Cryptex 2.0.0

dotnet tool install --global Cryptex --version 2.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local Cryptex --version 2.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=Cryptex&version=2.0.0
                    
nuke :add-package Cryptex --version 2.0.0
                    

Cryptex

A free command-line tool for encrypting and decrypting files and folders with a passphrase, using AES-256-GCM authenticated encryption.

No warranty. Cryptex is free software provided "as is". Booolean (booolean.com) and the contributors accept no responsibility or liability for any data loss or other damage arising from its use.

Installation

Requires the .NET 10 runtime or SDK.

dotnet tool install -g Cryptex

Usage

cryptex encrypt <inputFile> <outputFile> [options]   (alias: e)
cryptex decrypt <inputFile> <outputFile> [options]   (alias: d)
cryptex encrypt-folder <folderPath> [options]        (alias: ef)
cryptex decrypt-folder <folderPath> [options]        (alias: df)

Options:
  -p, --passphrase <pass>  Passphrase (visible in shell history and to other processes)
  -x, --delete-original    Delete source files after successful encryption
  -h, --help               Show help
  -v, --version            Show the version
cryptex encrypt report.pdf report.pdf.enc
cryptex decrypt report.pdf.enc report.pdf
cryptex encrypt-folder ./confidential
cryptex decrypt-folder ./confidential

encrypt-folder writes <name>.enc next to every file in the folder tree. decrypt-folder decrypts every .enc file to the same name without .enc and keeps the encrypted files.

Passphrase

Taken from the first of these that is set:

  1. --passphrase / -p (use with caution)
  2. The CRYPTEX_PASSPHRASE environment variable (recommended for scripts)
  3. An interactive prompt with hidden input

Things to know

  • Existing output files are overwritten without asking.
  • A lost passphrase cannot be recovered.
  • Markdown files (.md, .markdown) are never encrypted or decrypted.
  • Symbolic links are skipped by folder commands.
  • --delete-original is a normal delete, not a secure erase.
  • File names, sizes and folder structure are not hidden.

Configuration (.cryptex.yaml)

Read from the current working directory on every run:

# Delete each plaintext source after it has been encrypted successfully. Default: false.
deleteOriginalOnEncrypt: true

# Glob patterns, relative to the folder being processed, to skip in folder commands.
exclude:
  - "*.log"        # any depth
  - ".env"         # any depth
  - "secrets/**"   # everything below secrets

An invalid .cryptex.yaml stops Cryptex before any file is touched.

Security details

  • Cipher: AES-256-GCM with a 16-byte tag, in 64 KiB chunks; tampering, truncation and reordering are detected
  • Key derivation: PBKDF2-HMAC-SHA256 with 600,000 iterations and a random salt, then HKDF-SHA256 with a random per-file salt
  • Atomic output: files appear at their final path only when complete and authenticated

Cryptex 2 reads files written by Cryptex 1.x. Files written by Cryptex 2 cannot be read by Cryptex 1.x.

Full documentation: https://github.com/greatb/Cryptex

Disclaimer

Cryptex is free of charge and provided "as is", without warranty of any kind. To the fullest extent permitted by law, Booolean (booolean.com), the owner and the contributors are not responsible or liable for any loss of data or any other damage that results from, or is suspected to result from, using Cryptex. You use it at your own risk. Keep independent backups.

License

MIT

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
2.0.0 0 10/1/2026
1.1.2 470 5/7/2026
1.1.1 539 10/28/2025
1.1.0 230 10/28/2025
1.0.0 232 10/28/2025