forked from keepassxreboot/keepassxc
-
Notifications
You must be signed in to change notification settings - Fork 0
/
keepassxc-cli.1
274 lines (178 loc) · 10.2 KB
/
keepassxc-cli.1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
.TH KEEPASSXC-CLI 1 "Jan 04, 2020"
.SH NAME
keepassxc-cli \- command line interface for the \fBKeePassXC\fP password manager.
.SH SYNOPSIS
.B keepassxc-cli
.I command
.B [
.I options
.B ]
.SH DESCRIPTION
\fBkeepassxc-cli\fP is the command line interface for the \fBKeePassXC\fP password manager. It provides the ability to query and modify the entries of a KeePass database, directly from the command line.
.SH COMMANDS
.IP "\fBadd\fP [options] <database> <entry>"
Adds a new entry to a database. A password can be generated (\fI-g\fP option), or a prompt can be displayed to input the password (\fI-p\fP option).
The same password generation options as documented for the generate command can be used when the \fI-g\fP option is set.
.IP "\fBanalyze\fP [options] <database>"
Analyzes passwords in a database for weaknesses.
.IP "\fBclip\fP [options] <database> <entry> [timeout]"
Copies an attribute or the current TOTP (if the \fI-t\fP option is specified) of a database entry to the clipboard. If no attribute name is specified using the \fI-a\fP option, the password is copied. If multiple entries with the same name exist in different groups, only the attribute for the first one is copied. For copying the attribute of an entry in a specific group, the group path to the entry should be specified as well, instead of just the name. Optionally, a timeout in seconds can be specified to automatically clear the clipboard.
.IP "\fBclose\fP"
In interactive mode, closes the currently opened database (see \fIopen\fP).
.IP "\fBdb-create\fP [options] <database>"
Creates a new database with a password and/or a key file. The key file will be created if the file that is referred to does not exist. If both the key file and password are empty, no database will be created.
.IP "\fBdb-info\fP [options] <database>"
Show a database's information.
.IP "\fBdiceware\fP [options]"
Generates a random diceware passphrase.
.IP "\fBedit\fP [options] <database> <entry>"
Edits a database entry. A password can be generated (\fI-g\fP option), or a prompt can be displayed to input the password (\fI-p\fP option).
The same password generation options as documented for the generate command can be used when the \fI-g\fP option is set.
.IP "\fBestimate\fP [options] [password]"
Estimates the entropy of a password. The password to estimate can be provided as a positional argument, or using the standard input.
.IP "\fBexit\fP"
Exits interactive mode. Synonymous with \fIquit\fP.
.IP "\fBexport\fP [options] <database>"
Exports the content of a database to standard output in the specified format (defaults to XML).
.IP "\fBgenerate\fP [options]"
Generates a random password.
.IP "\fBhelp\fP [command]"
Displays a list of available commands, or detailed information about the specified command.
.IP "\fBimport\fP [options] <xml> <database>"
Imports the contents of an XML database to the target database.
.IP "\fBlocate\fP [options] <database> <term>"
Locates all the entries that match a specific search term in a database.
.IP "\fBls\fP [options] <database> [group]"
Lists the contents of a group in a database. If no group is specified, it will default to the root group.
.IP "\fBmerge\fP [options] <database1> <database2>"
Merges two databases together. The first database file is going to be replaced by the result of the merge, for that reason it is advisable to keep a backup of the two database files before attempting a merge. In the case that both databases make use of the same credentials, the \fI--same-credentials\fP or \fI-s\fP option can be used.
.IP "\fBmkdir\fP [options] <database> <group>"
Adds a new group to a database.
.IP "\fBmv\fP [options] <database> <entry> <group>"
Moves an entry to a new group.
.IP "\fBopen\fP [options] <database>"
Opens the given database in a shell-style interactive mode. This is useful for performing multiple operations on a single database (e.g. \fIls\fP followed by \fIshow\fP).
.IP "\fBquit\fP"
Exits interactive mode. Synonymous with \fIexit\fP.
.IP "\fBrm\fP [options] <database> <entry>"
Removes an entry from a database. If the database has a recycle bin, the entry will be moved there. If the entry is already in the recycle bin, it will be removed permanently.
.IP "\fBrmdir\fP [options] <database> <group>"
Removes a group from a database. If the database has a recycle bin, the group will be moved there. If the group is already in the recycle bin, it will be removed permanently.
.IP "\fBshow\fP [options] <database> <entry>"
Shows the title, username, password, URL and notes of a database entry. Can also show the current TOTP. Regarding the occurrence of multiple entries with the same name in different groups, everything stated in the \fIclip\fP command section also applies here.
.SH OPTIONS
.SS "General options"
.IP "\fB--debug-info\fP"
Displays debugging information.
.IP "\fB-k\fP, \fB--key-file\fP <path>"
Specifies a path to a key file for unlocking the database. In a merge operation this option, is used to specify the key file path for the first database.
.IP "\fB--no-password\fP"
Deactivates the password key for the database.
.IP "\fB-y\fP, \fB--yubikey\fP <slot>"
Specifies a yubikey slot for unlocking the database. In a merge operation this option is used to specify the yubikey slot for the first database.
.IP "\fB-q\fP, \fB--quiet\fP <path>"
Silences password prompt and other secondary outputs.
.IP "\fB-h\fP, \fB--help\fP"
Displays help information.
