IronStorage

IronStorage is a native client for pass and pass-otp.

pass stores entries as GPG-encrypted .gpg files in an ordinary directory tree (normally ~/.password-store), selects one or more recipients through .gpg-id files, and can track changes in Git. IronStorage keeps that format and the first-party pass command behavior. pass-otp compatibility adds otpauth:// secrets, OTP generation, and QR import/export.

The compatibility target includes init, list/show, find/grep, insert/edit, generate, remove, move/copy, and Git-backed commit and synchronization flows. Remote synchronization is HTTPS-only and uses server/application credentials kept in the operating system's secure store.

The central ironstorage Rust crate owns repository access, Git, GPG-compatible encryption and key handling, entries, OTP, synchronization, and platform-secure credential orchestration. Applications are presentation and interaction adapters only. Runtime subprocesses—including pass, git, and gpg—are forbidden; compatibility is implemented in Rust.

Candidate libraries and the pending project-license decision are tracked in DEPENDENCIES.md.

The shared TOML schema, path rules, editor precedence, and HTTPS remote format are documented in docs/configuration.md. The capability-scoped password-store layout and atomic mutation guarantees are documented in docs/repository-core.md. The embedded OpenPGP backend, exported-key model, secret-provider boundary, and GnuPG compatibility evidence are documented in docs/cryptography.md. Hierarchical .gpg-id resolution, signed policies, selective reencryption, and the rollback/commit contract are documented in docs/recipient-policies.md. Typed list/show/find/decrypted-grep models and secret presentation selection are documented in docs/read-domains.md.

Project layout

crates/storage  password-store domain and storage library
crates/apple    UniFFI boundary for Apple presentation code
apps/cli        pass-compatible command-line frontend
apps/tui        Ratatui frontend
apps/desktop    Iced desktop frontend for macOS, Windows, and Linux
apple/          iPhone, AutoFill, and watchOS presentation targets

The Apple project is generated with XcodeGen:

cd apple
xcodegen generate
Description
a rust implementation of the pass password storage format (git repol with gpg encrypted files).
Readme MIT 16 MiB
Languages
Rust 78.7%
Swift 17.7%
C 3.1%
HTML 0.3%
Python 0.2%