
Uma ferramenta de criptografia simples, moderna e segura (e biblioteca Go) com chaves explícitas pequenas, sem opções de configuração e composibilidade ao estilo UNIX.
age é uma ferramenta de criptografia de arquivos, um formato e uma biblioteca Go simples, moderna e segura.
Ele apresenta chaves explícitas pequenas, suporte pós-quântico, nenhuma opção de configuração e composabilidade no estilo UNIX.
$ age-keygen -o key.txt
Public key: age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p
$ tar cvz ~/data | age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p > data.tar.gz.age
$ age --decrypt -i key.txt data.tar.gz.age > data.tar.gz
📜 A especificação do formato está em age-encryption.org/v1. O age foi projetado por @benjojo e @FiloSottile.
🦀 Uma implementação alternativa interoperável em Rust está disponível em github.com/str4d/rage.
🌍 Typage é uma implementação em TypeScript. Funciona no navegador, Node.js, Deno e Bun.
🔑 Tokens PIV de hardware, como YubiKeys, são suportados por meio do plugin age-plugin-yubikey.
✨ Para mais plugins, implementações, ferramentas e integrações, confira a lista awesome age.
💬 O autor pronuncia [aɡe̞] com um g forte, como GIF, e é sempre escrito em minúsculas.
| Homebrew (macOS ou Linux) |
brew install age
|
| MacPorts |
port install age
|
| Windows |
winget install --id FiloSottile.age
|
| Alpine Linux v3.15+ |
apk add age
|
| Arch Linux |
pacman -S age
|
| Debian 12+ (Bookworm) |
apt install age
|
| Debian 11 (Bullseye) |
apt install age/bullseye-backports
(ative os backports para age v1.0.0+)
|
| Fedora 33+ |
dnf install age
|
| Gentoo Linux |
emerge app-crypt/age
|
| Guix System |
guix package -i age
|
| NixOS / Nix |
nix-env -i age
|
| openSUSE Tumbleweed |
zypper install age
|
| Ubuntu 22.04+ |
apt install age
|
| Void Linux |
xbps-install age
|
| FreeBSD |
pkg install age (security/age)
|
| OpenBSD 6.7+ |
pkg_add age (security/age)
|
| Chocolatey (Windows) |
choco install age.portable
|
| Scoop (Windows) |
scoop bucket add extras && scoop install age
|
No Windows, Linux, macOS e FreeBSD, você pode usar os binários pré-compilados.
Se você baixar os binários pré-compilados, pode verificar suas provas Sigsum.
Se o seu sistema tiver uma versão suportada do Go, você pode compilar a partir do código-fonte.
go install filippo.io/age/cmd/...@latest
A ajuda de novos empacotadores é muito bem-vinda.
Para a documentação completa, leia a página de manual do age(1).
Usage:
age [--encrypt] (-r RECIPIENT | -R PATH)... [--armor] [-o OUTPUT] [INPUT]
age [--encrypt] --passphrase [--armor] [-o OUTPUT] [INPUT]
age --decrypt [-i PATH]... [-o OUTPUT] [INPUT]
Options:
-e, --encrypt Encrypt the input to the output. Default if omitted.
-d, --decrypt Decrypt the input to the output.
-o, --output OUTPUT Write the result to the file at path OUTPUT.
-a, --armor Encrypt to a PEM encoded format.
-p, --passphrase Encrypt with a passphrase.
-r, --recipient RECIPIENT Encrypt to the specified RECIPIENT. Can be repeated.
-R, --recipients-file PATH Encrypt to recipients listed at PATH. Can be repeated.
-i, --identity PATH Use the identity file at PATH. Can be repeated.
--version Print the version.
INPUT defaults to standard input, and OUTPUT defaults to standard output.
If OUTPUT exists, it will be overwritten.
RECIPIENT can be an age public key generated by age-keygen ("age1...")
or an SSH public key ("ssh-ed25519 AAAA...", "ssh-rsa AAAA...").
Recipient files contain one or more recipients, one per line. Empty lines
and lines starting with "#" are ignored as comments. "-" may be used to
read recipients from standard input.
Identity files contain one or more secret keys ("AGE-SECRET-KEY-1..."),
one per line, or an SSH key. Empty lines and lines starting with "#" are
ignored as comments. Passphrase encrypted age files can be used as
identity files. Multiple key files can be provided, and any unused ones
will be ignored. "-" may be used to read identities from standard input.
When --encrypt is specified explicitly, -i can also be used to encrypt to an
identity file symmetrically, instead or in addition to normal recipients.
Os arquivos podem ser criptografados para vários destinatários repetindo -r/--recipient. Cada destinatário poderá descriptografar o arquivo.
$ age -o example.jpg.age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p \
-r age1lggyhqrw2nlhcxprm67z43rta597azn8gknawjehu9d9dl0jq3yqqvfafg example.jpg
Vários destinatários também podem ser listados, um por linha, em um ou mais arquivos passados com a flag -R/--recipients-file.