sealbox

File and text encryption from the command line, with a one time mode.

JavaScriptMITGitHub

sealbox encrypts a file or a piece of text with a passphrase. It uses authenticated encryption, so it also detects when the data has been changed. There are no runtime dependencies, everything is built on the crypto module that ships with Node.js.

With --burn a file becomes one time. After the first successful decryption it is overwritten with random bytes and removed.

Features

  • scrypt turns the passphrase into a 256 bit key, slow on purpose so guessing is expensive
  • AES-256-GCM encryption, so any change to the file makes decryption fail
  • A new random salt and nonce for every file
  • One time files with --burn
  • No runtime dependencies, Node.js 18 or newer

Get started

You need Node.js 18 or newer.

git clone https://github.com/VincentBorgers/sealbox.git
cd sealbox
npm link
sealbox encrypt notes.txt

The full documentation is in the README.