Skip to content

rclone crypt

Add client-side encryption to any cloud storage with rclone.

Self-hostedNot yet verified
Report issueDemo online
MIT★ 47000

Open the official app on rclone.org

This tool is hosted by its maintainers. Click below to open rclone.org in a new tab — it's their official demo.

Browse encryption tools →

What's next with rclone crypt?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is rclone crypt?

rclone crypt is an open-source encryption tool integrated into the rclone project, designed to provide client-side encryption for cloud storage. It acts as a wrapper around existing rclone remotes, adding an encryption layer that ensures data is encrypted before upload and decrypted after download. This tool is used by individuals and organizations seeking to secure sensitive data stored in untrusted cloud environments. By encrypting data locally, rclone crypt mitigates risks of data breaches or unauthorized access to cloud storage providers. It solves the problem of storing unencrypted data in third-party services, offering a balance between accessibility and security through symmetric key encryption.

How it works

rclone crypt is a feature within the rclone toolkit that enables client-side encryption for data stored in cloud services. It operates by wrapping an existing remote (e.g., Google Drive, S3) and encrypting files before they are uploaded, ensuring data remains encrypted at rest. The primary purpose of rclone crypt is to protect data confidentiality by preventing unauthorized access to unencrypted files. It allows users to securely store data in cloud environments without relying on the provider’s encryption capabilities, which may not always be trustworthy. rclone crypt supports symmetric key encryption using a password, ensuring data is scrambled and unreadable without the correct decryption key. It can be layered over multiple remotes, enabling complex encryption workflows. For example, data can be encrypted, compressed, and uploaded to a remote storage system in a single operation.

How to use it

  1. 1Configure a remote storage provider (e.g., Google Drive) using rclone config. 2. Define a crypt remote that wraps the existing remote, specifying an encryption password. 3. Use rclone commands (e.g., sync, copy) to transfer files between the crypt remote and local system. 4. Verify encryption by checking that uploaded files are scrambled and require the password for decryption. Practical tips: Store passwords securely using a password manager, avoid reusing passwords across services, and test encryption/decryption workflows before relying on them for critical data.

What it can do

  • cloud encryption

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/rclone/rclone
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Data is encrypted only when accessed through rclone crypt; direct access to the underlying remote reveals scrambled files
  • Relies on user-provided passwords, which may be vulnerable to brute-force attacks or phishing
  • Encryption/decryption adds computational overhead, potentially slowing transfer speeds
  • Requires careful key management to prevent data loss if passwords are forgotten
  • Does not support server-side encryption offered by some cloud providers

Understanding the result

Add client-side encryption to any cloud storage with rclone.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(rclone/rclone)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with rclone/rclone. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

How does rclone crypt differ from server-side encryption provided by cloud providers?

rclone crypt performs encryption locally on the user’s machine before uploading data, ensuring files are encrypted at rest even if the cloud provider’s encryption is compromised. Server-side encryption, in contrast, encrypts data after it is uploaded to the cloud, relying on the provider’s infrastructure for key management. rclone crypt gives users full control over encryption keys but requires manual password management.

How does the symmetric key encryption work in rclone crypt?

rclone crypt uses a password provided by the user to generate cryptographic keys for AES-256 encryption. When uploading files, the tool encrypts data locally using these keys, storing the encrypted bytes in the remote storage. During download, the same password is used to decrypt the data. The password is never stored with the files, ensuring that only authorized users with the correct key can access the content.

How do I create an encrypted remote for Google Drive using rclone crypt?

First, configure a Google Drive remote with rclone config. Then, define a new remote with type 'crypt', specifying the wrapped remote (e.g., 'remote=drive') and a password. For example: 'crypt remote=drive password=yourpassword'. Finally, use rclone commands like 'rclone sync /local/path crypt:/' to transfer files, which will be automatically encrypted during upload.

How does rclone crypt compare to tools like Cryptomator or Boxcryptor?

rclone crypt integrates directly with rclone’s ecosystem, allowing seamless use with existing cloud storage configurations and advanced features like mounting encrypted remotes. Unlike Cryptomator or Boxcryptor, which often require separate interfaces or client applications, rclone crypt operates as a command-line tool, offering greater flexibility for automation and scripting. However, it lacks the user-friendly GUI of some alternatives.

What should I do if I forget the password for my rclone crypt remote?

If the password is forgotten, data becomes irretrievable, as rclone crypt does not store encryption keys. To prevent this, use a password manager to securely save the password. If access is lost, the encrypted files cannot be decrypted, and recovery is not supported by the tool. Always verify the password before initiating critical operations.

Spotted something wrong with rclone crypt, or want to maintain it? See how to help.