Password Protect Archives with 7-Zip Command Line

Securing your data by adding a password to an archive prevents unauthorized access to sensitive files. This guide details how to use the 7-Zip command-line utility to create encrypted archives, conceal filenames, and choose the right encryption standards for both .7z and .zip formats.

Basic Password Protection Syntax

To create an archive with a password, use the a (add) command combined with the -p switch followed immediately by your chosen password.

7z a archive_name.7z target_file_or_folder -pYourPassword
  • Replace archive_name.7z with your desired output filename.
  • Replace target_file_or_folder with the file or directory you want to compress.
  • Replace YourPassword with your chosen password. Do not leave a space between -p and the password string.

Hiding Password from Command Line History

Entering your password directly into the command line stores it in plain text within your shell or command prompt history. To enter the password securely via a hidden interactive prompt, specify the -p switch without a password value:

7z a archive_name.7z target_file_or_folder -p

The terminal will prompt you to enter and confirm the password before compression begins.

Encrypting File and Directory Names (Header Encryption)

By default, 7-Zip encrypts file contents, but the filenames and directory structures remain visible to anyone opening the archive. To completely hide the archive contents, use the -mhe=on flag. This feature is exclusive to the .7z format.

7z a secure_backup.7z sensitive_data/ -pYourPassword -mhe=on

Anyone attempting to view the contents of secure_backup.7z will be forced to enter the password before any file names or directory listings are displayed.

Password-Protecting Standard ZIP Archives

If you require compatibility with systems that do not natively support the .7z format, you can create a password-protected .zip archive. By default, 7-Zip uses standard ZipCrypto, which is vulnerable to modern attacks. To enforce stronger AES-256 encryption on a .zip archive, use the -mem=AES256 parameter:

7z a archive_name.zip target_file -pYourPassword -mem=AES256

Note that header encryption (-mhe=on) is not supported by the ZIP archive format.