
Una herramienta de cifrado simple, moderna y segura (y biblioteca Go) con claves explícitas pequeñas, sin opciones de configuración y componibilidad al estilo UNIX.
age es una herramienta de cifrado de archivos, un formato y una biblioteca Go simples, modernos y seguros.
Cuenta con claves explícitas pequeñas, soporte post-cuántico, sin opciones de configuración y componibilidad al estilo UNIX.
$ age-keygen -o key.txt
Public key: age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p
$ tar cvz ~/data | age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p > data.tar.gz.age
$ age --decrypt -i key.txt data.tar.gz.age > data.tar.gz
📜 La especificación del formato está en age-encryption.org/v1. age fue diseñado por @benjojo y @FiloSottile.
🦀 Una implementación alternativa e interoperable en Rust está disponible en github.com/str4d/rage.
🌍 Typage es una implementación en TypeScript. Funciona en el navegador, Node.js, Deno y Bun.
🔑 Los tokens PIV de hardware como los YubiKeys son compatibles mediante el plugin age-plugin-yubikey.
✨ Para más plugins, implementaciones, herramientas e integraciones, consulta la lista awesome age.
💬 El autor lo pronuncia [aɡe̞] con una g fuerte, como GIF, y siempre se escribe en minúsculas.
| Homebrew (macOS o Linux) |
brew install age
|
| MacPorts |
port install age
|
| Windows |
winget install --id FiloSottile.age
|
| Alpine Linux v3.15+ |
apk add age
|
| Arch Linux |
pacman -S age
|
| Debian 12+ (Bookworm) |
apt install age
|
| Debian 11 (Bullseye) |
apt install age/bullseye-backports
(habilita los backports para age v1.0.0+)
|
| Fedora 33+ |
dnf install age
|
| Gentoo Linux |
emerge app-crypt/age
|
| Guix System |
guix package -i age
|
| NixOS / Nix |
nix-env -i age
|
| openSUSE Tumbleweed |
zypper install age
|
| Ubuntu 22.04+ |
apt install age
|
| Void Linux |
xbps-install age
|
| FreeBSD |
pkg install age (security/age)
|
| OpenBSD 6.7+ |
pkg_add age (security/age)
|
| Chocolatey (Windows) |
choco install age.portable
|
| Scoop (Windows) |
scoop bucket add extras && scoop install age
|
En Windows, Linux, macOS y FreeBSD puedes usar los binarios precompilados.
Si descargas los binarios precompilados, puedes verificar sus pruebas Sigsum.
Si tu sistema tiene una versión compatible de Go, puedes compilar desde el código fuente.
go install filippo.io/age/cmd/...@latest
Se agradece la ayuda de nuevos empaquetadores.
Para la documentación completa, lee la página de manual de age(1).
Usage:
age [--encrypt] (-r RECIPIENT | -R PATH)... [--armor] [-o OUTPUT] [INPUT]
age [--encrypt] --passphrase [--armor] [-o OUTPUT] [INPUT]
age --decrypt [-i PATH]... [-o OUTPUT] [INPUT]
Options:
-e, --encrypt Encrypt the input to the output. Default if omitted.
-d, --decrypt Decrypt the input to the output.
-o, --output OUTPUT Write the result to the file at path OUTPUT.
-a, --armor Encrypt to a PEM encoded format.
-p, --passphrase Encrypt with a passphrase.
-r, --recipient RECIPIENT Encrypt to the specified RECIPIENT. Can be repeated.
-R, --recipients-file PATH Encrypt to recipients listed at PATH. Can be repeated.
-i, --identity PATH Use the identity file at PATH. Can be repeated.
--version Print the version.
INPUT defaults to standard input, and OUTPUT defaults to standard output.
If OUTPUT exists, it will be overwritten.
RECIPIENT can be an age public key generated by age-keygen ("age1...")
or an SSH public key ("ssh-ed25519 AAAA...", "ssh-rsa AAAA...").
Recipient files contain one or more recipients, one per line. Empty lines
and lines starting with "#" are ignored as comments. "-" may be used to
read recipients from standard input.
Identity files contain one or more secret keys ("AGE-SECRET-KEY-1..."),
one per line, or an SSH key. Empty lines and lines starting with "#" are
ignored as comments. Passphrase encrypted age files can be used as
identity files. Multiple key files can be provided, and any unused ones
will be ignored. "-" may be used to read identities from standard input.
When --encrypt is specified explicitly, -i can also be used to encrypt to an
identity file symmetrically, instead or in addition to normal recipients.
Los archivos se pueden cifrar para múltiples destinatarios repitiendo -r/--recipient. Cada destinatario podrá descifrar el archivo.
$ age -o example.jpg.age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p \
-r age1lggyhqrw2nlhcxprm67z43rta597azn8gknawjehu9d9dl0jq3yqqvfafg example.jpg