Where Does git-crypt Store Keys?
git-crypt keeps the repo key in .git-crypt/keys with encrypted blobs in git objects and .gitattributes rules.
Last updated
git-crypt encrypts marked files transparently inside normal Git objects. The .gitattributes file names which paths encrypt. The symmetric repo key lives in .git-crypt/keys with one file per trusted GPG user.
Unlocking copies the key into .git/git-crypt for the working copy. New clones stay locked until someone exports the key to them. Rotate by rotating the key and re encrypting, then push the result.
Where git-crypt stores this, by platform
[Repo]/.git-crypt/keys
One key file per trusted GPG identity. Working copies unlock into .git/git-crypt locally. Export keys to onboard teammates.
[Repo]/.git-crypt/keys
Same in repo layout on Mac. GPG identities come from your keyring. Lock with git-crypt lock before sharing the machine.
[Repo]\.git-crypt\keys
Same tree on Windows. GPG4Win identities work like any GPG setup. Keep key exports off shared drives.
Frequently asked questions
How do I onboard a teammate to git-crypt?
Add their GPG key with git-crypt add-gpg-user and push the result. They unlock on next pull. No secret travels outside encrypted channels.
Why do files show as gibberish on a fresh clone?
The clone is locked without the repo key. Import it with git-crypt unlock using an export or GPG access. Commits stay encrypted upstream regardless.
Notice an outdated path? Let us know.