Because FileVault prevents direct access to your data volume at startup, turning it on requires a backup plan. That backup plan is the FileVault Recovery Key. This key is a precious object that you should treat like the gold that it is virtually made of. If anything were to go wrong with the boot portion of your Mac’s operating system, or in the unlikely event you forget the password to your computer’s account, the only way you can decrypt the drive is using the Recovery Key. Without it and any accessible backup, its contents are truly gone for good.
This Recovery Key is entirely unrelated to the Apple Account Recovery Key, used to regain access to your online account.
When you need a Recovery Key
You should only ever need to use your Recovery Key if you attempt to log in with your macOS account password or username and password, and macOS refuses to let you proceed. In such cases, you should see text that reads Reset Password with a right-pointing arrow to its left. You can also bring up that link right away by clicking the question-mark button to the right of the password field. Follow the instructions to reset your password with the Recovery Key.
Apple has historically had two different ways it manages the Recovery Key. The first lasted for several years, through Tahoe. The second, in Tahoe and later, was optional through version 26.3. It’s mandatory starting in 26.4 and Golden Gate.
The older method is worth understanding if you set up FileVault years ago; the newer one is much safer.
How to view the key
With Tahoe, Apple made three key changes:
- View anytime: You can view the FileVault Recovery Key at any time after it is created—it’s no longer shown just once ever.
- No iCloud account escrow: Simple iCloud escrow is no more.
- Recovery Key in Passwords: The FileVault Recovery Key is added to Passwords. If you have Passwords syncing enabled with iCloud, the key is synced using end-to-end encryption—not simple Apple Account access—among your devices.
If you didn’t interact with FileVault when upgrading to Tahoe or installing 26.1, 26.2, or 26.3, you will be forced in a simple process when you install 26.4 or later, or upgrade from any pre-26.4 version of macOS to Golden Gate. I recommend upgrading manually in 26.0 to 26.3, using the steps below.
In System Settings > Privacy & Security > FileVault, you can click the Show button, validate with Touch ID or a password, and display the key in full.
You can also view the key in Passwords.
In the initial iOS 26/iPadOS 26 release (or maybe the first few), the Recovery Key synced to iPhones and iPads, appearing in the Passwords app, but lacking any information except the Recovery Key label and the key itself. Apple fixed this in a later update, ensuring the information appears identically on all platforms.
Even though the Recovery Key now syncs via iCloud, you could still wind up with a problem:
- With Passwords, if you lose access to all your devices besides your Mac, and it cannot start up using your password, you need another way to access the Recovery Key. Storing it in Passwords is not enough given the consequences of not having it.
- If you don’t use Passwords, you must use another password manager or some other secure method to make sure you can access it if your Mac becomes unavailable.
Check an older key still works
If you set up a locally stored Recovery Key before Tahoe, you can use a Mac command-line tool to validate that the Recovery Key you have on hand is truly accurate without trying to reset an account password. In Terminal, enter sudo fdesetup validaterecovery and press Return.
At the prompt, enter your administrator password, and then paste or enter the Recovery Key. If the result is anything but true, try re-entering. If it continues to produce false or an error, it’s time to reset FileVault.
If you want to disable FileVault, rotate your Recovery Key (because it was exposed), or upgrade to the new method in Tahoe 26.0–26.3, follow these steps:
- Go to System Settings > Privacy & Security > FileVault and disable FileVault.
- Click Turn Off Encryption.
- Use Touch ID or enter your password, as prompted.
- “Decryption” may take a moment; really, it’s making a few low-level changes in the startup partition. Stop here if you simply wanted to disable FileVault; otherwise, proceed.
- Now, re-enable the switch. If it’s been more than a moment since you carried out step 3, you may be prompted to use Touch ID or enter your administrator password.
- “Encrypting” may appear for a moment as macOS rewrites the startup information. There’s no additional action you need to take.
Unlocking remotely, as a last resort
Starting in Tahoe, Apple added an option to enter a Recovery Key via SSH if Remote Login is enabled on your Mac and it’s connected to a network. This could be useful in desperate circumstances, where you’re unable to type directly on the Mac, or it’s located in a hard-to-reach location. Whatever the reason, consider enabling Remote Login if you’re concerned, as described in which Mac sharing services are safe to turn on.
What Apple changed, and why
Before Tahoe, Apple let you choose between two options:
- Store locally: The key was generated, displayed to you, and never stored anywhere. You could never retrieve it after seeing it once.
- Use escrow: The key was securely stored in your iCloud account.
I never liked the iCloud option much, though it was less scary than a “show once, lose forever” local key. However, iCloud escrow had three implications:
- If you somehow lost access to your iCloud account, the key was not retrievable. (If you could still log in to your Mac, you could disable FileVault and re-enable it to generate a new key you stored locally.)
- If someone gained access to your Apple Account credentials, they could unlock a Mac you own that they have access to by using the FileVault recovery process.
- A government agency, rightly or wrongly, could have forced Apple legally or extrajudicially to provide this key for a device they had seized or otherwise obtained. To my knowledge, this has never occurred, but it’s possible Apple would have been constrained from revealing it in any country in which it occurred; that seems unlikely given the company’s stance on encryption and privacy.
Apple’s operating system and cloud security teams must have had thoughts like this when they revamped Recovery Key access in Tahoe.










