# Install reop with Homebrew

Encrypted keypair management. Version 2.1.1 via Homebrew; verified 2026-06-27.

## Install

```sh
sudo av install brew:reop
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install reop
```

  Evidence: local Homebrew formula metadata

## Package facts

- **Package key:** brew:reop
- **Package manager:** Homebrew
- **Version:** 2.1.1
- **Source summary:** Encrypted keypair management
- **Homepage:** <https://web.archive.org/web/20251224210131/https://flak.tedunangst.com/post/reop>
- **Last updated:** 2026-06-27T18:58:57-04:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- reop (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 2.1.1
## Project history and usage

reop, short for reasonable expectation of privacy, is a minimalist command-line tool for signatures and file encryption.

### Project history

The README frames reop as an extension of ideas from signify rather than an OpenPGP clone. It was written by Ted Unangst and uses NaCl/libsodium primitives for signing and encryption.

### Adoption history

reop was adopted mainly by BSD and Homebrew-style packaging channels as a compact alternative to larger tools such as GnuPG or OpenSSL for simple signing and encryption workflows. Homebrew packages version 2.1.1 from a ports distfile and marks it unmaintained.

### How it is used

The manual documents modes for generating keys, encrypting, decrypting, signing, and verifying. It searches ~/.reop for default key files named seckey, pubkey, and pubkeyring, while command-line options can point to explicit key and message files.

### Why package nerds care

reop is notable to package maintainers because it is a small cryptographic CLI with a tight dependency story around libsodium, explicit limits, a simple trust model, and source releases that remain useful even without broad ecosystem adoption.

### Timeline

- 2014: reop.1 carries an Mdoc date of March 16, 2014.
- 1.0: README history records the initial release.
- 1.1.1: README history records binary encrypted messages via the -b option.
- 2.1: README history records a more secure encrypted message format as the default.
- 2.1.1: Homebrew packages this version from the ports distfile.

### Related projects

- The README names signify as an influence and libsodium/NaCl as the cryptographic foundation.

### Sources

- GitHub unkaktus/reop README.
- Homebrew formula metadata for reop.
- reop README and reop.1 from the 2.1.1 source tarball.


## Security Notes

broad file, network, media, or database tool signal.

- **Geiger risk:** blue / medium
- broad file, network, media, or database tool signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Credential files

- Unix: ~/.reop/seckey, ~/.reop/pubkey, ~/.reop/pubkeyring

## Combined YAML source

View the package source record on GitHub. [combined/reop.yml](https://github.com/mxcl/pkgdb/blob/main/combined/reop.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
