Vaultic
Command Line

Installation & overview

Install @vaultic-dev/cli and point it at a Vaultic server.

The vaultic CLI is published to npm as @vaultic-dev/cli — the unscoped name vaultic was already taken (too close to the existing valtio package), so it's scoped under the vaultic-dev npm account instead. The scoping only affects the package name: installing it still gets you a plain vaultic binary.

npm install -g @vaultic-dev/cli
vaultic --help

Requires Node.js 20 or later.

Update notices

When run interactively, the CLI checks npm for a newer @vaultic-dev/cli release at most once every 24 hours (cached under ~/.vaultic/update-check.json) and prints a one-line notice to stderr if you're behind. It never blocks scripts or CI: the check is skipped whenever stderr isn't a TTY, and it can also be disabled explicitly with VAULTIC_NO_UPDATE_CHECK=1.

Pointing it at a server

The CLI talks to a Vaultic server over its REST API and never handles cryptography itself beyond decrypting values already fetched over the wire. You'll need either your own self-hosted instance or one your team already runs.

Server URL resolution order:

--server <url>

Only accepted on vaultic login — sets the server for this login and every command after it.

VAULTIC_API_URL environment variable

export VAULTIC_API_URL=https://vaultic.your-team.com/api

The serverUrl saved from your last vaultic login

Stored at ~/.vaultic/credentials.json (mode 0600) alongside your token.

https://vaultic.dev/api

The default if nothing else is set.

Command groups

Configuration schema (.vaultic.yaml) lives on its own page: Configuration.

On this page