Command-Line Interface Manual.
Universal Vault is built for speed and scriptability. Master the command-line flags, batch automation workflows, and exit codes for seamless integration into server pipelines.
Quick Start in 30 Seconds
Download and extract the static binary for your architecture.
Encrypts instantly in-place without generating temporary files.
Restore plaintexts on Windows, Linux, macOS, or Android.
Command Reference
Detailed options, argument signatures, and real-world examples for each CLI subcommand.
vault lock
Encrypts files or directories in-place using AES-256-CTR and writes the authenticated 64-byte header and 104-byte recovery footer.
vault unlock
Decrypts a VAULTV05 file, validating HMAC-SHA256 authentication tags and handling crash checkpoints.
vault verify
Performs complete cryptographic integrity audit by calculating HMAC-SHA256 across all blocks without writing plaintext to disk.
vault inspect
Parses and prints the 64-byte binary header, format revision, salt, and iteration counter without requiring password.
vault bench
Executes hardware-calibrated benchmark testing AES-CTR throughput and PBKDF2 hash speed on host CPU.
Batch Processing & Server Scripts
Automate routine backup encryption across thousands of files with native shell scripts.
#!/usr/bin/env bash
set -euo pipefail
# Lock all database dumps recursively
find /var/backups -type f -name "*.sql" | while read -r file; do
echo "Encrypting: $file"
vault lock "$file" --password "$VAULT_SECRET" --rounds 600000
doneProcesses files sequentially with atomic 1 MB fsync write barriers.
# Encrypt all log archives in C:\Exports
Get-ChildItem -Path "C:\Exports" -Filter *.zip | ForEach-Object {
Write-Host "Locking: $($_.FullName)" -ForegroundColor Cyan
vault lock $_.FullName -p $env:VAULT_KEY
if ($LASTEXITCODE -ne 0) {
throw "Encryption failed on $($_.Name)"
}
}Checks process exit codes for zero-error pipeline execution.
Process Exit Codes
Deterministic status codes for shell condition checking and monitoring alerts.
| Code | Name | Description |
|---|---|---|
| 0 | SUCCESS | Operation completed successfully; all write barriers flushed. |
| 1 | AUTH_FAILURE | Invalid password supplied or HMAC-SHA256 authentication tag mismatch. |
| 2 | IO_ERROR | File permission denied, sector read failure, or read-only filesystem. |
| 3 | CORRUPT_HEADER | File does not begin with valid VAULTV05 magic signature. |
| 4 | INTERRUPTED | Process aborted (SIGINT/SIGTERM); checkpoint logged to footer. |
Sponsor Universal Vault or Feature Your Developer Tool
Reach security researchers, DevOps engineers, and privacy-conscious developers worldwide.
Your Files Belong to You.
Keep Them That Way.
Zero setup. Zero accounts. Zero telemetry. Download the binary, run a single command, and lock your files with mathematical certainty.
