qnap
A CLI for QNAP NAS management. It is designed for both interactive use and automation: human-friendly tables by default, stable JSON contracts on inspection commands, and a schema command for agent introspection.
Supported platforms: Linux and macOS.
Installation
Or build from source:
Quick Start
# Save connection settings and password
# Inspect the NAS
# Structured output for automation
Commands
| Command | Description |
|---|---|
login |
Save credentials and verify connectivity |
info |
Model, firmware, hostname, serial, uptime |
status |
CPU, RAM, temperature, uptime |
volumes |
Storage volumes and installed disks |
shares |
Shared folders |
network |
Network adapters, IPs, MACs, DNS (--json) |
config |
Show saved host, username, TLS settings, and file paths (--json) |
files ls <PATH> |
List files and directories (--all to paginate, --json) |
files stat <PATH> |
Normalized metadata plus raw QNAP fields (--json) |
files find <PATH> <PATTERN> |
Recursive glob search (*.txt, backup*) (--json) |
files mkdir <PATH> |
Create a directory |
files rm <PATH>... |
Delete one or more files or directories |
files mv <SRC> <DST> |
Move or rename a file or directory |
files cp <SRC> <DST> |
Copy a file or directory (--overwrite) |
files upload <LOCAL> <REMOTE_DIR> |
Upload a file or directory (--overwrite, -r recursive) |
files download <REMOTE> [LOCAL] |
Download a file or directory (-r recursive) |
dump [DIR] |
Save raw API responses for debugging |
schema |
Print full command schema |
Global Flags
These flags work on every authenticated command, including login.
| Flag | Description |
|---|---|
--host <HOST> |
Override the NAS host for one command. HTTPS only. |
--username <USERNAME> |
Override the username for one command. |
--insecure |
Skip TLS certificate verification for one command. |
--secure |
Force TLS certificate verification for one command. |
--password-stdin |
Read the password from stdin. |
Examples:
|
Authentication
qnap login verifies the credentials before saving anything. Host, username, and the saved TLS verification preference are stored in config.toml. The password is stored separately in credentials.toml.
The CLI requires HTTPS. Plain http:// targets are rejected. If your NAS uses a self-signed certificate, use --insecure or QNAP_INSECURE=1 explicitly.
If you do not want local password persistence, skip qnap login and provide QNAP_HOST, QNAP_USERNAME, and QNAP_PASSWORD directly when running commands.
JSON Output
The following commands support --json with stable, typed output:
infostatusvolumessharesfiles lsfiles stat
Highlights:
status --jsonuses numeric fields such ascpu_usage_pct,mem_total_mb, andtemp_c.volumes --jsonincludesstatus_code,pool_id, and per-disktemp_c.shares --jsonusesitems_countas a number.files ls --jsonusessize_bytesandmodified_epoch.files stat --jsonreturns normalized fields plus arawobject for unnormalized QNAP metadata.
Use qnap schema for the full machine-readable command and output contract.
Environment Variables
Environment variables override local files.
| Variable | Description |
|---|---|
QNAP_HOST |
NAS host, for example https://nas.local or nas.local |
QNAP_USERNAME |
Username |
QNAP_PASSWORD |
Password |
QNAP_INSECURE |
1/true/yes to skip TLS verification, 0/false/no to force verification |
NO_COLOR |
Disable colored output |
Stored Files
config.toml stores host, username, and TLS verification preference. credentials.toml stores the password separately in plaintext on the local machine.
| Platform | Config file | Credentials file |
|---|---|---|
| macOS | ~/Library/Application Support/qnap/config.toml |
~/Library/Application Support/qnap/credentials.toml |
| Linux | ~/.config/qnap/config.toml |
~/.config/qnap/credentials.toml |
Security
- Passwords are never accepted as CLI flags.
- HTTPS is required for NAS connections.
- TLS verification is enabled by default.
credentials.tomlis written atomically.- On Unix,
credentials.tomlis restricted to owner-only (0600) permissions. - On Unix, the config directory is tightened to owner-only (
0700) permissions. - Symlink and non-regular-file credential targets are rejected.
- If you do not want local password persistence, use environment variables or
--password-stdin.
Compatibility
Tested against QTS 5.1.x and 5.2.x. The core authentication and file manager APIs have been stable since QTS 4.3, but qnap dump is the recommended way to capture compatibility issues from older or unusual firmware builds.
License
MIT