lockbox

Lockbox CLI

Hand secrets and files to other people and their agents. Everything is encrypted on your machine first. These pages list every command.

Install

You need Node.js. Then install the CLI:

npm i -g @opslane/lockbox

Run lockbox with no arguments to see the built-in help.

Log in

Log in with your email. Lockbox emails you a 6-digit code. In a terminal, it asks for the code right away.

lockbox login you@example.com

Logging in also creates keys for this computer. Your private keys stay on this computer.

For agents. When there's no terminal to type into, the CLI prints: Ask your user for the 6-digit code, then run: lockbox login --code <code>. The agent asks you for the code, then runs:

lockbox login --code 123456

If your account already has a device, this new one must be approved from an old one. See Devices.

Share files

lockbox share <files...>

Encrypts the files and prints a link. Without --to, anyone with the link can open it. The key is in the part after #, which browsers never send to the server.

lockbox share report.html notes.pdf --to sam@acme.com --views 2 --expires 48h
FlagWhat it does
--to emailLock the share to this person. If they use Lockbox, only their approved devices can open it.
--to a@x.com,b@y.comSeveral people, up to 10 (or repeat --to). Each gets their own share and link, printed one per line as "email link". If any address fails a check, nothing is shared.
--views NHow many times it can be opened. Default 3 for files, up to 10.
--expires 24hHow long it lasts. Default 7 days for files, up to 30 days.
--note "..."A short note for the recipient. Encrypted like the files.
--jsonPrint the result as JSON, for scripts and agents.
--require-deviceRefuse if the recipient hasn't set up Lockbox yet, instead of warning.
--accept-new-keysContinue even though the recipient's devices changed since you last shared with them.

Recipient not set up yet? The CLI warns: Anyone with this link AND access to <their> inbox can open it. Add --require-device to refuse instead.

Recipient's devices changed? The CLI stops and asks you to check with them another way. If you expected the change, add --accept-new-keys.

Share a secret

lockbox share --secret-from .env:KEY --to email

Reads one value from a file and shares it. A secret always needs --to. The value is never printed.

lockbox share --secret-from .env:STRIPE_KEY --to priya@acme.com

Or pipe the value in and give it a name:

pbpaste | lockbox share --secret-stdin --name STRIPE_KEY --to priya@acme.com

Secrets default to 1 open within 24 hours. The same --views, --expires, --require-device and --accept-new-keys flags work here.

Open a link

lockbox open <link>

Decrypts on your machine. Files go to a folder. Secrets go into a file like .env, without being printed.

lockbox open https://lockbox.run/p/... --to .env
lockbox open https://lockbox.run/p/... --out ./downloads
FlagWhat it does
--out dirSave files into this folder. Without it, files go into a new lockbox- folder, so nothing lands next to your code by surprise.
--to .env[:NAME]Save a secret into this file. Add :NAME to choose the variable name.
--printShow the secret on screen instead. Avoid this in agent chats.
--overwriteReplace a file or variable that already exists.
--jsonPrint the result as JSON.
  • A secret needs --to or --print.
  • The CLI refuses risky variable names chosen by the sender, like NODE_OPTIONS, PATH or LD_*. To accept one, name it yourself: --to .env:NAME.
  • Values with ', $ or line breaks can't go into .env. Use --out to save them as a file.

Ask for a secret

lockbox request KEY --from email

Prints a link to send to the person who has the secret. When they answer, the value lands in .env. This is the safe way for an agent to say "I need the Stripe key".

lockbox request STRIPE_KEY --from priya@acme.com --wait
FlagWhat it does
--waitKeep running until they answer.
--timeout 30mHow long --wait waits. Default 30 minutes.
--to .env:NAMEWhere to save the answer. Default .env, under the same name.
--expires 24hHow long the request link stays open.

lockbox request --resume <id>

Collect an answer later. Only works on the computer that made the request. You can also save it somewhere else.

lockbox request --resume 3f2a... --to .env.local:STRIPE_KEY --overwrite

Or save it as a file with --out dir.

Answer a request

lockbox fill <link>

Encrypts your answer so only the person who asked can read it. Read the value from a file or from stdin.

lockbox fill https://lockbox.run/r/... --from-env .env:STRIPE_KEY
pbpaste | lockbox fill https://lockbox.run/r/... --stdin

Status and revoke

lockbox status

Lists your shares and requests: who they're for, opens used and left, and when they expire.

lockbox status

lockbox revoke <id>

Stops a share from being opened again. Copies already downloaded can't be recalled.

lockbox revoke 3f2a...

Devices

Each computer you log in from is a device with its own keys. A new device must be approved by one you already use.

lockbox devices [list]

lockbox devices

lockbox devices approve <id>

lockbox devices approve 7c1d...

lockbox devices remove <id>

lockbox devices remove 7c1d...

lockbox devices recover

Lost every device? Run this from a new one. It becomes active after 72 hours, unless it's cancelled from the email we send you.

lockbox devices recover

Account

lockbox whoami

lockbox whoami

lockbox logout

Removes this device from your account and deletes its keys. If it's your only device, the CLI stops you, since shares locked to you couldn't be opened. Add --force to go ahead.

lockbox logout

Limits and defaults

WhatLimit
Files, default3 opens, 7 days
Secrets, default1 open, 24 hours
Most opens10
Longest life30 days
File size25 MiB per file
Files per share20

Something not working? See Support.