rclone crypt
Add client-side encryption to any cloud storage with rclone.
Open the official app on rclone.org
This tool is hosted by its maintainers. Click below to open rclone.org in a new tab — it's their official demo.
Browse encryption tools →What's next with rclone crypt?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is rclone crypt?
rclone crypt is an open-source encryption tool integrated into the rclone project, designed to provide client-side encryption for cloud storage. It acts as a wrapper around existing rclone remotes, adding an encryption layer that ensures data is encrypted before upload and decrypted after download. This tool is used by individuals and organizations seeking to secure sensitive data stored in untrusted cloud environments. By encrypting data locally, rclone crypt mitigates risks of data breaches or unauthorized access to cloud storage providers. It solves the problem of storing unencrypted data in third-party services, offering a balance between accessibility and security through symmetric key encryption.
How it works
rclone crypt is a feature within the rclone toolkit that enables client-side encryption for data stored in cloud services. It operates by wrapping an existing remote (e.g., Google Drive, S3) and encrypting files before they are uploaded, ensuring data remains encrypted at rest. The primary purpose of rclone crypt is to protect data confidentiality by preventing unauthorized access to unencrypted files. It allows users to securely store data in cloud environments without relying on the provider’s encryption capabilities, which may not always be trustworthy. rclone crypt supports symmetric key encryption using a password, ensuring data is scrambled and unreadable without the correct decryption key. It can be layered over multiple remotes, enabling complex encryption workflows. For example, data can be encrypted, compressed, and uploaded to a remote storage system in a single operation.
How to use it
- 1Configure a remote storage provider (e.g., Google Drive) using rclone config. 2. Define a crypt remote that wraps the existing remote, specifying an encryption password. 3. Use rclone commands (e.g., sync, copy) to transfer files between the crypt remote and local system. 4. Verify encryption by checking that uploaded files are scrambled and require the password for decryption. Practical tips: Store passwords securely using a password manager, avoid reusing passwords across services, and test encryption/decryption workflows before relying on them for critical data.
What it can do
- cloud encryption
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/rclone/rclone
- license: MIT — free to use
- privacy: Self-hosted — you control your data
Limitations
- Data is encrypted only when accessed through rclone crypt; direct access to the underlying remote reveals scrambled files
- Relies on user-provided passwords, which may be vulnerable to brute-force attacks or phishing
- Encryption/decryption adds computational overhead, potentially slowing transfer speeds
- Requires careful key management to prevent data loss if passwords are forgotten
- Does not support server-side encryption offered by some cloud providers
Understanding the result
Add client-side encryption to any cloud storage with rclone.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (rclone/rclone)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with rclone/rclone. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- MIT License
Upstream project
Frequently asked
How does rclone crypt differ from server-side encryption provided by cloud providers?
rclone crypt performs encryption locally on the user’s machine before uploading data, ensuring files are encrypted at rest even if the cloud provider’s encryption is compromised. Server-side encryption, in contrast, encrypts data after it is uploaded to the cloud, relying on the provider’s infrastructure for key management. rclone crypt gives users full control over encryption keys but requires manual password management.
How does the symmetric key encryption work in rclone crypt?
rclone crypt uses a password provided by the user to generate cryptographic keys for AES-256 encryption. When uploading files, the tool encrypts data locally using these keys, storing the encrypted bytes in the remote storage. During download, the same password is used to decrypt the data. The password is never stored with the files, ensuring that only authorized users with the correct key can access the content.
How do I create an encrypted remote for Google Drive using rclone crypt?
First, configure a Google Drive remote with rclone config. Then, define a new remote with type 'crypt', specifying the wrapped remote (e.g., 'remote=drive') and a password. For example: 'crypt remote=drive password=yourpassword'. Finally, use rclone commands like 'rclone sync /local/path crypt:/' to transfer files, which will be automatically encrypted during upload.
How does rclone crypt compare to tools like Cryptomator or Boxcryptor?
rclone crypt integrates directly with rclone’s ecosystem, allowing seamless use with existing cloud storage configurations and advanced features like mounting encrypted remotes. Unlike Cryptomator or Boxcryptor, which often require separate interfaces or client applications, rclone crypt operates as a command-line tool, offering greater flexibility for automation and scripting. However, it lacks the user-friendly GUI of some alternatives.
What should I do if I forget the password for my rclone crypt remote?
If the password is forgotten, data becomes irretrievable, as rclone crypt does not store encryption keys. To prevent this, use a password manager to securely save the password. If access is lost, the encrypted files cannot be decrypted, and recovery is not supported by the tool. Always verify the password before initiating critical operations.