EncryptCredential

0.4.0

Apteco PS Modules - PowerShell security encryption module

Execute commands like

"Hello World" | Convert-PlaintextToSecure

to get a string like

76492d1116743f0423413b16050a5345MgB8AEEAYQBmAEEAOABPAEEAYQBmAEYAKwBuAGQAegBxACsASQBRAGIAaQA0AEEAPQA9AHwANAAxAGEAYQBhADAAYwA3ADQAYwBiADkAYwAzADEAZgBkAGUAZQBkADQAOABhADIAMgA5AGUAMAAyADkANwBiADcAMQAyADgAOAAzADkAMwBiADA
Apteco PS Modules - PowerShell security encryption module

Execute commands like

"Hello World" | Convert-PlaintextToSecure

to get a string like

76492d1116743f0423413b16050a5345MgB8AEEAYQBmAEEAOABPAEEAYQBmAEYAKwBuAGQAegBxACsASQBRAGIAaQA0AEEAPQA9AHwANAAxAGEAYQBhADAAYwA3ADQAYwBiADkAYwAzADEAZgBkAGUAZQBkADQAOABhADIAMgA5AGUAMAAyADkANwBiADcAMQAyADgAOAAzADkAMwBiADAANAA0ADcAMwA3ADQANgAxADMAYwBmADQAZQAyADIAMwBkAGQAMQBhADUAMAA=

This string can be decrypted by calling

"76492d1116743f0423413b16050a5345MgB8AEEAYQBmAEEAOABPAEEAYQBmAEYAKwBuAGQAegBxACsASQBRAGIAaQA0AEEAPQA9AHwANAAxAGEAYQBhADAAYwA3ADQAYwBiADkAYwAzADEAZgBkAGUAZQBkADQAOABhADIAMgA5AGUAMAAyADkANwBiADcAMQAyADgAOAAzADkAMwBiADAANAA0ADcAMwA3ADQANgAxADMAYwBmADQAZQAyADIAMwBkAGQAMQBhADUAMAA=" | Convert-SecureToPlaintext

and get back

Hello World

You better save the strings into variables ;-)

This module is used to double encrypt sensitive data like credentials, tokens etc.

Encryption happens in two layers: AES-256 with a random keyfile plus a machine-bound layer
(DPAPI on Windows, machine-id derived keys on Linux/macOS). So even if an attacker steals the
encrypted string AND the keyfile, it cannot be decrypted on another machine. With
-Scope User the string is additionally bound to the current user account.

At the first encryption a new random keyfile will be generated automatically.
The key is saved per default in your users profile, but can be exported into any other folder
via Export-Keyfile and loaded from there via Import-Keyfile.

Strings encrypted with older versions of this module stay decryptable (legacy format is
detected automatically).

Show more

Minimum PowerShell version

5.1

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name EncryptCredential

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name EncryptCredential

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Apteco GmbH. All rights reserved.

Package Details

Author(s)

  • florian.von.bracht@apteco.de

Tags

powershell Windows Linux Apteco

Functions

Convert-PlaintextToSecure Convert-SecureToPlaintext Export-Keyfile Import-Keyfile New-Keyfile

PSEditions

Desktop Core

Dependencies

This module has no dependencies.

Release Notes


0.4.0 Encrypted strings are now really bound to the machine they were created on:
     a second encryption layer via DPAPI (Windows) or machine-id derived keys with
     AES + HMAC integrity protection (Linux/macOS) wraps the existing keyfile encryption.
     So a stolen ciphertext plus keyfile is useless on another machine.
     New -Scope parameter on Convert-PlaintextToSecure:
     'Machine' (default), 'User' (additionally bound to the current account) and
     'Portable' (old single-layer behaviour for moving ciphertexts between machines).
     Decryption stays downwards compatible - strings from older versions are detected
     and decrypted with the keyfile only.
     Export-Keyfile now re-applies restrictive file permissions to the exported copy
     and no longer switches to the new path if the copy failed.
     Import-Keyfile now validates that the file is a usable 16/24/32 byte AES key.
     Added a Pester test suite.
0.3.3 Fixed Convert-PlaintextToSecure calling New-Keyfile (the public, confirmation-gated wrapper with no -Path/-ByteLength params)
     instead of the private New-KeyfileRaw when auto-creating a missing keyfile. This threw a parameter binding error
     on any machine without an existing keyfile yet, e.g. fresh CI runners.
0.3.2 Fixed a bug where the module would not properly handle cases where the keyfile did not exist. Using New-Keyfile now instead of Create-Keyfile
0.3.1 Fixed returning an exception, when decryption failed instead of writing
     an error and returning an empty string
0.3.0 Reworked the module with Claude AI to be more secure and robust, now using another way to create
     a keyfile for salting. The old encryption method is still supported, so all
     previously encrypted strings will stay valid UNTIL you call New-Keyfile. After that,
     please re-encrypt all your credentials.
     Added ACL and linux file permission handling for the keyfile.
     Dispose the used AES object after encryption/decryption for better security.
     Changed internal functions verbs for more consistency
     Updated the copyright year to 2026
0.2.0 Tested successfully Linux support
0.1.2 Updated copyright to 2025
0.1.1 Bumped the copyright year to 2024
0.1.0 Making this module more mature with only explicit functions to export
     Removing not needed verbose output, use -verbose to see it again
     Fixed the path joining
0.0.2 Fixed a bug regarding output if a keyfile does not exist
0.0.1 Initial release through PSGallery

FileList

Version History

Version Downloads Last updated
0.4.0 (current version) 28 7/29/2026
0.3.3 21 7/22/2026
0.3.2 63 6/3/2026
0.3.1 41 3/30/2026
0.3.0 25 3/3/2026
0.2.0 67 10/1/2025
0.1.2 13 9/23/2025
0.1.1 92 6/24/2024
0.1.0 100 10/5/2023
0.0.2 67 11/28/2022
0.0.1 22 10/31/2022
Show more