claude-file-recovery
Recover files created and modified by Claude Code from its JSONL session transcripts — even if you lost track of them across sessions.
Claude Code stores a full log of every tool call in ~/.claude/projects/. This tool parses those transcripts, replays Write, Edit, and Read operations in order, and reconstructs the files so you can browse, search, and extract them.
Features
- Interactive TUI with fuzzy search and vim keybindings (j/k/g/G,
/to search) - Point-in-time recovery — reconstruct files at any historical snapshot, not just the latest
- Colored diff view showing how files changed over time (unified, full-context, and raw modes)
- Batch extraction — select multiple files and extract them all at once
- Fast scanning — parallel session parsing with orjson and fast-reject byte checks that skip ~77% of lines before parsing
- Symlink deduplication — detects aliased paths and merges them into canonical entries
- Smart-case search — case-sensitive only when your query contains uppercase (like ripgrep)
Installation
# Recommended
uv tool install claude-file-recovery
# Or with pipx
pipx install claude-file-recovery
# Or with pip
pip install claude-file-recovery
Requires Python 3.10+.
Quick Start
# Launch the interactive TUI (default command)
claude-file-recovery
# List all recoverable files
claude-file-recovery list-files
# Filter by pattern
claude-file-recovery list-files --filter '*.py'
# Export as CSV
claude-file-recovery list-files --filter '*.ts' --csv
# Extract files to disk
claude-file-recovery extract-files --output ./recovered --filter '*.py'
# Recover files as they were before a certain time
claude-file-recovery list-files --before '2025-02-20 14:00'
# Point to a different Claude data directory
claude-file-recovery --claude-dir /path/to/claude-backup
How It Works
-
Scan — Discovers all JSONL session files under
~/.claude/projects/and parses them in parallel using a thread pool. A fast-reject byte check skips progress and history-snapshot lines (~77% of all lines) before touching the JSON parser. -
Correlate — Links tool-use requests in assistant messages to their results in user messages via
tool_use_id. This is how file content (which only appears in results, not requests) gets attached to each operation. -
Reconstruct — Replays operations in chronological order per file path. Write ops set content, Edit ops apply string replacements, and Read ops capture snapshots. The
--beforeflag uses binary search to cut off at any point in time. -
Present — The TUI lets you browse all recovered files, search with fuzzy matching, view colored diffs between snapshots, and batch-extract to disk.
TUI Keybindings
| Key | Action |
|---|---|
j / k |
Move up/down |
g / G |
Jump to top/bottom |
/ |
Search |
Ctrl+R |
Cycle search mode (fuzzy / glob / regex) |
x or Space |
Toggle file selection |
Enter |
View file detail + diffs |
d |
Cycle diff mode (unified / full-context / raw) |
Ctrl+E |
Extract selected files |
q |
Back / quit |
Contributing
Contributions are welcome! Feel free to open an issue or submit a pull request.
License
MIT — Rikkert ten Klooster
Metadata
Release files for claude-file-recovery 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| claude_file_recovery-0.2.0.tar.gz | 2.1 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| claude_file_recovery-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 2.1 MB
Release files / claude_file_recovery-0.2.0.tar.gz
| Download URL | claude_file_recovery-0.2.0.tar.gz |
|---|---|
| Size | 2.1 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
955211bb52994c127f0a23d13ef9183aa52527f2dc19a1930e792c18a25ddfd5
|
|
BLAKE2b-256 checksum How to use checksums |
e76a2f79edfc7f70a36cc684403e692cd7520962b233d0e64db843eec4713003
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 27, 2026.
Transparency logRelease files / claude_file_recovery-0.2.0-py3-none-any.whl
| Download URL | claude_file_recovery-0.2.0-py3-none-any.whl |
|---|---|
| Size | 43.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
616c228c026478da20a7927bdcdc1ca150b87eaa2156f8e1639e03ea0cbef93e
|
|
BLAKE2b-256 checksum How to use checksums |
cb1fd58f845eb2b8eb257623baa9f2985893d16d958dc30ffd0db70554503f13
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 27, 2026.
Transparency log