Purse is a free, open source identity & access management (iam) project written in Shell and released under MIT. It has 615 GitHub stars, 43 forks and 0 open issues, and was last pushed 2 months ago. On this registry it ranks #54 of 56 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is Purse?

Purse is a Bash script that stores passwords and secrets in GnuPG-encrypted files, unlocking them with a YubiKey instead of a passphrase, for people who manage their own credentials on the command line.

What it is

Purse is a shell script written in Bash and released under the MIT licence, based on the author's earlier tool drduh/pwd.sh. Where pwd.sh relies on symmetric, passphrase-based authentication, Purse uses GnuPG asymmetric (public-key) authentication: plug in the YubiKey, enter the PIN, touch the token, and the secrets become available. A GnuPG identity is a prerequisite, and the project points to drduh/YubiKey-Guide for setting one up. Secrets live in encrypted text files on the local filesystem, with an index file named purse.index tracking what is stored.

The concrete problem it solves is the burden of remembering and typing a master passphrase for every secret. Because authentication is delegated to a hardware token, no passphrase is needed at all, and the material never sits decrypted on disk beyond a copy placed in the clipboard or shown on screen for a limited time. Secrets are kept under revision control by epoch timestamp, so an older password can still be retrieved rather than being silently overwritten. For privacy, the recipient key ID is deliberately kept out of metadata through the GnuPG throw-keyids option.

Key capabilities

  • Five interactive or command-line operations: w to create a secret, r to access one, l to list all secrets, b to create a backup archive, and h to print the help text.
  • Password generation with a configurable default length (PURSE_LEN, default 14) and a configurable character set (PURSE_CHARS, default [:alnum:]!?@#$%^&*();:+=), for example ./purse.sh w userName 20.
  • Revision history in which every secret is stored with an epoch timestamp; the newest version is copied to the clipboard on read, and a specific version can be read with ./purse.sh r userName@1574723600.
  • Clipboard handling with an auto-clear delay (PURSE_TIME, default 10 seconds), a selectable clipboard command such as xclip or pbcopy on macOS, and a PURSE_DEST option that sends output to screen instead.
  • Backup and restore: ./purse.sh b writes an archive named purse.$hostname.$today.tar, restorable with tar xvf purse*tar, and PURSE_DAILY creates a daily archive on write.
  • Optional index encryption through PURSE_ENCIX, which requires two separate YubiKey touches for the distinct decryption operations.
  • Tunable behaviour through environment variables in the shell rc file, including PURSE_COPY, PURSE_ECHO, PURSE_SAFE, PURSE_INDEX, and PURSE_COMMENT, alongside recommended GnuPG options from drduh/config gpg.conf.

Who uses it and how

  • Developers and system administrators who already carry a YubiKey and want credentials retrievable at the terminal without typing a master password.
  • Individuals running a fully local secret store on Linux with xclip, passing clipboard arguments such as -i -selection clipboard through PURSE_CLIP_ARGS.
  • macOS users switching the clipboard command to pbcopy and adjusting PURSE_TIME for their workflow.
  • People who symlink purse.sh into a directory on PATH and use it both interactively and as scripted commands in daily shell use.
  • Users who enable PURSE_DAILY so that a backup archive is produced automatically every time a secret is written.

Getting started

Purse is downloaded from the project's Releases page or fetched directly with wget https://github.com/drduh/Purse/blob/master/purse.sh, then run interactively as ./purse.sh or symlinked into a directory on PATH. A GnuPG identity provisioned on a YubiKey, following drduh/YubiKey-Guide, must exist before the script is usable.

How it compares

Purse sits alongside its sibling pwd.sh as the asymmetric counterpart to that tool's symmetric design, trading a memorised passphrase for hardware-token authentication and its PIN-and-touch flow. No paid products it replaces are named, so the relevant distinction within the registry is that it occupies a deliberately narrow, Bash-and-GnuPG niche rather than overlapping with the browser-integrated password managers.

When to use it — and when not

You must operate GnuPG, provision a YubiKey identity, and have a working clipboard command such as xclip or pbcopy, and the option to store unencrypted comments in the index and safe files means metadata privacy depends on leaving PURSE_COMMENT unset. It is a poor fit for anyone without a hardware token, for teams needing shared or role-based secret distribution, or for users who want a graphical interface. Note also that backups are plain tar archives that you are responsible for storing safely, and PURSE_ENCIX costs an extra YubiKey touch each time.

project readme (upstream, from github) — read inline

Purse is a Bash shell script based on drduh/pwd.sh.

Both programs use GnuPG to manage secrets in encrypted text files. Purse is based on asymmetric (public-key) authentication, while pwd.sh is based on symmetric (passphrase-based) authentication.

Purse eliminates the need for a passphrase: plug in the YubiKey, enter PIN and touch it to access secrets.

[!IMPORTANT] A GnuPG identity is required to use Purse - see drduh/YubiKey-Guide to set one up.

Install

Purse is available for download from Releases, or directly from GitHub:

wget https://github.com/drduh/Purse/blob/master/purse.sh

Use

Run the script interactively using ./purse.sh or symlink to a directory in PATH:

  • w to create a secret
  • r to access a secret
  • l to list all secrets
  • b to create a backup archive
  • h to print the help text

Options can also be passed on the command line.

Create a 20-character password for userName:

./purse.sh w userName 20

Read password for userName:

./purse.sh r userName

Passwords are stored with an epoch timestamp for revision control. The most recent version is copied to clipboard on read. To list all passwords or read a specific version of a password:

./purse.sh l

./purse.sh r userName@1574723600

Create an archive for backup:

./purse.sh b

Restore an archive from backup:

tar xvf purse*tar

Configure

See config/gpg.conf for recommended GnuPG options.

Several customizable options and features are also available, and can be configured with environment variables, for example in the shell rc file:

Variable Description Default Available options
PURSE_CLIP clipboard to use xclip pbcopy on macOS
PURSE_CLIP_ARGS arguments to pass to clipboard command unset (disabled) -i -selection clipboard to use primary (control-v) clipboard with xclip
PURSE_TIME seconds to clear password from clipboard/screen 10 any valid integer
PURSE_LEN default generated password length 14 any valid integer
PURSE_COPY copy password to clipboard before write unset (disabled) 1 or true to enable
PURSE_DAILY create daily backup archive on write unset (disabled) 1 or true to enable
PURSE_ENCIX encrypt index for additional privacy; 2 YubiKey touches will be required for separate decryption operations unset (disabled) 1 or true to enable
PURSE_COMMENT unencrypted comment to include in index and safe files unset any valid string
PURSE_CHARS character set for passwords [:alnum:]!?@#$%^&*();:+= any valid characters
PURSE_DEST password output destination, will set to screen without clipboard clipboard clipboard or screen
PURSE_ECHO character used to echo password input * any valid character
PURSE_SAFE safe directory name safe any valid string
PURSE_INDEX index file name purse.index any valid string
PURSE_BACKUP backup archive file name purse.$hostname.$today.tar any valid string

[!NOTE] For privacy, the recipient key ID is not included in metadata (using the GnuPG throw-keyids option).

Frequently asked questions

Is Purse free to use?

Purse is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does Purse do?

Manage secrets with Bash and GnuPG asymmetric encryption (YubiKey)

What is Purse written in?

Purse is primarily written in Shell. Its source is publicly available at https://github.com/drduh/Purse, and it has 615 GitHub stars.