Recovery CLI
The recovery CLI is a single self-contained executable for Linux (x86-64, ARM64), Windows and macOS. It works on backup files directly — from your storage, a download or a USB disk — and never needs the Xtic server.
| Command | What it does |
|---|---|
xtic inspect <file> |
Identifies every layer (BMENC, OpenPGP, 7z, zip, gzip, zstd, xz, bzip2, tar) and prints the chain, key ids and sizes |
xtic verify <file> [--manifest m --signing-keys k] [keys] |
Checks the stored SHA-256 against the run manifest and the manifest signature; with keys, a full integrity pass without writing output |
xtic decrypt <file> [keys] [-o out] |
Removes the encryption layer: BMENC (recovery key, key export or password), OpenPGP (secret key or password), zip-AES; 7z AES via 7zz |
xtic decompress <file> [-o out] |
gzip, zstd, xz, bzip2 |
xtic extract <file> --to <dir> [keys] |
The whole chain to files, safely: path and link checks, size and entry limits, never overwrites by default |
xtic list <file> [keys] |
Lists tar or zip contents, or the encrypted file index |
xtic db-hints <file> [--manifest m] |
Prints the native restore command for a database backup |
xtic password --manifest m --identity k --artifact <id> |
Unseals the escrowed archive password of a password-mode backup for gpg or 7zz |
xtic keygen recovery -o recovery-key.txt |
Generates the recovery key pair offline and prints the public key to import |
xtic catalog export <s3-prefix> --signing-keys k -o catalog.json |
Rebuilds a catalog from the manifests in storage, verifying their signatures |
Example: a platform-key backup, by hand
Section titled “Example: a platform-key backup, by hand”xtic decrypt --identity recovery-key.txt web.tar.zst.bmenc -o - | zstd -dc | tar -xf - -C /restoreWithout the CLI at all, the published BMENC v1 reference script does the same with Python:
python3 bmenc_ref.py --identity recovery-key.txt web.tar.zst.bmenc > web.tar.zst