Vaultic
Command Line

Configuration

The .vaultic.yaml and .vaultic.local.yaml schema, environment variables, and where credentials are stored.

vaultic init writes a .vaultic.yaml file into the current directory. It's safe to commit — it only holds your workspace/project/environment slugs and export preferences, never secret values.

version: 1                        # required, literal 1
workspace: <string>                # required — workspace slug
project: <string>                  # required — project slug
default_environment: <string>      # default: "development"
branch_mapping:                    # optional
  <branch-name>: <environment-slug>
export:                            # optional (all sub-fields optional/defaulted)
  format: dotenv | json | yaml | shell | appsettings   # default: "dotenv"
  path: <string>                          # default: ".env" (appsettings: "appsettings.{Environment}.json")
  include: [<glob>, ...]                  # default: ["*"]
  exclude: [<glob>, ...]                  # default: []
  delimiter: <string>                     # appsettings only, default: "__"
  section: <string>                       # appsettings only, default: none (root-level merge)
  pascal_case: <boolean>                  # appsettings only, default: false (reserved, not yet implemented)
hooks:                             # optional
  post_sync: <shell command string>       # run after `vaultic sync` regenerates the local file

vaultic init itself only ever writes version, workspace, project, default_environment, and the export block with its defaults (dotenv / .env / include: ["*"] / exclude: []); branch_mapping and hooks.post_sync are edited in by hand when you need them.

Personal overrides: .vaultic.local.yaml

vaultic init offers to add .vaultic.local.yaml to .gitignore alongside .env/.env.*. It currently only reads one field:

default_environment: <string>

Environment resolution order for any command that takes -e/--env optionally: the -e/--env flag → .vaultic.local.yaml's default_environment → .vaultic.yaml's default_environment. Useful for pointing your own machine at a personal environment (e.g. dev-alice) without changing the committed default for the rest of the team.

hooks.post_sync

An arbitrary shell command, run immediately after vaultic sync regenerates the export file. Typical uses: restarting a local service, regenerating a derived config file, or printing a reminder.

hooks:
  post_sync: "docker compose restart api"

Export formats

export.format accepts dotenv | json | yaml | shell | appsettings, and controls what vaultic export / vaultic sync write. export.include/export.exclude are glob patterns applied against secret keys — handy if a project only wants a subset of an environment's secrets materialized locally.

export.delimiter and export.section only apply to format: appsettings — see Local file sync for how the nested-key convention, merge behavior, and --check staleness checksum work for that format. export.pascal_case is reserved for a future key-casing transform and currently has no effect; appsettings keys are always written uppercase, as-is.

Environment variables

VariableUsed byDefault
VAULTIC_API_URLServer URL resolution (all commands)https://vaultic.dev/api (or the URL saved from your last vaultic login)
VAULTIC_WEB_URLvaultic workspace invite (builds the accept-invite link) — overrides the server's own webAppUrl (from /auth/providers) if sethttp://localhost:5173
GITHUB_TOKENvaultic push github (if --token not passed)—
VERCEL_TOKENvaultic push vercel (if --token not passed)—

Credentials from vaultic login are stored at ~/.vaultic/credentials.json (mode 0600): serverUrl, token, and optionally email.

On this page