.IP "\fB-v\fP, \fB--version\fP"
Displays the program version.
.SS "Merge options"
.IP "\fB-d\fP, \fB--dry-run\fP <path>"
Prints the changes detected by the merge operation without making any changes to the database.
.IP "\fB--key-file-from\fP <path>"
Sets the path of the key file for the second database.
.IP "\fB--no-password-from\fP"
Deactivates password key for the database to merge from.
.IP "\fB--yubikey-from\fP <slot>"
Yubikey slot for the second database.
.IP "\fB-s\fP, \fB--same-credentials\fP"
Uses the same credentials for unlocking both databases.
.SS "Add and edit options"
The same password generation options as documented for the generate command can be used
with those 2 commands when the -g option is set.
.IP "\fB-u\fP, \fB--username\fP <username>"
Specifies the username of the entry.
.IP "\fB--url\fP <url>"
Specifies the URL of the entry.
.IP "\fB-p\fP, \fB--password-prompt\fP"
Uses a password prompt for the entry's password.
.IP "\fB-g\fP, \fB--generate\fP"
Generates a new password for the entry.
.SS "Edit options"
.IP "\fB-t\fP, \fB--title\fP <title>"
Specifies the title of the entry.
.SS "Estimate options"
.IP "\fB-a\fP, \fB--advanced\fP"
Performs advanced analysis on the password.
.SS "Analyze options"
.IP "\fB-H\fP, \fB--hibp\fP <filename>"
Checks if any passwords have been publicly leaked, by comparing against the given
list of password SHA-1 hashes, which must be in "Have I Been Pwned" format. Such
files are available from https://haveibeenpwned.com/Passwords; note that they
are large, and so this operation typically takes some time (minutes up to an
hour or so).
.SS "Clip options"
.IP "\fB-a\fP, \fB--attribute\fP"
Copies the specified attribute to the clipboard. If no attribute is specified,
the password attribute is the default. For example, "\fI-a\fP username" would
copy the username to the clipboard. [Default: password]
.IP "\fB-t\fP, \fB--totp\fP"
Copies the current TOTP instead of the specified attribute to the clipboard.
Will report an error if no TOTP is configured for the entry.
.SS "Create options"
.IP "\fB-k\fP, \fB--set-key-file\fP <path>"
Set the key file for the database.
.IP "\fB-p\fP, \fB--set-password\fP"
Set a password for the database.
.IP "\fB-t\fP, \fB--decryption-time\fP <time>"
Target decryption time in MS for the database.
.SS "Show options"
.IP "\fB-a\fP, \fB--attributes\fP <attribute>..."
Shows the named attributes. This option can be specified more than once,
with each attribute shown one-per-line in the given order. If no attributes are
specified and \fI-t\fP is not specified, a summary of the default attributes is given.
Protected attributes will be displayed in clear text if specified explicitly by this option.
.IP "\fB-s\fP, \fB--show-protected\fP"
Shows the protected attributes in clear text.
.IP "\fB-t\fP, \fB--totp\fP"
Also shows the current TOTP, reporting an error if no TOTP is configured for
the entry.
.SS "Diceware options"
.IP "\fB-W\fP, \fB--words\fP <count>"
Sets the desired number of words for the generated passphrase. [Default: 7]
.IP "\fB-w\fP, \fB--word-list\fP <path>"
Sets the Path of the wordlist for the diceware generator. The wordlist must
have > 1000 words, otherwise the program will fail. If the wordlist has < 4000
words a warning will be printed to STDERR.
.SS "Export options"
.IP "\fB-f\fP, \fB--format\fP"
Format to use when exporting. Available choices are xml or csv. Defaults to xml.
.SS "List options"
.IP "\fB-R\fP, \fB--recursive\fP"
Recursively lists the elements of the group.
.IP "\fB-f\fP, \fB--flatten\fP"
Flattens the output to single lines. When this option is enabled, subgroups and subentries will be displayed with a relative group path instead of indentation.
.SS "Generate options"
.IP "\fB-L\fP, \fB--length\fP <length>"
Sets the desired length for the generated password. [Default: 16]
.IP "\fB-l\fP, \fB--lower\fP"
Uses lowercase characters for the generated password. [Default: Enabled]
.IP "\fB-U\fP, \fB--upper\fP"
Uses uppercase characters for the generated password. [Default: Enabled]
.IP "\fB-n\fP, \fB--numeric\fP"
Uses numbers characters for the generated password. [Default: Enabled]
.IP "\fB-s\fP, \fB--special\fP"
Uses special characters for the generated password. [Default: Disabled]
.IP "\fB-e\fP, \fB--extended\fP"
Uses extended ASCII characters for the generated password. [Default: Disabled]
.IP "\fB-x\fP, \fB--exclude\fP <chars>"
Comma-separated list of characters to exclude from the generated password. None is excluded by default.
.IP "\fB--exclude-similar\fP"
Exclude similar looking characters. [Default: Disabled]
.IP "\fB--every-group\fP"
Include characters from every selected group. [Default: Disabled]
.SH REPORTING BUGS
Bugs and feature requests can be reported on GitHub at https://github.com/keepassxreboot/keepassxc/issues.
.SH AUTHOR
This manual page was originally written by Manolis Agkopian <m.agkopian@gmail.com>,
and is maintained by the KeePassXC Team <team@keepassxc.org>.