Vaultic
Web App

Secrets & the environment matrix

The Secrets tab for one environment, and the cross-environment Compare view.

The Secrets tab

The main secrets table for one environment, and the primary place to manage values day to day.

Toolbar: search (matches key or tag), sort (Key A→Z / Z→A / Recently updated), filter (by type hint, or "Inherited only"), filter by tag, a reveal-all/hide-all toggle, a version-history picker to jump straight to a key's history, a Trash button (30-day retention for deleted secrets), and an "Add secret" split button (single secret, or bulk import by pasting .env content).

Per-row details:

  • Key — a note icon opens a comments panel (with a count badge if any exist, and fires a notification for anyone @mentioned in a new comment); inline badges show inherited · <parentEnv> for keys not overridden locally, personal override if you have one set, ref for reference/template values, expired/expires soon based on expiresAt, rotation due if overdue, a lock icon + restricted or an unmasked badge based on the secret's visibility, and any tags (clickable to filter).
  • Type — an inline select (string, multiline, json, url, boolean, number, certificate, private-key); changing it re-saves the secret with the new type hint. Disabled on restricted rows, since changing type requires resubmitting the value and that can't be retrieved.
  • Value — masked by default; a Reveal button fetches and shows the real value, Copy fetches and copies without ever displaying it. unmasked secrets show their real value directly, with no Reveal button needed. restricted secrets show a lock icon instead — Reveal and Copy are unavailable; only a service token can retrieve the value.
  • Row menu — Edit value, Comments, Version history/rollback, Secret references, Rename, Copy value, Share link, Delete. Version history/rollback, Rename, and Delete are disabled on inherited-only rows (you edit those from the parent environment instead). Copy value and Share link are disabled for restricted rows, since neither can retrieve the value.

Editing a restricted secret's value in the Add/Edit modal always starts from an empty value field — its current value can't be shown, so you must enter a new one. The Visibility dropdown only lets you loosen a restricted secret to masked/unmasked once you've typed a new value; see Visibility for why.

The Secrets tab, showing expired, tagged, unmasked, and restricted badges

Adding to or deleting from a locked environment doesn't apply immediately — it becomes a pending change proposal, and the UI shows a toast explaining that. See Locking & change requests.

An admin can disable personal overrides for a specific environment (column header menu → Settings). Turning it off wipes every existing personal override in that environment, not just hides them — everyone falls back to seeing the shared value.

Row menu → Share link opens a modal for handing a secret's current value to someone without adding them to the workspace. Set an expiry duration (15m, 1h, 7d, ...), a max-view count, or both — at least one is required, so a link can't be created with no limit at all.

Creating the link snapshots the resolved value at that moment: rotating the underlying secret afterward doesn't change what the link reveals. The resulting /share/<token> URL is shown once, with a Copy button, and needs no sign-in to view — the form and the result never share the same screen, so a copied link can't be mistaken for the secret's actual value.

Unavailable for restricted secrets, since their value can't be retrieved to put in a link.

Prefer the terminal? vaultic share <key> does the same thing — see CLI: sharing & webhooks.

Compare (the matrix view)

.../compare shows every key as a row and every environment as a column, side by side — the closest thing to a bird's-eye view of a project's secrets. Each cell has its own reveal/copy/ delete actions; a ref badge marks reference values, and a missing badge flags a key that exists in some environments but not this one.

Each column header has a lock/unlock toggle (locking an environment routes future direct writes through approval) and a locked badge when applicable.

The Compare matrix view, with a locked environment column and missing-key badges

Compare is intentionally read/reveal/delete/lock-only — there's no way to add a secret from here. To add or edit values, open a single environment's Secrets tab.

On this page