Decrypt and Retrieve a Stored File with vault get
vault get decrypts one stored file, authenticating every object before anything is written. This guide picks the output path, explains the overwrite refusal and what gets restored.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about five minutes. You need a key and a stored file name from vault-list(1). It takes a shared lock, so it runs alongside other readers.
1. Retrieve into the current directory
$ vault get work/2026/report.pdfWith no output option the file is written to the base name of the stored name, here report.pdf, in the current directory.
2. Choose the output path
$ vault get work/2026/report.pdf -o /tmp/report.pdf
3. Trust what arrives
Nothing appears at the output path until every object has authenticated. A half-written or tampered file is never left behind. On success the stored mode and modification time are restored.
4. Handle the overwrite refusal
Safety boundary
get refuses to overwrite an existing file. Pick a new -o path, or move the old file aside yourself.
5. Check the result
$ ls -l /tmp/report.pdfUse --key and --vault if yours are not the defaults. Overview: vault(1).
Done means
- The stored name was taken from
vault list. - The output landed at the path you chose, with the mode and time restored.
- No existing file was overwritten.
- The decrypted copy is somewhere you are prepared to protect.