Installation & overview
Install @vaultic-dev/cli and point it at a Vaultic server.
The vaultic CLI is published to npm as @vaultic-dev/cli — the unscoped name vaultic was
already taken (too close to the existing valtio package), so it's scoped under the
vaultic-dev npm account instead. The scoping only affects the package name: installing it still
gets you a plain vaultic binary.
npm install -g @vaultic-dev/cli
vaultic --helpRequires Node.js 20 or later.
Update notices
When run interactively, the CLI checks npm for a newer @vaultic-dev/cli release at most once
every 24 hours (cached under ~/.vaultic/update-check.json) and prints a one-line notice to
stderr if you're behind. It never blocks scripts or CI: the check is skipped whenever stderr
isn't a TTY, and it can also be disabled explicitly with VAULTIC_NO_UPDATE_CHECK=1.
Pointing it at a server
The CLI talks to a Vaultic server over its REST API and never handles cryptography itself beyond decrypting values already fetched over the wire. You'll need either your own self-hosted instance or one your team already runs.
Server URL resolution order:
--server <url>
Only accepted on vaultic login — sets the server for this login and every command after it.
VAULTIC_API_URL environment variable
export VAULTIC_API_URL=https://vaultic.your-team.com/apiThe serverUrl saved from your last vaultic login
Stored at ~/.vaultic/credentials.json (mode 0600) alongside your token.
https://vaultic.dev/api
The default if nothing else is set.
Command groups
Authentication
login, logout, whoami, init
Secrets
set, get, list, delete, history, rollback, rename, rotate, override
Environments
create, duplicate, diff, promote, lock/unlock, change proposals
Local file sync
run, export, import, status, sync
Workspace & access
workspace, access, tokens
Sharing & webhooks
share, webhooks
Configuration schema (.vaultic.yaml) lives on its own page: Configuration.