Welcome to Vaultic
Encrypted, versioned secrets management for teams — a CLI, a web dashboard, and a server you run yourself.
Vaultic stores your app's secrets outside your codebase, injects them into local dev and CI without ever writing them to disk, and gives your team one place to see who changed what and when. Most teams have a first secret injected into a running process in under five minutes.
Quickstart
Install the CLI, log in, and inject your first secret into a running process.
Core concepts
Workspaces, projects, environments, and how inheritance and versioning fit together.
Command line
Full reference for @vaultic-dev/cli — every command, every flag.
Web app
The dashboard: the environment matrix, team access, webhooks, and the audit log.
What Vaultic does
Versioned, encrypted secrets
Every write is a new version — old ones stay fetchable. Values are envelope-encrypted (AES-256-GCM) and masked everywhere except an explicit, separately-audited reveal.
Environments with inheritance
dev-alice can fall through to development for anything it doesn't override. env promote
diffs and copies changes up a chain, e.g. staging → production.
Built for local dev and CI
vaultic run -- <cmd> injects secrets as env vars into a subprocess — nothing touches disk.
vaultic export --check fails a CI job when a local .env drifts from the server.
A dashboard for everything else
The environment matrix, locked-environment change approvals, member roles and access grants, webhooks, secret trash, and Secrets Health.
Automation hooks
- Webhooks — HMAC-signed generic JSON, or Slack-formatted, for the full write/rotation/ lifecycle event catalog.
- Push to third parties —
vaultic push githubandvaultic push vercelsync an environment's secrets outward on demand. - Cloud secret store sync — push to AWS Secrets Manager, AWS SSM Parameter Store, GCP Secret
Manager, or Azure Key Vault, either on demand (
vaultic push <target>) or automatically from the web app every time a secret changes. - Ephemeral preview environments — a Git webhook auto-spawns a
preview-<branch>environment per PR branch and tears it down when the branch is deleted. - Provider-assisted rotation —
secrets rotate --provider <name>runs the actual credential rotation server-side (postgres, mysql, redis, aws-iam, cloudflare, gitlab, or a generic webhook), then stores the result through the normal versioned-write path.
See Automated syncs and Cloud secret store sync for the outbound integrations, and Terraform / Kubernetes for infrastructure-side reads.
Getting a server to talk to
The CLI and web app both need a Vaultic server to point at — your own self-hosted instance, or one your team already runs. This site documents how to use the CLI and the web app once you have a server; it's not a self-hosting guide.