pass
The standard unix password manager, a simple shell script that uses GPG and git.
Open the official app on www.passwordstore.org
This tool is hosted by its maintainers. Click below to open www.passwordstore.org in a new tab — it's their official demo.
Browse encryption tools →What's next with pass?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is pass?
pass is an open-source password manager designed for Unix systems that leverages GPG encryption and standard file operations to securely store and manage passwords. It organizes passwords into encrypted files stored within a directory structure, allowing users to manage credentials using familiar command-line tools. The tool is particularly suited for developers, system administrators, and power users who prioritize simplicity, security, and integration with Unix workflows. By encrypting each password individually and storing them in plain text files, pass eliminates the need for complex databases or proprietary formats, aligning with the Unix philosophy of tool-based problem-solving. It addresses the challenge of securely managing multiple passwords across devices by enabling synchronization through Git version control and manual file transfers.
How it works
pass is a password manager that encrypts individual passwords using GPG (GNU Privacy Guard) and stores them in plain text files within a directory hierarchy. Each password file is named after the associated service or account, ensuring clarity and organization. Its primary purpose is to provide a lightweight, secure, and flexible solution for managing passwords without relying on proprietary software. By using Unix file operations, users can easily navigate, copy, and back up their passwords while maintaining encryption. pass supports generating strong passwords, encrypting them with GPG, and storing them in a hierarchical directory structure under ~/.password-store. It integrates with Git for version control, allowing users to track changes and back up their password store. Commands like pass generate, pass insert, and pass show enable password creation, storage, and retrieval.
How to use it
- 1Install pass and GPG on your system. 2. Generate a GPG key pair for encryption. 3. Create a password entry using pass generate [service-name]. 4. Store the password in the password store with pass insert [service-name]. 5. Retrieve the password with pass show [service-name]. 6. Copy the password to the clipboard using pass cp [service-name]. Practical tips: Use Git to track changes in ~/.password-store, organize passwords into folders, and leverage shell completion for faster navigation.
What it can do
- unix password store
Use cases
Assumptions and limitations
Assumptions
- source: https://git.zx2c4.com/password-store
- license: GPL-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Lacks a built-in graphical user interface (GUI) for non-technical users
- Requires manual organization of password files into directories
- Dependent on GPG for encryption, which may be unfamiliar to some users
- No native synchronization across devices without manual file transfers
- Limited search functionality for locating specific passwords
Understanding the result
The standard unix password manager, a simple shell script that uses GPG and git.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (https://git.zx2c4.com/password-store)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with https://git.zx2c4.com/password-store. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- GPL-2.0 License
Upstream project
Frequently asked
What is pass and how does it differ from other password managers?
pass is a command-line password manager that uses GPG encryption and Unix directories to store passwords. Unlike proprietary tools like Bitwarden or KeePass, it relies on standard file operations and avoids complex databases. This makes it lightweight and highly customizable for Unix users, though it lacks GUI features and cloud integration found in alternatives.
How does pass ensure password security?
pass encrypts each password individually using GPG, ensuring that even if files are compromised, decryption requires the corresponding private key. Passwords are stored in plain text within encrypted files, and the directory structure allows for granular access control. Git integration enables secure versioning of the password store, though users must manage their GPG keys carefully.
How do I generate and store a password with pass?
To generate a password, run 'pass generate [service-name]'. This creates an encrypted file in ~/.password-store/[service-name].password. To store a custom password, use 'pass insert [service-name]' and manually enter the password. The file is automatically encrypted with your GPG key, and you can retrieve it with 'pass show [service-name]'.
How does pass compare to Bitwarden or KeePass?
pass differs from Bitwarden and KeePass by using GPG encryption and Unix directories instead of a proprietary database. It offers greater flexibility for advanced users but lacks features like cloud sync, biometric login, and GUI interfaces. Bitwarden and KeePass provide cross-platform tools with built-in sync, while pass requires manual file management and depends on external tools like Git.
How do I troubleshoot GPG decryption errors with pass?
GPG decryption errors typically occur if the private key is missing or corrupted. Verify your GPG key with 'gpg --list-secret-keys' and ensure the pass configuration points to the correct key. If the key is damaged, regenerate it using 'gpg --gen-key' and re-encrypt existing passwords. Check pass's man page for key configuration options.