Skip to main content

obsideo-cli

Client-side encrypted storage: your content is encrypted on your machine before upload, so the platform cannot read it. File and folder names are encrypted too, by default (AES-SIV, keyed off your data key), so the platform sees opaque tokens rather than your filenames. Save, browse, and sync whatever you want from your terminal. Files are encrypted on your machine before they leave, so Obsideo's gateway, coordinator, and storage providers only ever see ciphertext. Your data lands on three providers (RF=3).

pip install obsideo-cli
obsideo login    # email -> 12 GB free
obsideo          # open the shell

Get started

$ obsideo login
Enter your email: you@example.com
Check your email for a verification code.
Enter verification code: 482913
You're all set. 12 GB free.

Login is handled by Obsideo's signup service at signup.obsideo.io: it emails you a one-time code and provisions your free tier. There's no password - just your email and a local key (see How it works).

Then either drop into the shell or run one-shot commands:

$ obsideo
obsideo:/ put ~/notes.txt
obsideo:/ ls
  [file] notes.txt  1.2 KB
obsideo:/ put ~/photos                       # a whole folder, uploaded recursively
obsideo:/ put "C:\My Files\tax return.pdf"   # paths with spaces: just quote them
obsideo:/ mkdir trip
obsideo:/ cd trip
obsideo:/trip/ put ~/cat.jpg
obsideo:/trip/ get cat.jpg ./downloaded.jpg

Commands

Command Description
obsideo login Sign up / log in with your email (12 GB free)
ls [path] List files and folders
cd <path> / pwd Move around / show location
put <local> [name] Encrypt + upload a file, or a whole folder (recursive). --no-encrypt to store as-is
get <remote> [local] Download + decrypt a file
rm <remote> Delete a file
mkdir <name> Create a folder
info <remote> Show object metadata
account Show storage used vs. your free quota
key status|export|import Back up or restore your encryption key (see below)
sync push|pull|status Sync your local folder with Obsideo
config [set k v] Show or change settings

Using it on more than one machine

Your files are encrypted with a key generated on your machine and held only there. A second machine that logs in without that key gets a new one, and your existing files stay unreadable on it (they show as ? in ls). Nobody can reissue the key for you, us included.

So before you need it:

obsideo key export          # prints the line to save, or: key export ~/obsideo-key.txt

Then on the other machine, before uploading anything:

obsideo key import OBSIDEO_DATA_KEY=...
obsideo key status          # same fingerprint on both = both can read the same files

key status prints a fingerprint, not the key, so it is safe to compare over any channel. Importing over an existing key needs --force, because it makes whatever the old key protected unreadable.

How it works

obsideo is a thin front-end over the shared obsideo_core layer (storage seam, signing identity, account crypto, email-OTP login). The mlvault ML extension builds on the same core - build the core once, two front-ends.

  • Encryption: AES-256-GCM with one account data key held locally at ~/.obsideo/data.key. Copy that key to another machine and everything is readable there; lose it and the data is unrecoverable by design. Back it up.
  • Signing identity: an Ed25519 key (~/.obsideo/signing.key) authorizes deletes (Principle 2 - the network can't delete your data without your signature). Generated locally; only the public half is ever sent.
  • Filename encryption: on by default (encrypt_names). Each path component (folder names + filename) is encrypted on your machine with AES-SIV - deterministic, so ls/cd still list under the encrypted prefix and the client decrypts the returned tokens back to real names. Turn it off with config set encrypt_names false (interop/debug; existing objects aren't migrated).
  • What Obsideo sees: ciphertext only - never a filename or a byte of content. Residual leaks (by design at this level): directory structure (depth, fan-out), object sizes (ciphertext ≈ plaintext), and object counts. Identical names encrypt to identical tokens, so Obsideo can tell two objects share a name - never what it is.

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

obsideo_cli-0.6.0.tar.gz (43.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

obsideo_cli-0.6.0-py3-none-any.whl (37.4 kB view details)

Uploaded Python 3

File details

Details for the file obsideo_cli-0.6.0.tar.gz.

File metadata

  • Download URL: obsideo_cli-0.6.0.tar.gz
  • Upload date:
  • Size: 43.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.7

File hashes

Hashes for obsideo_cli-0.6.0.tar.gz
Algorithm Hash digest
SHA256 830671861594c9efa34117370bf8920b7f9a65ff4ded3d019aad8737654fb501
MD5 089466c6761f05ceeda25ec058ac8785
BLAKE2b-256 f99cd7d5414d229d044213b8196e1ba20c5df1a3de1c220bdb49a1125678b329

See more details on using hashes here.

File details

Details for the file obsideo_cli-0.6.0-py3-none-any.whl.

File metadata

  • Download URL: obsideo_cli-0.6.0-py3-none-any.whl
  • Upload date:
  • Size: 37.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.7

File hashes

Hashes for obsideo_cli-0.6.0-py3-none-any.whl
Algorithm Hash digest
SHA256 2176dcdab870837b1b40bf0de83c008489c7982d4b07a2d6e6bbfee529658171
MD5 9aa715e58d70c2ce5ed75bf486d3c225
BLAKE2b-256 a618c8d8f7ebc8ace4d13d1d24ec9e899e27a5ff3f693daceda9560b93b3e3db

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.6.0 This release

2 files

0.5.0

2 files

0.4.0

2 files

0.3.1

2 files

0.3.0

2 files

0.2.9

2 files

0.2.8

2 files

0.2.7

2 files

0.2.6

2 files

0.2.5

2 files

0.2.4

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page