Skip to content
Add as Preferred Source

How to Back Up Filen (or Move Files Out) Without the CLI

Back up Filen or move files out without the CLI

Filen encrypts your files on your device before they upload, and its servers never hold the keys. That protects your privacy, and it also means no other service can simply fetch your files. Any backup or migration out of Filen has to decrypt the files somewhere you control.

Why the usual routes go through the CLI

Section titled "Why the usual routes go through the CLI"

Filen's answer for other tools is the Filen CLI. With it you can:

  • run a WebDAV or S3 server on your own machine that mirrors your drive
  • export an API key for rclone

rclone's Filen backend, added in rclone 1.73, needs that exported key. You install the CLI, sign in, run export-api-key, then give rclone your email, password and key. If you change your Filen password, you export the key again and update the rclone config[1].

Filen is also retiring the CLI in favor of a Rust rewrite. The CLI README points users to version 0.0.36 for now[2].

The WebDAV and S3 servers run only while the CLI is running on your computer, so there is no hosted endpoint to point another tool at.

Threads on the rclone forum show the same trouble spots:

  • Setup fails at the first sign-in with a getMasterKeys error[3], or with "cipher: message authentication failed" while decrypting the master keys[4]
  • One user calls the setup "pretty confusing" and asks whether anyone has it working[5]
  • A 15 to 20 GiB single-file backup uploads at about 3 MiB/s when an rclone encryption layer sits on top of the Filen remote[6]

Blober connects to Filen directly, so there is no CLI to install and no server to keep running. Sign in once through Filen's own login page, with two-factor authentication if you use it, and Blober decrypts files on your computer as it reads them.

  • Back up Filen to a local folder, a NAS, or any other connected provider
  • Move files into Filen from another provider, encrypted as they upload
  • Re-run the same workflow whenever you want a fresh copy

To set it up, follow the Filen setup guide. Then pick Filen as the source (or destination) in a workflow, choose where the files should go, and start the task. A file that fails is retried without repeating the whole task.

Files leaving Filen are decrypted on your computer. If the destination also encrypts, such as Proton Drive, it encrypts them again with its own keys. A backup to local disk or a NAS is plain files, readable without Filen.

After a Filen password change you sign in to Blober again. The old session stops working.

Do I need the Filen CLI to use Blober with Filen? No. Blober signs in through the Filen login page and needs no CLI, API key export or local server.

Does Blober store my Filen password? No. You type it into Filen's own login page. See the setup guide for the steps.

Is the backup still encrypted? Only if the destination encrypts it. Files are decrypted when Blober reads them from Filen. A copy on local disk is plain files, so keep that drive protected.

Can Blober copy Filen files to another Filen account? Yes. Pick Filen as the source and as the destination, signing in to each account separately. The files pass through your computer and are encrypted again with the second account's keys.

What happens when I change my Filen password? The old session stops working. Click Open Filen Login and sign in again.

Are deleted files really gone? Deleting through Blober moves a file to the Filen trash. Empty the trash in Filen to remove it for good.

Back up Filen, or move your files out, without installing a CLI. Blober runs on Windows, macOS and Linux, and connects to 20+ providers.

Download Blober at blober.io