11Download

LDAP Studio

LDAP, finally native on the Mac.

Browse, search and edit any LDAP directory in a fast SwiftUI app built on OpenLDAP. No Java runtime, no Windows VM, no ldapsearch one-liners.

macOS 27 or later · Apple Silicon · free and open source (MIT)

LDAP Studio - Example Research Lab

uid=adauid=ada,ou=people,dc=example,dc=org
Attribute Value
cnAda Lovelace
displayNameAda Lovelace
givenNameAda
jpegPhotoAL
mailada@example.org
memberOfcn=researchers,ou=groups,dc=example,dc=org
objectClassinetOrgPerson
snLovelace
titleAnalyst
uidada
userPassword{PBKDF2-SHA512}100000$…
Operation Log3

This window works. Expand the tree, pick an entry, search.

Why it exists

LDAPStudiostartedatCBPF,theBrazilianresearchcenterwhereitsauthorworks.TheonlyrealLDAPclientavailablewasLDAPAdmin:Windows-onlyandnotupdatedinyears,andeverylookupmeantbootingavirtualmachinejusttoopenit.SoitsauthorbuiltanativeoneformacOS.

From five steps to two.

Flip between before and after to see what editing a single entry used to take.

Editing one entry

  1. 1Boot the Windows virtual machine
  2. 2Wait for Windows to start and log in
  3. 3Open LDAP Admin and connect
  4. 4Find the entry and edit it
  5. 5Copy the result back to the Mac

Native, not ported

SwiftUI windows, the macOS menu bar, a shortcut for every action and passwords kept in the Keychain.

Reads your schema

Attribute names and object classes autocomplete from the server's own schema, with superior-class inheritance resolved.

Careful with your data

Read-only mode per connection, passwords hashed before they leave your Mac, and a count of affected entries before any recursive delete.

Under the hood

Native from the window down to the wire.

No JVM, no Electron. Three layers, each one doing the job it is best at.

  1. The interface

    SwiftUI

    Windows, sheets, menus and shortcuts written in SwiftUI, with connection passwords stored in the macOS Keychain.

  2. The C core

    libldapstudio

    A small C library that runs every LDAP operation, parses the schema, resizes photos and hashes passwords.

  3. The foundations

    OpenLDAP · OpenSSL · libxcrypt

    Proven libraries for the LDAP protocol, TLS, and the crypt(3) password formats.

Features

Everything you do in a directory, in one window.

From a quick lookup to moving whole subtrees, without leaving the keyboard.

Browse the tree

Expand any branch, filter it as you type and see how many children each container holds.

dc=example,dc=org
└─ ou=people  (128)
   └─ uid=alice
  • Jump straight to any DN
  • Bookmarks for each connection
  • Multi-select and drag to move

Search with real filters

Write RFC 4515 filters by hand or build them visually, then pin the ones you use every day.

(&(objectClass=inetOrgPerson)
  (mail=*@example.org))
  • Visual filter builder
  • Pinned filters and search history
  • Search scoped to a branch

Edit entries

Add, edit and delete attributes, binary values included, with names suggested by the server's schema.

  mail: alice@example.org
+ telephoneNumber: +55 21 5555-0100
  • Guided new entry
  • Group membership editor
  • Move, copy and rename whole subtrees

Hash passwords locally

userPassword is hashed on your Mac. The plaintext is never stored or sent as is.

userPassword:
  {PBKDF2-SHA512}100000$Zk3q…$9xQe…
  • PBKDF2-SHA512 by default
  • SSHA, SMD5, SHA1 and MD5
  • Unix, MD5, SHA-256 and SHA-512 crypt

Speak LDIF

Import and export LDIF files, or write and run LDIF in an editor with syntax highlighting.

dn: uid=alice,ou=people,dc=example,dc=org
changetype: modify
replace: title
title: Directory admin
  • Export a whole subtree
  • Copy any entry as LDIF
  • Run LDIF against the server

Read the schema

Browse object classes and attributes, with superior-class inheritance resolved for you.

inetOrgPerson
→ organizationalPerson → person → top
  • Jump from an attribute to its definition
  • Autocomplete driven by the schema

