Skip to content

age

Simple, modern, secure file encryption tool with small keys.

Self-hostedNot yet verified
Report issueDemo online
BSD-3-Clause★ 18000

Open the official app on age-encryption.org

This tool is hosted by its maintainers. Click below to open age-encryption.org in a new tab — it's their official demo.

Browse encryption tools →

What's next with age?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is age?

age is an open-source encryption tool and Go library designed for secure, simple file encryption with minimal configuration. It enables users to encrypt data using small explicit keys, ensuring strong security without complex setup. Developers, system administrators, and security professionals use age to protect sensitive information during transmission or storage. The tool addresses the challenge of secure encryption by eliminating configuration options, reducing human error, and leveraging UNIX-style composability for integration into workflows. Its post-quantum cryptographic features make it suitable for long-term data protection against future quantum computing threats. age’s design prioritizes transparency and ease of use while maintaining security standards.

How it works

age is a command-line tool and Go library for encrypting files and data streams. It uses small, explicit keys (e.g., 128-bit or 256-bit) to encrypt data, ensuring simplicity and security. The tool is designed for developers and system administrators who need to securely transmit or store sensitive information without complex setup. Its primary purpose is to provide a lightweight, configurable-free encryption solution. By avoiding configuration files, age minimizes attack surfaces and reduces the risk of misconfiguration. It also supports UNIX-style pipelining, allowing it to integrate smoothly with other command-line tools. age supports modern cryptographic algorithms, including post-quantum-resistant options. It can encrypt files, data streams, and even entire directories. The tool’s explicit key design ensures users manage keys directly, enhancing transparency. Additionally, age includes a Go library for embedding encryption capabilities into applications. Its composability allows chaining with tools like `tar` or `gzip` for secure data packaging.

How to use it

  1. 1Install age using `go get github.com/Filosottile/age` or download precompiled binaries from the GitHub releases page. 2. Generate a keypair with `age key generate` to create a public/private key pair. 3. Encrypt a file using `age -e -r <recipient-key> <file>`, which produces an encrypted file with a `.age` extension. 4. Decrypt the file with `age -d -r <private-key> <encrypted-file.age`. Practical tips: Use standard file formats like `.age` for encrypted outputs. Store private keys securely, as they are required for decryption. Always verify the recipient’s public key before encryption to prevent key mismatches.

What it can do

  • file encryption

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/FiloSottile/age
  • license: BSD-3-Clause — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Lacks built-in key management systems; users must handle key storage manually
  • No graphical user interface (GUI) for non-technical users
  • Limited integration with proprietary systems or services
  • Depends on Go runtime for the library, which may not be ideal for all environments
  • No support for legacy cryptographic algorithms beyond modern standards

Understanding the result

Simple, modern, secure file encryption tool with small keys.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (BSD-3-Clause).
Built with
(FiloSottile/age)
License
BSD-3-Clause
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with FiloSottile/age. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
BSD-3-Clause
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is age and how does it differ from traditional encryption tools?

age is a modern encryption tool and Go library that emphasizes simplicity and security through explicit keys and no configuration. Unlike traditional tools like GPG, which rely on configuration files and complex key management, age uses small, human-readable keys and avoids configuration entirely. This reduces the risk of misconfiguration and makes it easier to integrate into pipelines. It also supports post-quantum cryptographic algorithms, making it suitable for long-term data protection.

How does age ensure security with small explicit keys?

age uses small explicit keys (e.g., 128-bit or 256-bit) that are directly provided by the user, eliminating the need for configuration files or complex key derivation processes. This approach minimizes attack surfaces by avoiding hidden configuration defaults. The keys are typically stored in a human-readable format, allowing users to verify and manage them directly. Additionally, age leverages modern cryptographic algorithms, including post-quantum-resistant options, to ensure security against both classical and future quantum computing threats.

How do I encrypt a file using age?

To encrypt a file, first generate a recipient’s public key using `age key generate`. Then, use the `age -e -r <recipient-key> <file>` command, replacing `<recipient-key>` with the public key and `<file>` with the file path. This will create an encrypted file with a `.age` extension. To decrypt, use `age -d -r <private-key> <encrypted-file.age` and provide the private key for decryption.

How does age compare to alternatives like GPG or OpenSSL?

age differs from GPG and OpenSSL by prioritizing simplicity and explicit key management. GPG uses configuration files and complex key management, while age avoids these with minimal setup. OpenSSL offers broader cryptographic features but requires detailed configuration. age’s UNIX-style composability makes it easier to integrate into command-line workflows, whereas GPG’s interface is more tailored for traditional email-based encryption. age also focuses on post-quantum security, which is less emphasized in older tools.

What should I do if I encounter an error during encryption?

Common errors include invalid keys, missing files, or incorrect permissions. Verify the recipient’s public key is correctly formatted and matches the encryption command. Ensure the file path exists and the user has read permissions. For decryption errors, confirm the private key is valid and matches the encrypted file. Check the age documentation or GitHub issues for specific error codes, and ensure the Go runtime is correctly installed if using the library.

Spotted something wrong with age, or want to maintain it? See how to help.