Home / Alt manpages / vault-add(1)

  • vault-add(1)
  • User command
  • linux

Encrypt Files, Folders and URLs into a Vault with vault add

vault add turns a file, a directory or a downloaded URL into encrypted records inside the vault. This guide covers each of the three, folders inside the vault and the overwrite rule.

Allow about ten minutes. You need a key and an initialised vault. No elevated privileges are needed. Originals are left untouched, unlike vault-migrate(1).

1. Add a single file

The file is stored under its base name. Give a second argument to place it in a folder inside the vault:

$ vault add report.pdf
$ vault add report.pdf work/2026

Contents are cut into 4 MiB chunks, and the last one is padded to a bucket size so lengths do not leak.

2. Add a whole directory

A directory goes in recursively, keeping its structure beneath its own name:

$ vault add ./photos
$ vault add ./photos holidays

A directory named . or .. adds its contents directly, with no wrapping folder. Non-regular files (sockets, devices), the vault itself and the key are skipped.

3. Add a URL

An http:// or https:// URL is downloaded with a Chrome user agent and stored under the last element of its final path, after redirects. If there is none it uses the host name. Only a 200 response is accepted:

$ vault add https://example.com/paper.pdf papers

4. Mind the overwrite rule

Warning

A stored name that already exists is replaced without a prompt. Run vault list first if you are unsure whether a name is taken.

For a preview and confirmation step, vault-migrate(1) lists the names it would overwrite and asks first.

5. Check it landed

$ vault list work

Set VAULT_PASSPHRASE in the environment for unattended runs, and use --key or --vault to point at non-default locations. See vault(1) for the shared options.

Done means

  • The file, directory or URL appears in vault list.
  • Any overwrite of an existing name was intended.
  • The originals are still on disk, since add never deletes them.
  • URL downloads were only from sources you are allowed to copy.