Purse is a Bash script that stores passwords and secrets in GnuPG-encrypted files, unlocking them with a YubiKey instead of a passphrase, for people who manage their own credentials on the command line.
What it is
Purse is a shell script written in Bash and released under the MIT licence, based on the author's earlier tool drduh/pwd.sh. Where pwd.sh relies on symmetric, passphrase-based authentication, Purse uses GnuPG asymmetric (public-key) authentication: plug in the YubiKey, enter the PIN, touch the token, and the secrets become available. A GnuPG identity is a prerequisite, and the project points to drduh/YubiKey-Guide for setting one up. Secrets live in encrypted text files on the local filesystem, with an index file named purse.index tracking what is stored.
The concrete problem it solves is the burden of remembering and typing a master passphrase for every secret. Because authentication is delegated to a hardware token, no passphrase is needed at all, and the material never sits decrypted on disk beyond a copy placed in the clipboard or shown on screen for a limited time. Secrets are kept under revision control by epoch timestamp, so an older password can still be retrieved rather than being silently overwritten. For privacy, the recipient key ID is deliberately kept out of metadata through the GnuPG throw-keyids option.
Key capabilities
- Five interactive or command-line operations:
w to create a secret, r to access one, l to list all secrets, b to create a backup archive, and h to print the help text.
- Password generation with a configurable default length (
PURSE_LEN, default 14) and a configurable character set (PURSE_CHARS, default [:alnum:]!?@#$%^&*();:+=), for example ./purse.sh w userName 20.
- Revision history in which every secret is stored with an epoch timestamp; the newest version is copied to the clipboard on read, and a specific version can be read with
./purse.sh r userName@1574723600.
- Clipboard handling with an auto-clear delay (
PURSE_TIME, default 10 seconds), a selectable clipboard command such as xclip or pbcopy on macOS, and a PURSE_DEST option that sends output to screen instead.
- Backup and restore:
./purse.sh b writes an archive named purse.$hostname.$today.tar, restorable with tar xvf purse*tar, and PURSE_DAILY creates a daily archive on write.
- Optional index encryption through
PURSE_ENCIX, which requires two separate YubiKey touches for the distinct decryption operations.
- Tunable behaviour through environment variables in the shell rc file, including
PURSE_COPY, PURSE_ECHO, PURSE_SAFE, PURSE_INDEX, and PURSE_COMMENT, alongside recommended GnuPG options from drduh/config gpg.conf.
Who uses it and how
- Developers and system administrators who already carry a YubiKey and want credentials retrievable at the terminal without typing a master password.
- Individuals running a fully local secret store on Linux with
xclip, passing clipboard arguments such as -i -selection clipboard through PURSE_CLIP_ARGS.
- macOS users switching the clipboard command to
pbcopy and adjusting PURSE_TIME for their workflow.
- People who symlink
purse.sh into a directory on PATH and use it both interactively and as scripted commands in daily shell use.
- Users who enable
PURSE_DAILY so that a backup archive is produced automatically every time a secret is written.
Getting started
Purse is downloaded from the project's Releases page or fetched directly with wget https://github.com/drduh/Purse/blob/master/purse.sh, then run interactively as ./purse.sh or symlinked into a directory on PATH. A GnuPG identity provisioned on a YubiKey, following drduh/YubiKey-Guide, must exist before the script is usable.
How it compares
Purse sits alongside its sibling pwd.sh as the asymmetric counterpart to that tool's symmetric design, trading a memorised passphrase for hardware-token authentication and its PIN-and-touch flow. No paid products it replaces are named, so the relevant distinction within the registry is that it occupies a deliberately narrow, Bash-and-GnuPG niche rather than overlapping with the browser-integrated password managers.
When to use it — and when not
You must operate GnuPG, provision a YubiKey identity, and have a working clipboard command such as xclip or pbcopy, and the option to store unencrypted comments in the index and safe files means metadata privacy depends on leaving PURSE_COMMENT unset. It is a poor fit for anyone without a hardware token, for teams needing shared or role-based secret distribution, or for users who want a graphical interface. Note also that backups are plain tar archives that you are responsible for storing safely, and PURSE_ENCIX costs an extra YubiKey touch each time.
project readme (upstream, from github) — read inline
Purse is a Bash shell script based on drduh/pwd.sh.
Both programs use GnuPG to manage secrets in encrypted text files. Purse is based on asymmetric (public-key) authentication, while pwd.sh is based on symmetric (passphrase-based) authentication.
Purse eliminates the need for a passphrase: plug in the YubiKey, enter PIN and touch it to access secrets.
[!IMPORTANT]
A GnuPG identity is required to use Purse - see drduh/YubiKey-Guide to set one up.
Install
Purse is available for download from Releases, or directly from GitHub:
wget https://github.com/drduh/Purse/blob/master/purse.sh
Use
Run the script interactively using ./purse.sh or symlink to a directory in PATH:
w to create a secret
r to access a secret
l to list all secrets
b to create a backup archive
h to print the help text
Options can also be passed on the command line.
Create a 20-character password for userName:
./purse.sh w userName 20
Read password for userName:
./purse.sh r userName
Passwords are stored with an epoch timestamp for revision control. The most recent version is copied to clipboard on read. To list all passwords or read a specific version of a password:
./purse.sh l
./purse.sh r userName@1574723600
Create an archive for backup:
./purse.sh b
Restore an archive from backup:
tar xvf purse*tar
Configure
See config/gpg.conf for recommended GnuPG options.
Several customizable options and features are also available, and can be configured with environment variables, for example in the shell rc file:
[!NOTE]
For privacy, the recipient key ID is not included in metadata (using the GnuPG throw-keyids option).