How to encrypt files from the command line on Windows (and Linux)
Point-and-click is fine for a few files. For a nightly backup, a folder of exports or a deployment script, you want encryption you can
script. Windows has no built-in command for file encryption that's easy to move between machines (cipher /e uses EFS,
which is tied to your Windows account), so here's how to do it with clavis-cli, the command-line side of Clavis.
The basics
The Windows installer puts clavis-cli on your PATH. Open a new PowerShell or Command Prompt and:
PS C:\Users\Alex> clavis-cli encrypt Reports Password: encrypted Reports\Board minutes.docx -> e9c09fcd-2129-4319-a6a1-14ea7efbcf04.enc encrypted Reports\Q3 sales.xlsx -> 89c7af5f-df0c-42e1-8a4b-a38c825b7b77.enc 2 files. PS C:\Users\Alex> clavis-cli list Reports Password: Q3 sales.xlsx 89c7af5f-df0c-42e1-8a4b-a38c825b7b77.enc Board minutes.docx e9c09fcd-2129-4319-a6a1-14ea7efbcf04.enc PS C:\Users\Alex> clavis-cli verify Reports Password: ok Reports\89c7af5f-df0c-42e1-8a4b-a38c825b7b77.enc (Q3 sales.xlsx, 7.3 KB) ok Reports\e9c09fcd-2129-4319-a6a1-14ea7efbcf04.enc (Board minutes.docx, 8.8 KB) 2 files.
encrypt takes files and folders and securely deletes the originals (add --keep to keep them, --out DIR to write
elsewhere). list shows the real names behind the random .enc names, and verify checks every file is intact.
Wildcards such as *.xlsx work even in cmd.exe.
Passwords in scripts — the safe way
clavis-cli never accepts a password as a command-line argument: arguments are visible to every other program on the machine and saved in your shell
history. Interactively, it asks with a hidden prompt. In scripts, pipe it in with --password-stdin, reading it from somewhere protected —
for example the Windows Credential Manager, or a file only your account can read.
A scheduled encrypted backup
A simple pattern for Task Scheduler (or cron on Linux):
- Copy what you want to back up into a staging folder.
clavis-cli encrypt --out D:\Backup\Encrypted Staging --password-stdinclavis-cli verify D:\Backup\Encrypted --password-stdin— and alert if the exit code isn't 0.
Exit codes make scripts easy: 0 ok, 1 some files failed, 2 usage error, 3 needs Clavis Premium,
4 wrong password or key file. Every run also appears in the app's Activity history.
On Linux
Install the .deb and use /opt/clavis/bin/clavis-cli the same way. The file format is identical, so a file encrypted on Linux opens on
Windows with the same vault, and vice versa.
All commands and options: Encrypt from the command line (clavis-cli). The command line is part of Clavis Premium.