get
Copies a secret to the clipboard, so it does not end up in the terminal scrollback.
sefy get <REFERENCE>| Option | Meaning |
|---|---|
--field <NAME> |
Which field of a record to take. Omit for the kind’s own secret. |
--stdout |
Print the secret instead of copying it. |
--clear-after <SECONDS> |
Clear the clipboard again after this long. Default 45; 0 leaves it. |
$ sefy get mailcopied password of "mail" to the clipboard; clearing in 45sclipboard clearedsefy get mail --field loginsefy get visa --field expirysefy get bank --clear-after 0 # leave it theresefy get bank --stdout | wl-copy # for pipes and scriptsWhich field, when you do not say
Section titled “Which field, when you do not say”--field takes any field the record carries, by name. Omitted, sefy takes the
one the kind is mostly about — its first secret field:
| Kind | Default field |
|---|---|
login |
password |
card |
number |
ssh-key |
private-key |
note |
the text |
A record whose fields are all public has no such default, and sefy says so
rather than guessing which value you meant. A note has no fields at all, so
--field on one is refused rather than quietly handing over its text. A name
the record does not carry is an error that lists what it does carry:
$ sefy get mail --field pinerror: "mail" has no "pin"; it holds: login, password, url, totp, notes--stdout is what scripts want, but the secret then lives in the scrollback and
— if the command is recalled — in the shell history.
The clipboard timeout
Section titled “The clipboard timeout”sefy waits for the timeout before exiting, so the command sits there until the secret is taken back off. It clears the clipboard only if the secret is still what is on it — anything copied in the meantime is left alone.
On Linux this works differently, because X11 and Wayland make the owning
process serve the clipboard: sefy keeps serving the value for the timeout and
then lets go, so the secret disappears when sefy exits either way. There
--clear-after 0 means “hold it for a long while” rather than “leave it
forever”, since letting go immediately would make the value unpastable.
A clipboard manager that keeps history gets the secret regardless — the timer clears the clipboard, not someone else’s copy of it.
Stored files
Section titled “Stored files”get will not hand back a file, not even with --stdout:
$ sefy get id_ed25519 --stdouterror: "id_ed25519" is a file; write it to disk with: sefy extract 3A key or a binary dumped into a terminal is a key in the scrollback, and pasting
one through the clipboard would corrupt it. Files leave through
extract.
Related
Section titled “Related”show— an item’s surroundings, without its secretsextract— stored files- Versions and compatibility — items a newer sefy wrote