Andrew Mercer
on this page

pass keeps each secret as a GPG-encrypted file under ~/.password-store/, organised in directories. It is scriptable and works with git for syncing. See also the ArchWiki page.

Set up

gpg --list-keys                          # find your key ID or email (see the GnuPG page)
pass init "[email protected]"              # initialise the store, encrypting to that key
pass git init                            # optional: track changes in git

Add, list, show

pass insert web/example.com/password         # single line (prompted)
pass insert -m bank/example/online           # multi-line secret; end with Ctrl+D
username: alice
password: <the-password>
pass                                     # list everything as a tree
pass ls bank
pass show bank/example/online
pass show -c web/example.com/password    # copy to clipboard, cleared after 45 s
pass generate web/example.com/password 24        # generate a 24-character password
pass edit bank/example/online
pass rm web/old-site

Directory and file names are not encrypted, so don't put sensitive information in the entry names themselves (the account number belongs inside the file, not in its path).

The gpg-agent cache

pass uses GPG, which caches the passphrase in gpg-agent (the GNOME desktop also uses it). Control how long it is remembered:

echo "default-cache-ttl 600" >> ~/.gnupg/gpg-agent.conf
gpg-connect-agent reloadagent /bye       # apply the change and clear the cache

After the cache clears you can still list entries but must re-enter your passphrase to show one.