# Linux keyring

> The desktop keeps a Google connection only in the operating system's secret store. On Linux that means GNOME Keyring or KWallet must be installed, running and unlocked.

When it cannot protect the connection, the desktop says **"This computer cannot protect the Google access"** and stops before anything else: no Google page is opened and nothing is saved. An existing connection shows as **Locked** — its account is hidden and it cannot be used until the store is back — and can still be disconnected.

## Fix it

1. **Install a secret store** if your desktop has none:
   - GNOME, Cinnamon, Xfce, MATE, Pantheon, Unity and other GNOME-based desktops: `gnome-keyring` (Debian/Ubuntu `sudo apt install gnome-keyring`, Fedora `sudo dnf install gnome-keyring`, Arch `sudo pacman -S gnome-keyring`), and optionally *Passwords and Keys* (`seahorse`) to see it.
   - KDE Plasma: KWallet (`kwalletmanager`), with the Secret Service integration enabled.
2. **Unlock it**: log out and back in so the store starts with your session, or open *Passwords and Keys* / *KWallet Manager* and unlock the default keyring when it asks.
3. **Remove `--password-store=basic`** if you start tamag0 with it (a custom launcher or `.desktop` file): that flag tells the app to keep secrets in plain obfuscation, which the desktop refuses for Google. The `--password-store=gnome-libsecret` and `--password-store=kwallet5`/`kwallet6` values are fine.
4. **Restart tamag0**, then press **Connect** on the card again.

If the message comes back after these steps, the app probably did not recognise your session. It chooses its secret store once, at startup, from the desktop it detects; on a window manager such as i3, sway or Hyprland, or another session it does not recognise, it falls back to the refused store even when a keyring is running. In that case:

- start `gnome-keyring-daemon` (or another Secret Service provider) at login and make sure it is unlocked;
- start tamag0 with `--password-store=gnome-libsecret`, in your launcher or the `Exec=` line of its `.desktop` file;
- restart tamag0 and press **Connect** again.

## Why it is strict

A Google connection opens your mail, calendar and Drive. A file the app could decrypt by itself on the same machine would protect it no better than the file's permissions, so the desktop accepts only a store held by the operating system, and never falls back to a weaker one.

## Related

- [Integrations](https://tamag0.ai/docs/integrations.md)
- [Security](https://tamag0.ai/docs/security.md)
