LinuxmacOSWindows

Where Does git-crypt Store Keys?

git-crypt keeps the repo key in .git-crypt/keys with encrypted blobs in git objects and .gitattributes rules.

Last updated

git-crypt encrypts marked files transparently inside normal Git objects. The .gitattributes file names which paths encrypt. The symmetric repo key lives in .git-crypt/keys with one file per trusted GPG user.

Unlocking copies the key into .git/git-crypt for the working copy. New clones stay locked until someone exports the key to them. Rotate by rotating the key and re encrypting, then push the result.

Where git-crypt stores this, by platform

Linux
[Repo]/.git-crypt/keys

One key file per trusted GPG identity. Working copies unlock into .git/git-crypt locally. Export keys to onboard teammates.

macOS
[Repo]/.git-crypt/keys

Same in repo layout on Mac. GPG identities come from your keyring. Lock with git-crypt lock before sharing the machine.

Windows
[Repo]\.git-crypt\keys

Same tree on Windows. GPG4Win identities work like any GPG setup. Keep key exports off shared drives.

Frequently asked questions

How do I onboard a teammate to git-crypt?

Add their GPG key with git-crypt add-gpg-user and push the result. They unlock on next pull. No secret travels outside encrypted channels.

Why do files show as gibberish on a fresh clone?

The clone is locked without the repo key. Import it with git-crypt unlock using an export or GPG access. Commits stay encrypted upstream regardless.

Notice an outdated path? Let us know.