Unrar Passwords with Special Characters and Spaces

Extracting password-protected RAR archives using the command-line utility unrar often fails when the password contains spaces or special characters. This guide explains how unrar processes password arguments, how system shells interfere with these characters, and the proper methods—including quoting, character escaping, and interactive prompts—to ensure complex passwords are parsed accurately during extraction.

The Role of the Shell vs. Unrar

The unrar utility does not alter or strip characters from a password on its own; it receives whatever string the operating system's command-line interface passes to it. The primary issue with spaces and special characters stems from how shells (such as Bash, Zsh, Windows Command Prompt, or PowerShell) parse command arguments before invoking the unrar binary.

Shells use spaces as delimiters between different arguments. Furthermore, characters like $, !, ", \, &, and % are reserved for variable expansion, history substitution, or command chaining. If these are not protected, the shell alters, truncates, or misinterprets the password before unrar receives it, resulting in a "wrong password" or extraction error.

Handling Spaces in Passwords

When providing a password via the command-line flag -p, unrar expects the password immediately following the flag without a separating space. If the password itself contains spaces, the entire argument or the password string must be enclosed in quotes.

Examples

Wrap the password inside quotation marks:

unrar x -p"my secret password" archive.rar

Alternatively, enclose the entire switch:

unrar x "-pmy secret password" archive.rar

Do not leave a space between -p and the opening quote (e.g., -p "password"), as unrar may interpret the flag as empty and attempt to use the password as the target directory or file list.

Handling Special Characters

Special characters require different quoting strategies depending on the operating system.

Linux and macOS (Bash / Zsh)

In Unix-like shells, double quotes (") still allow the shell to evaluate characters such as $, `, and \. Single quotes (') should be used instead, as they preserve the literal value of every character within them.

unrar x -p'P@$$w0rd!' archive.rar

If the password contains a literal single quote, close the single-quoted string, insert an escaped single quote (\'), and reopen the single quotes:

unrar x -p'it'\''s-a-password' archive.rar

Windows (CMD and PowerShell)

  • Command Prompt (CMD): CMD interprets characters like &, |, and ^ as control operators. Wrap the flag and password in double quotes:

    unrar x "-pP@$$w0rd&123" archive.rar

    If using the percent sign (%), it may need to be escaped as %% to prevent CMD from treating it as an environment variable.

  • PowerShell: PowerShell treats $ as a variable prefix and requires single quotes to suppress variable expansion:

    unrar x -p'P@$$w0rd' archive.rar

The Interactive Prompt: The Safest Method

To completely bypass shell parsing issues with complex passwords, omit the -p switch entirely. When unrar encounters an encrypted archive and no password has been supplied via the command line, it prompts for the password interactively:

unrar x archive.rar

The terminal will display:

Enter password (will not be echoed):

Entering the password interactively sends the raw keystrokes directly to the unrar process via standard input. This prevents the shell from expanding variables, interpreting spaces, or requiring escape sequences.