Skip to main content

loz - password manager

Project description

loz

Command line password manager.

Why?

You may ask why is there a need for another open source password manager. Here are some features that most currently available password managers lack and that loz is focusing on:

  • Designed for command line. Loz allows you to perform all tasks directly on the command line.

    • You can pipe the secrets out of it directly to files.
    • Bash completion is available for all commands and even domains/usernames.
    • Commands are entered directly without loading any custom loz console.
  • Asymmetric encryption. Need to quickly add new entry or generate a password? No problem. With asymmetric encryption, you don't need to type your master password each time you add new entry. It even makes no sense to have to do that, right? You already know what you are entering.

  • Single file storage. Lozfile contains all entries, secrets and encryption keys in a simple json format. You can just copy it over to another machine and continue where you left off.

Requirements

  • Python >= 3.10

Install

pip install loz

Setup bash completion

Add the following to your .bashrc or .profile:

eval "$(loz bash-completion)"

Alternatively generate a bash completion file in a directory specific for your system, e.g. for Debian, Ubuntu and Fedora:

loz bash-completion | sudo tee /etc/bash_completion.d/loz

Usage

Initialize lozfile

loz init - This is required first step that will generate storage file at default location ~/.loz. If you want to use a different location or separate storage file, you can specify that with loz -f path/to/lozfile [COMMAND] [OPTIONS], but then you always need to include that switch when using other commands.

You will be asked to enter the master password which will be required for decrypting your secrets. Read more about the lozfile, what it contains, what is being encrypting and what it's always revealing in the lozfile section of this doc.

Add secret

loz add mydomain.com username@email.com - After this you will be prompted to enter your secret in a multi-line prompt. Press Alt-Return to save.

If you want loz to generate a secret for you, just use loz make mydomain.com username@email.com instead. It will generate and save a new secret and print it out for you.

Read secret

loz get mydomain.com username@email.com - After this you will be prompted for the master password. Note that you can autocomplete name of domains and usernames by pressing Tab.

loz show mydomain.com will print all secrets for all usernames under selected domain.

List entries

loz ls will list domains and loz ls mydomain.com will list usernames under selected domain.

loz find searchword will list all domains and/or usernames that contain a word searchword.

Delete an entry

loz rm mydomain.com username@email.com will delete selected username. If that's the only username under selected domain, the whole domain will be removed. If you want to delete a domain with all usernames under it, just type loz rm mydomain.com.

Export/Import

loz export > backup.csv will export all secrets in a plain text csv file. You can import a backed up file with loz import backup.csv. It will ask you if you want to overwrite existing entries.

Change password

loz passwd will prompt you for old and new password. It will then generate new keys and re-encrypt all secrets.

Development

Clone the repository and create a virtual environment:

git clone git@gitlab.nul.one:mush/loz.git
cd loz
python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"

Running checks

# Lint
ruff check loz/ tests/

# Format check
ruff format --check loz/ tests/

# Type check
mypy loz/

# Tests with coverage
pytest

# Build and verify distribution
python -m build
twine check dist/*

Pre-commit hooks

pre-commit install
pre-commit run --all-files

Lozfile and encryption

Lozfile is the json storage of all secrets. It contains plaintext RSA public key and Fernet (password) encrypted private key as well. Public key is used in the background when you are entering or generating new secrets. Private key is useless without your master password, but weak password means weak encryption.

All secrets are encrypted with RSA 4096. This is slow for encryption and decryption, but allows the asymmetric approach and doesn't have a big performance impact on short secrets.

Password generation uses secrets.choice (the Python standard-library CSPRNG) to ensure cryptographic strength.

Compatibility

Backwards compatibility will be guaranteed for all lozfiles created with loz versions 0.1.0 and above. If there is a change in lozfile format, you may be prompted to update your lozfile.

WARNING

Lozfile is revealing domains and usernames. This is by design to enable autocomplete. Future versions of loz may offer full encryption option, but for now it's not available and it's not a focus. If you are concerned about privacy of your usernames, then loz is not for you!

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

loz-0.2.0.tar.gz (22.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

loz-0.2.0-py3-none-any.whl (15.7 kB view details)

Uploaded Python 3

File details

Details for the file loz-0.2.0.tar.gz.

File metadata

  • Download URL: loz-0.2.0.tar.gz
  • Upload date:
  • Size: 22.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for loz-0.2.0.tar.gz
Algorithm Hash digest
SHA256 fa88f972f318b06d05868076c24a2bdfb1c011bc035f060f4c492ac061d22e66
MD5 6aa0581b605d0f3149aee286d72a8eb3
BLAKE2b-256 0dc6c59982f422f8fbb0131b7ed84d3e873ff30d4d09892e3ed8c90db989c266

See more details on using hashes here.

File details

Details for the file loz-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: loz-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 15.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for loz-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 29da6546b71832678c09f764bebe829fc59b2f0bca15fc7f67eef754e11dd843
MD5 4ebb15fbf835879dcde3bdb2d46c5b85
BLAKE2b-256 b60825e032f8c62b7a2d4de0fc3c9b57f87f49170248e9a844027631ce7ed5d7

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page