gopass: passwords on the command line, with GPG and Git
gopass is a terminal password manager, encrypted with GPG and versioned with Git. It fits if you already live in the terminal.
Before you get started
What to expect
gopass is for people who are comfortable in a terminal. The site describes local storage encrypted with GnuPG, Git history, and separate add-ons for the browser or Git. It is not a family app with a home screen. A lost GPG key takes the secrets with it.
If the command already feels natural
gopass shows, copies and generates secrets from the terminal. The site gives examples such as gopass init and gopass generate. If those commands mean nothing to you, a vault with a graphical app will be safer in practice, even if you like its cryptographic model less.
Secrets stay on the machine, encrypted with GPG. The private key should not leave your devices. A protected backup of the key is part of setup, not an option for later.
Git syncs history, not understanding
The project uses Git to version the store and sync it between machines. You see the changes. You also need to understand what you push, and to which repository. A remote repository receives encrypted files. It must not receive the private key.
Sharing with other people exists, still under encryption. Add someone only if you know how to remove their access. A two-person test with a worthless secret is better than sharing production access directly.
The browser is an add-on, not the core
gopass-bridge is presented as a bridge to Firefox and Chrome. That is not the same thing as the command-line tool. Install the core, check one generate and one show, and only then autofill.
The site also mentions a Have I Been Pwned check through an add-on. That check sends information to a third-party service. Read what the add-on transmits before you turn it on.
From the provider
gopass
Downloads, compatibility and current terms.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.