How to Encrypt File Names in 7-Zip Command Line

This guide explains how to enable header encryption in the 7-Zip command-line interface to conceal file names and directory structures inside 7z archives. You will learn the exact switch required to activate this feature, how it pairs with standard password protection, and practical command examples for securing your compressed data.

The Header Encryption Switch: -mhe

The command line option that enables header encryption in 7-Zip is -mhe=on (or simply -mhe).

By default, 7-Zip encrypts only the contents of files when you apply a password, leaving file names, sizes, and directory structures visible to anyone who opens the archive. The -mhe switch encrypts the archive header, requiring users to enter the password before they can view the list of contained files.

Header encryption is supported exclusively by the 7z archive format. It is not supported by standard ZIP formats.


Basic Command Syntax

To use header encryption, combine the -mhe=on flag with the add command (a) and the password parameter (-p).

7z a archive.7z -pYourPassword -mhe=on file1.txt file2.pdf

Breakdown of Parameters:

  • a: Adds files to the archive.
  • archive.7z: The name of the target archive.
  • -pYourPassword: Specifies the encryption password directly. Note that there is no space between -p and the password string.
  • -mhe=on: Enables header encryption.

Practical Examples

1. Masking Password Input via Prompt

Hardcoding passwords in shell history can be a security risk. If you omit the password string after -p, 7-Zip prompts you to enter and confirm the password securely:

7z a secure_backup.7z -p -mhe=on /path/to/folder/

2. Compressing and Encrypting an Entire Directory

To compress an entire folder along with all subdirectories and hide all file names:

7z a -r confidential.7z -pSecretKey123 -mhe=on ./ConfidentialData/*

(The -r flag enables recursive directory processing).


Parameter Values

  • -mhe=on or -mhe: Turns header encryption on.
  • -mhe=off: Explicitly disables header encryption (the default behavior).