Every server at hand

Save connections with SSL or StartTLS, trust certificates per server and keep passwords in the Keychain.

ldaps://ldap.example.org:636
bind: cn=admin,dc=example,dc=org
  • Favorites and read-only mode
  • Import from LDAP Admin (.lcf)
  • Import and export as JSON

Set photos

Set jpegPhoto from any image. It is resized and center-cropped to 300×300 for you.

photo.png  1920×1080
→ jpegPhoto  300×300 JPEG
  • Shown in the entry header

Know your server

Check what the server supports, test credentials and follow every operation as it runs.

supportedLDAPVersion: 3
supportedControl: 1.2.840.113556.1.4.319
  • Server info panel
  • Test Bind and password-policy card
  • Operation log

Try it

Play with it right here.

Two parts of the app, rebuilt for this page. Nothing you type leaves your browser.

Entries must match

(&(objectClass=inetOrgPerson)(mail=*example.org))

Special characters are escaped for you. In the app, Advanced Search runs the filter and you can pin it for later.

Install

Install it in four steps.

LDAP Studio ships as a zipped app on GitHub. No installer, no account.

  1. 1

    Download the latest release

    Get the ldap-studio zip file of the latest version, published on GitHub Releases.

  2. 2

    Move it to Applications

    Unzip the file and drag ldap-studio.app into your Applications folder.

  3. 3

    Allow it to open

    The app is not signed with a paid Apple Developer account, so macOS blocks the first launch. Open System Settings → Privacy & Security, scroll down and click Open Anyway.

  4. 4

    Still blocked? Clear the quarantine flag

    Run this in Terminal, then open the app again.

    $xattr -cr /Applications/ldap-studio.app

Requirements

  • macOS 27 Golden Gate or later
  • Apple Silicon (arm64). There is no Intel build yet.

Updating

The app checks GitHub for a new version when it launches, and you can check any time from the app menu (Check for Updates…). To update, download the new zip and replace the app in Applications.

Build from source

Needs Xcode and Homebrew. The script builds a Release app and zips it into the dist folder.

$git clone https://github.com/dethdkn/ldap-studio && cd ldap-studio
$brew bundle
$./scripts/build.sh

Get started

Your first connection.

On the home window, click Add Connection…, fill in the fields and press Test Connection before saving.

New Connection Configure directory access, authentication, and routing.

Directory Server

CancelAdd Connection

Point at a field

Host

The hostname or IP address of your LDAP server.

Connection as an LDAP URL

ldaps://ldap.example.org:636/dc=example,dc=org

bind cn=admin,dc=example,dc=org

  • Double-click a saved connection to open its directory in a new window.

  • Right-click any entry in the tree for every action you can take on it.

  • Select several entries and drag them onto another branch to move them.

Keep your hands on the keyboard.

Every action lives in the menu bar, and most have a shortcut.

Directory

  • Go to DN…⌘L
  • Refresh⌘R
  • Reload Entire Tree⌥⌘R
  • Bookmark Entry⌘D
  • Advanced Search…⇧⌘F
  • Server Info…⌘I
  • Run LDIF⇧⌘R
  • Operation Log⇧⌘Y

Entries

  • New Entry…⌘N
  • Edit Entry…⌘E
  • Rename…⇧⌘E
  • Move to…⇧⌘M
  • Copy to…⇧⌘D
  • Copy DN⇧⌘C
  • Copy as LDIF⌥⇧⌘C
  • Export as LDIF⇧⌘X
  • Delete Entry⌘⌫

Attributes

  • Show Operational Attributes⌥⌘O
  • Edit Value…⌥⌘E
  • View Value⌘J
  • Jump to Schema⇧⌘S
  • Set Password…⇧⌘K
  • Set Photo…⇧⌘I
  • Edit Members…⇧⌘U
  • Test Bind…⇧⌘B

Questions, answered.

Contributors

Made in the open.

LDAP Studio is built by the people below. Bug fixes, features and translations are welcome.

Download LDAP Studio.

Free, open source and made for the Mac. Get the latest version and connect to your first server.

ldap-studio-v1.3.0.zip · 6.2 MB · Oct 8, 2026