Where Does pass Keep the Password Store?
Where the pass password manager keeps its encrypted store, GPG keys reference, and per entry metadata on Linux and macOS.
Last updated
pass keeps every password as its own GPG encrypted file inside one directory: ~/.password-store. Subfolders organize entries, and a .gpg-id file in each folder records which key encrypts it.
Because the store is plain files, the whole password manager backs up with cp or git. The catch is that the files are useless without the GPG secret key, so a migration must move both the store and the key. Lose the key and the backup is decorative. Companion tools like browserpass and pass-otp read the same tree, so they migrate with the folder copy.
Where pass stores this, by platform
~/.password-store
One .gpg file per entry plus .gpg-id key assignments and an optional .git history. The PASSWORD_STORE_DIR variable relocates the whole tree. Extensions keep their own state here too, for example .extensions for pass-otp seeds.
~/.password-store
Same layout as Linux, usually via Homebrew or MacPorts installs. GPG Suite versus command line GnuPG keychains can split keys across homes, so confirm which gpg binary pass calls when decryption fails.
Frequently asked questions
how do i move pass to a new key or machine
Run pass init with a new GPG key ID, then re encrypt: pass init <new-key> re encrypts every entry to the new key. Copy ~/.password-store to the new machine first, along with the secret key (gpg --export-secret-keys). Without the secret key the store is unreadable.
how are entries organized in password-store
Each entry is a separate .gpg file under ~/.password-store, so normal file tools work: cp to duplicate, rm to delete, git mv to reorganize. Multiline entries keep extra lines after the password, which is where usernames and notes conventionally go.
what is the gpg-id file in password-store
In a .gpg-id file inside the folder, naming the key that folder uses. Nested folders can each hold their own .gpg-id, which lets work and personal entries encrypt to different keys in one store. pass init --path writes these for you.
Notice an outdated path? Let us know.