inro

command module
v0.1.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 20, 2026 License: MIT Imports: 26 Imported by: 0

README

inro

Self-contained PGP for the desktop: encrypt, sign, verify and decrypt messages, and keep the keys of the people you write to. The OpenPGP engine is built in. Nothing else to install; gpg is never needed.

inro generating a key and encrypting a message

An inro (印籠) is the small case that used to hang from an obi to carry a personal seal and its ink. This one carries yours.

Go, cgo-free. The window is glaze (the platform webview via purego), the UI is embedded HTML, the crypto is ProtonMail/go-crypto, and the configuration is Filo. One binary, no files alongside it.

Install

On macOS, with Homebrew:

brew install --cask crgimenes/tap/inro

Or take a binary from the releases page: the macOS app is signed and notarized, Windows and Linux get plain executables. Building from source needs only Go; there is no C toolchain on any platform:

go install github.com/crgimenes/inro@latest

inro carries its own crypto and UI; the one thing it borrows from the system is the webview the OS already ships. macOS has it, Windows uses the Edge WebView2 runtime (present on any current Windows), and Linux needs GTK with WebKitGTK (libwebkit2gtk-4.1, or libwebkitgtk-6.0 for GTK 4; one package install).

Use

On first run inro opens the Keys page. Generate your key pair right there: EdDSA/Curve25519, an expiry if you want one, and a passphrase set in a confirm-twice window with an honest strength estimate. Or bring keys you already have: paste an armored key or open a .asc file.

Coming from gpg? Export there, import the files here; inro never talks to gpg itself:

gpg --armor --export-secret-keys you@example.com > my-key.asc  # your keys
gpg --armor --export > contacts.asc                            # public keys of everyone else

Each key has its own page with nickname, note, export and delete. There is also certification: sign a friend's key with yours to state that you checked it really belongs to them. Certifications travel with the exported key, and inro shows who, among the keys you hold, vouches for each one.

Then everything happens on the Message page: one text field, like a translator with a single box. There is no mode to choose and usually nothing to click, because what lands in the field already decides what happens to it:

  • A signed message is verified the moment it is pasted, and the readable text takes its place. Zero clicks.
  • An encrypted message names its own recipients, so inro finds which of your keys opens it by itself. If that key needs no passphrase, or you typed it recently, the message is decrypted on the spot. Otherwise the one question inro ever asks appears in its own window, pinentry style: a wrong passphrase is reported right there and the window stays for another try. Messages protected by a shared passphrase instead of a key work too.
  • Plain text goes out: pick recipients to Encrypt, flip Sign as to sign, or both. The armored result replaces your text, selected and ready to copy, with a link to restore the original if you still need it.

Open loads a message from a file; Save writes the field to one. The same actions live in the application menu, and Cmd/Ctrl+Enter runs the primary action from anywhere.

Any signature found while decrypting or verifying is reported above the result. A signature only reports as valid when the signer's key is in your keyring. "Valid" means the message was not altered and it was signed by that key. Whether the key really belongs to who it claims to is still on you.

Your passphrase is never stored. After you type it, the unlocked key stays in memory for KeyCacheSeconds (default 5 minutes, 0 disables the cache) so a burst of work asks once; after it expires, operations ask again.

Files

~/.config/inro/
  init.filo        ; configuration (optional)
  keyring.filo     ; nicknames and notes
  keys/
    <FINGERPRINT>.asc

Keys are stored in PGP's own armored format, one file per key, so gpg --import ~/.config/inro/keys/*.asc works and nothing is locked inside this app. keyring.filo holds only what the key material cannot carry: the nickname and note you attach to a key. The two stores can never disagree about a fingerprint or a user ID.

$XDG_CONFIG_HOME is honoured. An inro_init.filo in the working directory takes precedence over ~/.config/inro/init.filo.

Configuration

Every setting is optional; the defaults are shown.

(set Width 1024)
(set Height 720)
(set Debug #f)                       ; open the webview developer tools
(set DataDir "~/.config/inro")       ; where keys and metadata live
(set DefaultKey "")                  ; fingerprint pre-selected in the UI
(set KeyCacheSeconds 300)            ; how long a typed passphrase keeps the key unlocked

Status

Early but whole: key generation (with expiry), import (paste, file), export, delete, certification, encrypt, decrypt (including passphrase-protected messages), sign, verify, automatic key selection, and the unlocked-key cache all work. Not there yet: key revocation, extending expiry on an existing key.

Documentation

Overview

Command inro is a desktop front end for PGP: encrypt, sign, verify and decrypt short messages, and keep a list of the keys of people you know.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL