Linux command
Wardlet
Encrypt files where they already are. A FIDO2-compatible key unlocks them.
The files stay put
Wardlet does not mount a drive and it does not collect your files into a container. An encrypted copy is written beside the original. SSH keys, notes, and anything else stay in the directory you chose. When you are satisfied the ciphertext opens, you delete the plaintext yourself.
Supported devices
Use a FIDO2-compatible key. Touch it to unlock. If it asks for a PIN, that is the same PIN a website asks for.
Enrolled with Wardlet: YubiKey 5 and Trezor.
The same kind of key should also work: other YubiKey 5 models, the current Yubico Security Key, Nitrokey 3, Nitrokey FIDO2, SoloKeys, and an OnlyKey using its FIDO2 app. For Trezor, that means Model T and the Safe models. Plug the key in with a USB cable.
An older login key will not work. That includes YubiKey 4 and the original Yubico Security Key. Trezor One will not work either.
The key never holds your files. Copying the vault does not copy a way to open them.
One lock, several keys
Every file is encrypted to one master. Each hardware key has its own wrapper of that master. Any one enrolled key opens the files. Adding a key writes one wrapper. Removing a key deletes that wrapper. The files are not rewritten.
The command is wardlet. This site is where the explanation will live while the tool is built.