Skip to content

Recovery CLI

The recovery CLI is a single self-contained executable for Linux (x86-64, ARM64), Windows and macOS. It works on backup files directly — from your storage, a download or a USB disk — and never needs the Xtic server.

Command What it does
xtic inspect <file> Identifies every layer (BMENC, OpenPGP, 7z, zip, gzip, zstd, xz, bzip2, tar) and prints the chain, key ids and sizes
xtic verify <file> [--manifest m --signing-keys k] [keys] Checks the stored SHA-256 against the run manifest and the manifest signature; with keys, a full integrity pass without writing output
xtic decrypt <file> [keys] [-o out] Removes the encryption layer: BMENC (recovery key, key export or password), OpenPGP (secret key or password), zip-AES; 7z AES via 7zz
xtic decompress <file> [-o out] gzip, zstd, xz, bzip2
xtic extract <file> --to <dir> [keys] The whole chain to files, safely: path and link checks, size and entry limits, never overwrites by default
xtic list <file> [keys] Lists tar or zip contents, or the encrypted file index
xtic db-hints <file> [--manifest m] Prints the native restore command for a database backup
xtic password --manifest m --identity k --artifact <id> Unseals the escrowed archive password of a password-mode backup for gpg or 7zz
xtic keygen recovery -o recovery-key.txt Generates the recovery key pair offline and prints the public key to import
xtic catalog export <s3-prefix> --signing-keys k -o catalog.json Rebuilds a catalog from the manifests in storage, verifying their signatures
Terminal window
xtic decrypt --identity recovery-key.txt web.tar.zst.bmenc -o - | zstd -dc | tar -xf - -C /restore

Without the CLI at all, the published BMENC v1 reference script does the same with Python:

Terminal window
python3 bmenc_ref.py --identity recovery-key.txt web.tar.zst.bmenc > web.tar.zst