Vaultic
Web App

Overview

The Vaultic dashboard — layout, navigation, and how it relates to the CLI.

The Vaultic web app is the dashboard for everything the CLI does, plus the things that only make sense as a UI: an environment matrix view, pending change approvals, member/invite management, access grants, secret trash, webhook management, and the audit log.

Signing in

Up to four options, each only shown if the server actually supports it (GET /auth/providers):

  • Email/password — the original, always-available option unless a self-hoster switches it off. New signups go through email verification and (if the server has Cloudflare Turnstile configured) a CAPTCHA before the account is usable.
  • Continue with GitHub / Continue with Google — OAuth, if the server has that provider's client credentials configured. A GitHub or Google login whose verified email matches an existing password-protected account never auto-links — you must confirm with your password first, since auto-linking purely by email is a known account-takeover vector.
  • Secure SSO — type your work email; Vaultic looks up your email domain against configured SAML connections and, if one matches, redirects you to your organization's identity provider. See Settings → Security for how an admin sets this up, and note a workspace can require SSO for its domain, which blocks the other three options entirely for matching addresses.

The login page also handles vaultic login's browser-based flow (/cli-login): the CLI prints a short code and this URL, you paste the code in and approve, and the CLI (which is polling separately) picks up the token on its own. No localhost callback server is involved — the code only ever travels by you copying it, so this works even when the page is opened on a different device than the CLI is running on, e.g. over SSH.

Layout

Every authenticated page shares a persistent shell: a left sidebar and top bar, with the routed page rendered in between. Cmd/Ctrl+K opens a command palette from anywhere.

The Vaultic dashboard shell: workspace switcher and nav in the sidebar, project list in the main pane

The sidebar has three sections:

  • Workspace switcher (top) — current workspace name + role badge; a popover lists every workspace you belong to, plus a link back to "All workspaces".
  • Workspace nav — a "Projects" link; once you're inside a project, this expands into a project sub-nav (Environments, Config Syncs, Members, Compare, Webhooks).
  • Organization nav (bottom-pinned, visible anywhere inside a workspace) — Change Requests, Activity, Secrets Health, Team, Tokens, Settings.

The top bar has a notification bell (unread count badge, polling popover — invite notifications and @mentions on secret comments land here, each read individually or all at once) and an account menu (profile, and Your account for data export/deletion).

Workspace  ->  Project  ->  Environment  ->  Secrets | Config Syncs | Access | Logs

Workspaces, projects & environments

The full breakdown of each level in the hierarchy above.

On this page