Authentication & project setup
vaultic login, logout, whoami, profile, and init.
vaultic login
Log in via browser (default), email/password, or by pasting a token.
| Flag | Description |
|---|---|
--token <token> | Paste a session or service token instead of logging in interactively |
--server <url> | Vaultic server URL |
--email <email> | Non-interactive login; skips the browser flow |
--password <password> | Non-interactive login; skips the browser flow |
--no-browser | Skip opening a browser; prompt for email/password instead |
--profile <name> | Save under a named profile and make it active |
If --token is given, credentials are just saved. Otherwise, with no email/password/
--no-browser, it opens a browser-based login flow. Given --email/--password (or after
--no-browser prompts), it posts to /auth/login; on a 401 it offers to register instead.
Multiple accounts with --profile
Credentials are normally saved under a default profile. Pass --profile <name> to save a
login under a separate named profile instead — useful for a work account and a personal
account, or a hosted account alongside a self-hosted server:
vaultic login --profile work --server https://vaultic.mycompany.com/api
vaultic login --profile personalLogging in with --profile also makes that profile active, so the CLI uses it for every
command until you switch. See vaultic profile below to switch back without re-authenticating,
and $VAULTIC_PROFILE to override the active profile for a single command or script.
vaultic logout
Clears stored credentials for the active profile (or --profile <name> if given).
| Flag | Description |
|---|---|
--profile <name> | Log out of a specific profile instead of the active one |
vaultic whoami
Shows the current logged-in identity — detects service tokens (prefixed sht_) vs. a user
session and prints accordingly, along with the active profile name.
| Flag | Description |
|---|---|
--profile <name> | Check a specific profile instead of the active one |
vaultic profile
Manage saved login profiles without re-authenticating.
vaultic profile list— lists saved profiles, marking the active one.vaultic profile use <name>— switches the active profile to an already-saved one.
For a one-off override without changing the active profile (e.g. in a script), set
VAULTIC_PROFILE=<name> in the environment; it takes precedence over the active profile but is
itself overridden by an explicit --profile flag on the command.
vaultic init
Initializes the current directory as a Vaultic project by writing .vaultic.yaml. Fully
interactive, no options:
- Warns and confirms before overwriting an existing
.vaultic.yaml. - Lets you pick or create a workspace, then pick or create a project, then pick a default environment.
- Writes
.vaultic.yaml— see Configuration for the full schema. - Offers to add
.env,.env.*, and.vaultic.local.yamlto.gitignore.