Encrypt from the command line (clavis-cli)

clavis-cli does what the app does — same vaults, same file format — from a terminal, for scripts and scheduled backups. The Windows installer adds it to your PATH, so it works in any new PowerShell or Command Prompt window. On Linux it's at /opt/clavis/bin/clavis-cli.

Windows PowerShell
PS C:\Users\Alex> clavis-cli encrypt Reports
Password:
encrypted  Reports\Board minutes.docx  ->  4d40b068-ab83-4ecb-8868-c9512cceee10.enc
encrypted  Reports\Q3 sales.xlsx  ->  deb63b14-5ad4-4631-918f-b71617bcb7a0.enc
2 files.

PS C:\Users\Alex> clavis-cli list Reports
Password:
Board minutes.docx	4d40b068-ab83-4ecb-8868-c9512cceee10.enc
Q3 sales.xlsx	deb63b14-5ad4-4631-918f-b71617bcb7a0.enc

PS C:\Users\Alex> clavis-cli verify Reports
Password:
ok         Reports\4d40b068-ab83-4ecb-8868-c9512cceee10.enc  (Board minutes.docx, 8.8 KB)
ok         Reports\deb63b14-5ad4-4631-918f-b71617bcb7a0.enc  (Q3 sales.xlsx, 7.3 KB)
2 files.

Commands

CommandWhat it does
clavis-cli encrypt FILES…Encrypt files or folders (originals are securely deleted)
clavis-cli decrypt FILES…Decrypt .enc files or folders
clavis-cli verify [FILES…]Check encrypted files are intact (current folder if none given)
clavis-cli list [FOLDER]Show the real names of .enc files
clavis-cli helpAll commands and options

Options: --vault NAME · --key-file PATH · --keep (keep the originals) · --out DIR · --password-stdin · --quiet. Wildcards like *.docx work in cmd.exe too.

Passwords in scripts

clavis-cli asks for the password on the console, hidden. For scripts, pipe it in with --password-stdin. It never accepts a password as an argument: arguments are visible to other programs and end up in your shell history.

Exit codes

0 success · 1 some files failed · 2 usage error · 3 needs Clavis Premium · 4 wrong password or key file. Command-line runs show up in Activity too.

Can't find what you need? All help articles · Email us