Where Does pass Store Passwords?
pass keeps GPG encrypted files in ~/.password-store. The tree, .gpg-id, and PASSWORD_STORE_DIR.
Last updated
pass stores each password as a GPG encrypted file inside ~/.password-store, mirroring folder names to entry paths. A .gpg-id file at the root (or per subfolder) records which keys can decrypt what sits below it. Extensions live in .extensions inside the store.
The whole tree is designed for git: pass git init turns it into a repo with per change commits. Relocate with PASSWORD_STORE_DIR. Back up the folder plus your GPG secret key; the .gpg files alone decrypt nowhere without it.
Where pass stores this, by platform
~/.password-store
One .gpg file per entry plus .gpg-id key map. PASSWORD_STORE_DIR relocates it. Pair with GPG agent to avoid per file passphrase prompts.
Frequently asked questions
how do i back up pass passwords
Copy ~/.password-store (ideally via its git remote) and export your GPG secret key separately. Either half alone is useless by design; keep both in different places.
how do i move the password store
Set PASSWORD_STORE_DIR to the new path or move ~/.password-store there. Subfolder .gpg-id files re encrypt their trees to different keys when migrating teams.
Notice an outdated path? Let us know.