Vaultic
Command Line

Authentication & project setup

vaultic login, logout, whoami, profile, and init.

vaultic login

Log in via browser (default), email/password, or by pasting a token.

FlagDescription
--token <token>Paste a session or service token instead of logging in interactively
--server <url>Vaultic server URL
--email <email>Non-interactive login; skips the browser flow
--password <password>Non-interactive login; skips the browser flow
--no-browserSkip opening a browser; prompt for email/password instead
--profile <name>Save under a named profile and make it active

If --token is given, credentials are just saved. Otherwise, with no email/password/ --no-browser, it opens a browser-based login flow. Given --email/--password (or after --no-browser prompts), it posts to /auth/login; on a 401 it offers to register instead.

Multiple accounts with --profile

Credentials are normally saved under a default profile. Pass --profile <name> to save a login under a separate named profile instead — useful for a work account and a personal account, or a hosted account alongside a self-hosted server:

vaultic login --profile work --server https://vaultic.mycompany.com/api
vaultic login --profile personal

Logging in with --profile also makes that profile active, so the CLI uses it for every command until you switch. See vaultic profile below to switch back without re-authenticating, and $VAULTIC_PROFILE to override the active profile for a single command or script.

vaultic logout

Clears stored credentials for the active profile (or --profile <name> if given).

FlagDescription
--profile <name>Log out of a specific profile instead of the active one

vaultic whoami

Shows the current logged-in identity — detects service tokens (prefixed sht_) vs. a user session and prints accordingly, along with the active profile name.

FlagDescription
--profile <name>Check a specific profile instead of the active one

vaultic profile

Manage saved login profiles without re-authenticating.

  • vaultic profile list — lists saved profiles, marking the active one.
  • vaultic profile use <name> — switches the active profile to an already-saved one.

For a one-off override without changing the active profile (e.g. in a script), set VAULTIC_PROFILE=<name> in the environment; it takes precedence over the active profile but is itself overridden by an explicit --profile flag on the command.

vaultic init

Initializes the current directory as a Vaultic project by writing .vaultic.yaml. Fully interactive, no options:

  • Warns and confirms before overwriting an existing .vaultic.yaml.
  • Lets you pick or create a workspace, then pick or create a project, then pick a default environment.
  • Writes .vaultic.yaml — see Configuration for the full schema.
  • Offers to add .env, .env.*, and .vaultic.local.yaml to .gitignore.

On this page