Linux

Where Does pass Store Passwords?

pass keeps GPG encrypted files in ~/.password-store. The tree, .gpg-id, and PASSWORD_STORE_DIR.

Last updated

pass stores each password as a GPG encrypted file inside ~/.password-store, mirroring folder names to entry paths. A .gpg-id file at the root (or per subfolder) records which keys can decrypt what sits below it. Extensions live in .extensions inside the store.

The whole tree is designed for git: pass git init turns it into a repo with per change commits. Relocate with PASSWORD_STORE_DIR. Back up the folder plus your GPG secret key; the .gpg files alone decrypt nowhere without it.

Where pass stores this, by platform

Linux
~/.password-store

One .gpg file per entry plus .gpg-id key map. PASSWORD_STORE_DIR relocates it. Pair with GPG agent to avoid per file passphrase prompts.

Frequently asked questions

how do i back up pass passwords

Copy ~/.password-store (ideally via its git remote) and export your GPG secret key separately. Either half alone is useless by design; keep both in different places.

how do i move the password store

Set PASSWORD_STORE_DIR to the new path or move ~/.password-store there. Subfolder .gpg-id files re encrypt their trees to different keys when migrating teams.

Notice an outdated path? Let us know.