← All modules

Distribution · terminal

Terminal::Getpass

Works

Read a password from the terminal with echo switched off — one sub, a prompt, and the terminal restored afterwards however it ends.

Version
0.0.11 zef:titsuki
Depends
Term::termios
License
Artistic-2.0
Its own test suite
1 file, green
Checked
2026-09-15 against Raku++ 3.28.0 and Rakudo 2026.08
Where it lives
raku.land · source

Install it #

$ rakupp install Terminal::Getpass

zef install Terminal::Getpass writes the same store; either installer leaves the module usable by both engines.

What it is for #

A program that asks for a password must not print it. The terminal echoes every keystroke by default, so the program has to turn that off, read the line, and turn it back on — including when the user presses Ctrl-C halfway, which is when leaving a terminal with echo disabled is most annoying.

That is three calls into the terminal driver and a signal handler, and it is the same three calls in every program. This distribution is them, as one sub.

Reading a password #

use Terminal::Getpass;

my $password = getpass();
say 'got ', $password.chars, ' characters';

my $other = getpass('Repeat: ');
say $password eq $other ?? 'they match' !! 'they differ';

That example is shown rather than run, because it waits for a person to type. The prompt is the first argument and goes to standard error, which means it still appears when the program's output is being redirected — the right default for something the user must see. The second argument chooses a different stream for the prompt.

Two control characters are handled: delete removes the previous character, and Ctrl-C restores the terminal before exiting, so the shell is not left in a strange state.

The one thing to know #

It needs standard output to be a terminal, not standard input:

File
use Terminal::Getpass;

say (try { getpass('never asked: ') }) // $!.message;
say 'still running';
Output
tcgetattr failed
still running

The implementation asks the driver about file descriptor 1. So a user sitting at a real terminal, with a real keyboard, running

$ myprogram | tee install.log

cannot type a password: standard input is still the terminal and standard output is now a pipe, and the call fails before the prompt appears. The message is tcgetattr failed, with no module name and no hint about which descriptor it means.

It throws rather than hanging, which is the good news — the example above catches it and carries on. Check $*OUT.t before calling, and when it is false either refuse with a clear message or fall back to an environment variable or a file, the way other tools do when they detect a pipe.