Password Protect Archives with 7-Zip Command Line
Securing your data by adding a password to an archive prevents
unauthorized access to sensitive files. This guide details how to use
the 7-Zip command-line utility to create encrypted archives, conceal
filenames, and choose the right encryption standards for both
.7z and .zip formats.
Basic Password Protection Syntax
To create an archive with a password, use the a (add)
command combined with the -p switch followed immediately by
your chosen password.
7z a archive_name.7z target_file_or_folder -pYourPassword- Replace
archive_name.7zwith your desired output filename. - Replace
target_file_or_folderwith the file or directory you want to compress. - Replace
YourPasswordwith your chosen password. Do not leave a space between-pand the password string.
Hiding Password from Command Line History
Entering your password directly into the command line stores it in
plain text within your shell or command prompt history. To enter the
password securely via a hidden interactive prompt, specify the
-p switch without a password value:
7z a archive_name.7z target_file_or_folder -pThe terminal will prompt you to enter and confirm the password before compression begins.
Encrypting File and Directory Names (Header Encryption)
By default, 7-Zip encrypts file contents, but the filenames and
directory structures remain visible to anyone opening the archive. To
completely hide the archive contents, use the -mhe=on flag.
This feature is exclusive to the .7z format.
7z a secure_backup.7z sensitive_data/ -pYourPassword -mhe=onAnyone attempting to view the contents of
secure_backup.7z will be forced to enter the password
before any file names or directory listings are displayed.
Password-Protecting Standard ZIP Archives
If you require compatibility with systems that do not natively
support the .7z format, you can create a password-protected
.zip archive. By default, 7-Zip uses standard ZipCrypto,
which is vulnerable to modern attacks. To enforce stronger AES-256
encryption on a .zip archive, use the
-mem=AES256 parameter:
7z a archive_name.zip target_file -pYourPassword -mem=AES256Note that header encryption (-mhe=on) is not supported
by the ZIP archive format.