you sign Git commits with a cryptographic key. Git hosting services can then mark the commit as verified.

The setup has a few moving parts on macOS. Here is the sequence that works for my configuration.

Install and configure GPG#

  1. Install GPG and pinentry-mac with Homebrew:
Terminal window
brew install gnupg pinentry-mac

pinentry-mac lets you enter the key passphrase in a macOS window instead of Terminal.

  1. Create the GPG configuration directory with private permissions:
Terminal window
mkdir -p ~/.gnupg
chmod 700 ~/.gnupg
  1. Add pinentry-mac to the GPG agent configuration:
Terminal window
echo "pinentry-program $(which pinentry-mac)" >> ~/.gnupg/gpg-agent.conf
  1. Add this line to the startup file for your shell:
Terminal window
export GPG_TTY=$(tty)

For Zsh, use ~/.zshrc. For Bash, use ~/.bash_profile or ~/.bashrc, depending on how you start the shell.

  1. Reload the startup file. This example reloads ~/.zshrc:
Terminal window
source ~/.zshrc
  1. Stop the current GPG agent. GPG will start it again when needed:
Terminal window
gpgconf --kill gpg-agent

Create a signing key#

  1. Start the interactive key generator:
Terminal window
gpg --full-generate-key

Choose a supported key type and size. Set an expiration period that fits how you plan to manage the key.

Use an email address that you have verified on GitHub. GitHub uses this address when it verifies a commit signature.

  1. List your secret keys with their long IDs:
Terminal window
gpg --list-secret-keys --keyid-format=long

The output includes a line similar to this one:

Terminal window
sec rsa4096/YOUR_LONG_KEY_ID 2026-08-21 [SC]

Copy the value after the slash. The remaining examples use YOUR_LONG_KEY_ID as a placeholder.

  1. Export the public key:
Terminal window
gpg --armor --export YOUR_LONG_KEY_ID
  1. Configure Git to use the key and sign commits by default:
Terminal window
git config --global user.signingkey YOUR_LONG_KEY_ID
git config --global commit.gpgsign true
  1. Create a signed test commit:
Terminal window
git commit -S -m "Test signed commit" --allow-empty

The pinentry-mac window asks for your passphrase. Enter it and select OK.

Add the public key to GitHub#

  1. Copy the public key:
Terminal window
gpg --armor --export YOUR_LONG_KEY_ID | pbcopy

Then sign in to GitHub. Open Settings > SSH and GPG keys and add the copied public key.

GitHub can now verify commits that use this key and a verified email address from your account.

For more detail, see the official guides for creating a GPG key, configuring Git with that key, and configuring GPG Agent.