How to Pass Passwords to 7-Zip in Scripts
When automating 7-Zip in automated pipelines, cron jobs, or batch files, handling password-protected archives requires non-interactive input to prevent the program from pausing execution to wait for user input. This guide details how 7-Zip processes passwords non-interactively using command-line parameters, how to fully automate extraction and compression without prompts, and the security considerations associated with each method.
The -p Switch
The primary way to pass a password to the 7-Zip command-line tool
(7z, 7za, or 7zr) is via the
-p switch. By supplying the password immediately following
-p without any space, 7-Zip consumes the credential
directly at launch and bypasses interactive console prompts.
Creating a password-protected archive:
7z a -t7z archive.7z /path/to/files -pSecretPassword123Extracting a password-protected archive:
7z x archive.7z -o/output/directory -pSecretPassword123 -y
Note: There must be no space between
-p and the password string. If a space is included, 7-Zip
treats -p as an instruction to prompt the user
interactively and considers the password text as a file target.
Preventing All Interactive Prompts
Providing a password is only part of ensuring non-interactive
execution. 7-Zip may still halt execution if files already exist or if
overwrite confirmation is needed. To guarantee fully non-interactive
runs, combine the password switch with the -y (assume Yes
on all queries) flag:
7z x backup.7z -o./extracted/ -p"SuperSecretPassword" -yEncrypting File Headers
When archiving sensitive data in the .7z format, file
names remain visible by default unless header encryption is enabled. To
encrypt both file contents and metadata non-interactively, add the
-mhe=on flag:
7z a secured.7z ./confidential_data/* -p"SecureKey" -mhe=onPassing Passwords via Environment Variables
Hardcoding passwords into scripts poses security risks. A safer pattern is to pass credentials dynamically using system environment variables, keeping sensitive values out of version-controlled script files.
Linux / macOS (Bash):
export ARCHIVE_PASS="dynamicPassword987"
7z a archive.7z ./data -p"$ARCHIVE_PASS"
unset ARCHIVE_PASSWindows (PowerShell):
$env:ARCHIVE_PASS = "dynamicPassword987"
& 7z.exe a archive.7z .\data "-p$env:ARCHIVE_PASS"
$env:ARCHIVE_PASS = $nullProcess Table Visibility and Alternatives
When passing passwords via the -p command-line switch,
the password becomes visible in the system process list (e.g., through
ps aux on Linux or Task Manager on Windows) for the
duration of the execution.
To mitigate process table exposure:
- Restrict Process Visibility: On Linux, mount the
/procfilesystem withhidepid=2to restrict users from viewing processes owned by other accounts. - Dedicated Automation Accounts: Run scripts under dedicated, unprivileged system accounts that other users cannot inspect.
- Piping via STDIN (Limitations): 7-Zip does not
natively support reading passwords directly from standard input
(
stdin) via the command-line utility; it reads passwords either via-parguments or from the active controlling terminal. Therefore, process separation and environment variable protection are the primary mitigation strategies.
Handling Exit Codes
In non-interactive scripts, monitor 7-Zip exit codes to detect password errors:
0: Success (no errors).1: Warning (e.g., non-fatal errors or locked files).2: Fatal error (typically returned on wrong passwords, CRC failures, or corrupted headers).7: Command-line syntax error.8: Insufficient memory.