command-line tool

deny.sh from your terminal.

For developers and administrators: encrypt files on your own machine, manage local secrets and store control files in your password manager. The free command-line interface (CLI) needs no account for local encryption. Install below.

↓

Install

Instant npx deny-sh
Permanent npm install -g deny-sh

Commands

deny-sh protect Protect a wallet recovery phrase. The wizard checks BIP-39 word count, a recovery-phrase format. Each control file has its own matching password: real with real, decoy with decoy. Save the zip, then separate the files.
$ deny-sh protect
deny-sh encrypt Encrypt a message or file. Accepts flags or reads from stdin.
$ deny-sh encrypt -m "message" -p1 pass1 -p2 pass2 $ echo "secret" | deny-sh encrypt -p1 pass1 -p2 pass2 $ deny-sh encrypt -f secret.txt -p1 pass1 -p2 pass2
deny-sh decrypt Open the encrypted data (ciphertext) with both passwords and a control file, which selects the real message or your chosen fake (decoy). For protect-wizard files, use that control file’s matching password for both password flags.
$ deny-sh decrypt -i encrypted.bin -c control.dat -p1 pass1 -p2 pass2
deny-sh deny Add a chosen fake message to existing encrypted data by creating a decoy control file. For core encryption, keep the same password pair.
$ deny-sh deny -i encrypted.bin -p1 pass1 -p2 pass2 -m "decoy message" -o decoy-control.dat
deny-sh env protect / restore Protect .env files with deniable encryption. Automatically adds .deny/ to .gitignore.
$ deny-sh env protect .env $ deny-sh env restore .env.deny
deny-sh vault Local encrypted key-value store. Data is encrypted at rest under your vault password.
$ deny-sh vault set API_KEY sk-abc123 $ deny-sh vault get API_KEY $ deny-sh vault list
deny-sh init Create a .deny/ directory in the current project and configure the local settings file.
$ deny-sh init
deny-sh verify Run the full verification test suite locally. Confirms the crypto implementation matches the deny.sh reference vectors.
$ deny-sh verify
deny-sh status Show current config, files stored in .deny/, and API usage summary.
$ deny-sh status

Integrations

1Password

Sync control files to your 1Password vault via the op CLI. Push, pull, list, and check sync status.

deny-sh 1p push
deny-sh 1p pull
deny-sh 1p list
deny-sh 1p status

Bitwarden

Sync control files to Bitwarden via the bw CLI. Same push/pull/list/status interface as 1Password.

deny-sh bw push
deny-sh bw pull
deny-sh bw list
deny-sh bw status

Cloud backup

Encrypted archives to local disk, Google Drive, Dropbox, or S3. Configure once, back up anywhere.

deny-sh backup push
deny-sh backup pull
deny-sh backup list
deny-sh backup config

The .deny/ directory

By convention, deny-sh init creates a .deny/ directory in your project. This is where control files, encrypted backups, and local config live.

.deny/
  config.json          # local settings (API key, vault path)
  *.control.json       # control files for each encrypted item
  *.decoy.json         # decoy control files
  backups/             # local encrypted archive copies

Add .deny/*.control.json to your .gitignore. deny-sh env protect does this automatically for .env files.

Encryption dependencies

Open source
See the current package
Local
Review package dependencies

AES-256-CTR via node:crypto from the Node.js standard library, encrypts the data. Argon2id via hash-wasm, a WebAssembly module for password-based key derivation. The CLI itself adds commander for argument parsing.