Configuration
The .vaultic.yaml and .vaultic.local.yaml schema, environment variables, and where credentials are stored.
vaultic init writes a .vaultic.yaml file into the current directory. It's safe to commit — it
only holds your workspace/project/environment slugs and export preferences, never secret values.
version: 1 # required, literal 1
workspace: <string> # required — workspace slug
project: <string> # required — project slug
default_environment: <string> # default: "development"
branch_mapping: # optional
<branch-name>: <environment-slug>
export: # optional (all sub-fields optional/defaulted)
format: dotenv | json | yaml | shell | appsettings # default: "dotenv"
path: <string> # default: ".env" (appsettings: "appsettings.{Environment}.json")
include: [<glob>, ...] # default: ["*"]
exclude: [<glob>, ...] # default: []
delimiter: <string> # appsettings only, default: "__"
section: <string> # appsettings only, default: none (root-level merge)
pascal_case: <boolean> # appsettings only, default: false (reserved, not yet implemented)
hooks: # optional
post_sync: <shell command string> # run after `vaultic sync` regenerates the local filevaultic init itself only ever writes version, workspace, project, default_environment,
and the export block with its defaults (dotenv / .env / include: ["*"] / exclude: []);
branch_mapping and hooks.post_sync are edited in by hand when you need them.
Personal overrides: .vaultic.local.yaml
vaultic init offers to add .vaultic.local.yaml to .gitignore alongside .env/.env.*. It
currently only reads one field:
default_environment: <string>Environment resolution order for any command that takes -e/--env optionally: the -e/--env
flag → .vaultic.local.yaml's default_environment → .vaultic.yaml's default_environment.
Useful for pointing your own machine at a personal environment (e.g. dev-alice) without
changing the committed default for the rest of the team.
hooks.post_sync
An arbitrary shell command, run immediately after vaultic sync regenerates the export file.
Typical uses: restarting a local service, regenerating a derived config file, or printing a
reminder.
hooks:
post_sync: "docker compose restart api"Export formats
export.format accepts dotenv | json | yaml | shell | appsettings, and controls what
vaultic export / vaultic sync write. export.include/export.exclude are glob patterns
applied against secret keys — handy if a project only wants a subset of an environment's secrets
materialized locally.
export.delimiter and export.section only apply to format: appsettings — see
Local file sync for how the
nested-key convention, merge behavior, and --check staleness checksum work for that format.
export.pascal_case is reserved for a future key-casing transform and currently has no effect;
appsettings keys are always written uppercase, as-is.
Environment variables
| Variable | Used by | Default |
|---|---|---|
VAULTIC_API_URL | Server URL resolution (all commands) | https://vaultic.dev/api (or the URL saved from your last vaultic login) |
VAULTIC_WEB_URL | vaultic workspace invite (builds the accept-invite link) — overrides the server's own webAppUrl (from /auth/providers) if set | http://localhost:5173 |
GITHUB_TOKEN | vaultic push github (if --token not passed) | — |
VERCEL_TOKEN | vaultic push vercel (if --token not passed) | — |
Credentials from vaultic login are stored at ~/.vaultic/credentials.json (mode 0600):
serverUrl, token, and optionally email.