key-crypt
Synopsis
Section titled “Synopsis”key-crypt [options] <input> [output]key-crypt -i <input> -o <output> [options]key-crypt --install | --uninstallDescription
Section titled “Description”Encrypts or decrypts a file or directory with OpenPGP, choosing the recipient/secret key from the connected smartcard (YubiKey etc.) by default. Direction is detected from the input: a GPG-encrypted file is decrypted (a tar payload is extracted into the output directory), anything else is encrypted. Run with --help for the full reference, including key selection and output-naming rules.
Arguments
Section titled “Arguments”-i, --input PATH |
Directory, file, or encrypted file to process |
-o, --output PATH |
Where to write the result |
-k, --key KEY |
Key ID or fingerprint (repeatable); overrides card detection |
-f, --force |
Overwrite an existing output |
-a, --archive |
Decrypt: keep the decrypted archive as-is instead of extracting |
-m, --mkdir |
Decrypt: create the output directory without asking |
-p, --preset |
Hands-off mode: same as --force --mkdir --remove |
-r, --remove |
Delete the input after a successful run --install Copy a standalone wrapper to ~/.local/bin and add “Open With” entries for .gpg files and folders. Must be the only argument. --uninstall Remove the installed wrapper and entries. Same rule. |
-h, --help |
Show this help message |
Exit Status
Section titled “Exit Status”0 |
Success |
1 |
Error (missing input, output exists, gpg or tar failed, no key) |
2 |
Bad usage |
--remove uses plain rm, not a secure wipe: on SSDs and copy-on-write filesystems the old data may remain recoverable. The input is only removed after the output is fully written; when decrypting, that means the encrypted file is deleted only once gpg has verified and decrypted it.
Example
Section titled “Example”key-crypt mydir # -> mydir.tgz.gpgkey-crypt mydir.tgz.gpg # -> extracted into mydir/key-crypt -k 0xDEADBEEF mydir # choose the recipient manuallykey-crypt --install # register the standalone wrapper + Open With entriesDependencies: gpg, tar
Classification: bypasses-shadow(rm), destructive