How to encrypt files from the command line on Windows (and Linux)

Point-and-click is fine for a few files. For a nightly backup, a folder of exports or a deployment script, you want encryption you can script. Windows has no built-in command for file encryption that's easy to move between machines (cipher /e uses EFS, which is tied to your Windows account), so here's how to do it with clavis-cli, the command-line side of Clavis.

The basics

The Windows installer puts clavis-cli on your PATH. Open a new PowerShell or Command Prompt and:

Windows PowerShell
PS C:\Users\Alex> clavis-cli encrypt Reports
Password:
encrypted  Reports\Board minutes.docx  ->  e9c09fcd-2129-4319-a6a1-14ea7efbcf04.enc
encrypted  Reports\Q3 sales.xlsx  ->  89c7af5f-df0c-42e1-8a4b-a38c825b7b77.enc
2 files.

PS C:\Users\Alex> clavis-cli list Reports
Password:
Q3 sales.xlsx	89c7af5f-df0c-42e1-8a4b-a38c825b7b77.enc
Board minutes.docx	e9c09fcd-2129-4319-a6a1-14ea7efbcf04.enc

PS C:\Users\Alex> clavis-cli verify Reports
Password:
ok         Reports\89c7af5f-df0c-42e1-8a4b-a38c825b7b77.enc  (Q3 sales.xlsx, 7.3 KB)
ok         Reports\e9c09fcd-2129-4319-a6a1-14ea7efbcf04.enc  (Board minutes.docx, 8.8 KB)
2 files.

encrypt takes files and folders and securely deletes the originals (add --keep to keep them, --out DIR to write elsewhere). list shows the real names behind the random .enc names, and verify checks every file is intact. Wildcards such as *.xlsx work even in cmd.exe.

Passwords in scripts — the safe way

clavis-cli never accepts a password as a command-line argument: arguments are visible to every other program on the machine and saved in your shell history. Interactively, it asks with a hidden prompt. In scripts, pipe it in with --password-stdin, reading it from somewhere protected — for example the Windows Credential Manager, or a file only your account can read.

A scheduled encrypted backup

A simple pattern for Task Scheduler (or cron on Linux):

  1. Copy what you want to back up into a staging folder.
  2. clavis-cli encrypt --out D:\Backup\Encrypted Staging --password-stdin
  3. clavis-cli verify D:\Backup\Encrypted --password-stdin — and alert if the exit code isn't 0.

Exit codes make scripts easy: 0 ok, 1 some files failed, 2 usage error, 3 needs Clavis Premium, 4 wrong password or key file. Every run also appears in the app's Activity history.

On Linux

Install the .deb and use /opt/clavis/bin/clavis-cli the same way. The file format is identical, so a file encrypted on Linux opens on Windows with the same vault, and vice versa.

All commands and options: Encrypt from the command line (clavis-cli). The command line is part of Clavis Premium.

Try Clavis — free for Windows and Linux