Lockbox CLI
Hand secrets and files to other people and their agents. Everything is encrypted on your machine first. These pages list every command.
Install
You need Node.js. Then install the CLI:
npm i -g @opslane/lockboxRun lockbox with no arguments to see the built-in help.
Log in
Log in with your email. Lockbox emails you a 6-digit code. In a terminal, it asks for the code right away.
lockbox login you@example.comLogging in also creates keys for this computer. Your private keys stay on this computer.
For agents. When there's no terminal to type into, the CLI prints: Ask your user for the 6-digit code, then run: lockbox login --code <code>. The agent asks you for the code, then runs:
lockbox login --code 123456If your account already has a device, this new one must be approved from an old one. See Devices.
Share files
lockbox share <files...>
Encrypts the files and prints a link. Without --to, anyone with the link can open it. The key is in the part after #, which browsers never send to the server.
lockbox share report.html notes.pdf --to sam@acme.com --views 2 --expires 48h| Flag | What it does |
|---|---|
--to email | Lock the share to this person. If they use Lockbox, only their approved devices can open it. |
--to a@x.com,b@y.com | Several people, up to 10 (or repeat --to). Each gets their own share and link, printed one per line as "email link". If any address fails a check, nothing is shared. |
--views N | How many times it can be opened. Default 3 for files, up to 10. |
--expires 24h | How long it lasts. Default 7 days for files, up to 30 days. |
--note "..." | A short note for the recipient. Encrypted like the files. |
--json | Print the result as JSON, for scripts and agents. |
--require-device | Refuse if the recipient hasn't set up Lockbox yet, instead of warning. |
--accept-new-keys | Continue even though the recipient's devices changed since you last shared with them. |
Recipient not set up yet? The CLI warns: Anyone with this link AND access to <their> inbox can open it. Add --require-device to refuse instead.
Recipient's devices changed? The CLI stops and asks you to check with them another way. If you expected the change, add --accept-new-keys.
Share a secret
lockbox share --secret-from .env:KEY --to email
Reads one value from a file and shares it. A secret always needs --to. The value is never printed.
lockbox share --secret-from .env:STRIPE_KEY --to priya@acme.comOr pipe the value in and give it a name:
pbpaste | lockbox share --secret-stdin --name STRIPE_KEY --to priya@acme.comSecrets default to 1 open within 24 hours. The same --views, --expires, --require-device and --accept-new-keys flags work here.
Open a link
lockbox open <link>
Decrypts on your machine. Files go to a folder. Secrets go into a file like .env, without being printed.
lockbox open https://lockbox.run/p/... --to .env
lockbox open https://lockbox.run/p/... --out ./downloads| Flag | What it does |
|---|---|
--out dir | Save files into this folder. Without it, files go into a new lockbox- |
--to .env[:NAME] | Save a secret into this file. Add :NAME to choose the variable name. |
--print | Show the secret on screen instead. Avoid this in agent chats. |
--overwrite | Replace a file or variable that already exists. |
--json | Print the result as JSON. |
- A secret needs
--toor--print. - The CLI refuses risky variable names chosen by the sender, like
NODE_OPTIONS,PATHorLD_*. To accept one, name it yourself:--to .env:NAME. - Values with
',$or line breaks can't go into.env. Use--outto save them as a file.
Ask for a secret
lockbox request KEY --from email
Prints a link to send to the person who has the secret. When they answer, the value lands in .env. This is the safe way for an agent to say "I need the Stripe key".
lockbox request STRIPE_KEY --from priya@acme.com --wait| Flag | What it does |
|---|---|
--wait | Keep running until they answer. |
--timeout 30m | How long --wait waits. Default 30 minutes. |
--to .env:NAME | Where to save the answer. Default .env, under the same name. |
--expires 24h | How long the request link stays open. |
lockbox request --resume <id>
Collect an answer later. Only works on the computer that made the request. You can also save it somewhere else.
lockbox request --resume 3f2a... --to .env.local:STRIPE_KEY --overwriteOr save it as a file with --out dir.
Answer a request
lockbox fill <link>
Encrypts your answer so only the person who asked can read it. Read the value from a file or from stdin.
lockbox fill https://lockbox.run/r/... --from-env .env:STRIPE_KEYpbpaste | lockbox fill https://lockbox.run/r/... --stdinStatus and revoke
lockbox status
Lists your shares and requests: who they're for, opens used and left, and when they expire.
lockbox statuslockbox revoke <id>
Stops a share from being opened again. Copies already downloaded can't be recalled.
lockbox revoke 3f2a...Devices
Each computer you log in from is a device with its own keys. A new device must be approved by one you already use.
lockbox devices [list]
lockbox deviceslockbox devices approve <id>
lockbox devices approve 7c1d...lockbox devices remove <id>
lockbox devices remove 7c1d...lockbox devices recover
Lost every device? Run this from a new one. It becomes active after 72 hours, unless it's cancelled from the email we send you.
lockbox devices recoverAccount
lockbox whoami
lockbox whoamilockbox logout
Removes this device from your account and deletes its keys. If it's your only device, the CLI stops you, since shares locked to you couldn't be opened. Add --force to go ahead.
lockbox logoutLimits and defaults
| What | Limit |
|---|---|
| Files, default | 3 opens, 7 days |
| Secrets, default | 1 open, 24 hours |
| Most opens | 10 |
| Longest life | 30 days |
| File size | 25 MiB per file |
| Files per share | 20 |
Something not working? See Support.