pass keeps each secret as a GPG-encrypted file under ~/.password-store/, organised in directories. It is scriptable and works with git for syncing. See also the ArchWiki page.
Set up¶
gpg --list-keys # find your key ID or email (see the GnuPG page)
pass init "[email protected]" # initialise the store, encrypting to that key
pass git init # optional: track changes in git
Add, list, show¶
pass insert web/example.com/password # single line (prompted)
pass insert -m bank/example/online # multi-line secret; end with Ctrl+D
username: alice
password: <the-password>
pass # list everything as a tree
pass ls bank
pass show bank/example/online
pass show -c web/example.com/password # copy to clipboard, cleared after 45 s
pass generate web/example.com/password 24 # generate a 24-character password
pass edit bank/example/online
pass rm web/old-site
Directory and file names are not encrypted, so don't put sensitive information in the entry names themselves (the account number belongs inside the file, not in its path).
The gpg-agent cache¶
pass uses GPG, which caches the passphrase in gpg-agent (the GNOME desktop also uses it). Control how long it is remembered:
echo "default-cache-ttl 600" >> ~/.gnupg/gpg-agent.conf
gpg-connect-agent reloadagent /bye # apply the change and clear the cache
After the cache clears you can still list entries but must re-enter your passphrase to show one.