Skip to content

pass

The standard unix password manager, a simple shell script that uses GPG and git.

Self-hostedNot yet verified
Demo online
MIT

Open the official app on www.passwordstore.org

This tool is hosted by its maintainers. Click below to open www.passwordstore.org in a new tab — it's their official demo.

Browse encryption tools →

What's next with pass?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is pass?

pass is an open-source password manager designed for Unix systems that leverages GPG encryption and standard file operations to securely store and manage passwords. It organizes passwords into encrypted files stored within a directory structure, allowing users to manage credentials using familiar command-line tools. The tool is particularly suited for developers, system administrators, and power users who prioritize simplicity, security, and integration with Unix workflows. By encrypting each password individually and storing them in plain text files, pass eliminates the need for complex databases or proprietary formats, aligning with the Unix philosophy of tool-based problem-solving. It addresses the challenge of securely managing multiple passwords across devices by enabling synchronization through Git version control and manual file transfers.

How it works

pass is a password manager that encrypts individual passwords using GPG (GNU Privacy Guard) and stores them in plain text files within a directory hierarchy. Each password file is named after the associated service or account, ensuring clarity and organization. Its primary purpose is to provide a lightweight, secure, and flexible solution for managing passwords without relying on proprietary software. By using Unix file operations, users can easily navigate, copy, and back up their passwords while maintaining encryption. pass supports generating strong passwords, encrypting them with GPG, and storing them in a hierarchical directory structure under ~/.password-store. It integrates with Git for version control, allowing users to track changes and back up their password store. Commands like pass generate, pass insert, and pass show enable password creation, storage, and retrieval.

How to use it

  1. 1Install pass and GPG on your system. 2. Generate a GPG key pair for encryption. 3. Create a password entry using pass generate [service-name]. 4. Store the password in the password store with pass insert [service-name]. 5. Retrieve the password with pass show [service-name]. 6. Copy the password to the clipboard using pass cp [service-name]. Practical tips: Use Git to track changes in ~/.password-store, organize passwords into folders, and leverage shell completion for faster navigation.

What it can do

  • unix password store

Use cases

Assumptions and limitations

Assumptions

  • source: https://git.zx2c4.com/password-store
  • license: GPL-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Lacks a built-in graphical user interface (GUI) for non-technical users
  • Requires manual organization of password files into directories
  • Dependent on GPG for encryption, which may be unfamiliar to some users
  • No native synchronization across devices without manual file transfers
  • Limited search functionality for locating specific passwords

Understanding the result

The standard unix password manager, a simple shell script that uses GPG and git.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(https://git.zx2c4.com/password-store)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with https://git.zx2c4.com/password-store. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is pass and how does it differ from other password managers?

pass is a command-line password manager that uses GPG encryption and Unix directories to store passwords. Unlike proprietary tools like Bitwarden or KeePass, it relies on standard file operations and avoids complex databases. This makes it lightweight and highly customizable for Unix users, though it lacks GUI features and cloud integration found in alternatives.

How does pass ensure password security?

pass encrypts each password individually using GPG, ensuring that even if files are compromised, decryption requires the corresponding private key. Passwords are stored in plain text within encrypted files, and the directory structure allows for granular access control. Git integration enables secure versioning of the password store, though users must manage their GPG keys carefully.

How do I generate and store a password with pass?

To generate a password, run 'pass generate [service-name]'. This creates an encrypted file in ~/.password-store/[service-name].password. To store a custom password, use 'pass insert [service-name]' and manually enter the password. The file is automatically encrypted with your GPG key, and you can retrieve it with 'pass show [service-name]'.

How does pass compare to Bitwarden or KeePass?

pass differs from Bitwarden and KeePass by using GPG encryption and Unix directories instead of a proprietary database. It offers greater flexibility for advanced users but lacks features like cloud sync, biometric login, and GUI interfaces. Bitwarden and KeePass provide cross-platform tools with built-in sync, while pass requires manual file management and depends on external tools like Git.

How do I troubleshoot GPG decryption errors with pass?

GPG decryption errors typically occur if the private key is missing or corrupted. Verify your GPG key with 'gpg --list-secret-keys' and ensure the pass configuration points to the correct key. If the key is damaged, regenerate it using 'gpg --gen-key' and re-encrypt existing passwords. Check pass's man page for key configuration options.

Spotted something wrong with pass, or want to maintain it? See how to help.