Vaultic
Command Line

Sharing & webhooks

One-time share links, and workspace-level webhook subscriptions.

vaultic share

vaultic share <key>

Generates a one-time/limited-view link to a secret's current value — no auth needed to view it. The link snapshots the resolved value at creation time, so rotating the underlying secret afterward doesn't change what an outstanding link reveals.

FlagDescription
-e, --env <environment>
--expires <duration>e.g. 1h, 30m, 2d
--max-views <n>Number of times the link can be viewed

Prints <serverUrl>/share/<token> with an expiry/max-views annotation.

Prefer a GUI? The web app has the same flow behind each secret row's Share link action — see Share links.

vaultic webhooks

Workspace-level webhook subscriptions — generic HMAC-signed JSON, or Slack-formatted.

webhooks create

webhooks create <url>
FlagDescription
--events <events>Required. Comma-separated event names, e.g. secret.created,secret.updated
--slackFormat deliveries as a Slack message instead of signed JSON

Prints the signing secret once, if one is returned — store it immediately.

webhooks list

No options.

webhooks delete

webhooks delete <id>

No options.

webhooks deliveries

webhooks deliveries <id>

Lists delivery attempts: timestamp, event, ok/FAILED, status code, duration, error. No options.

Event catalog

EventFires on
secret.created / secret.updated / secret.deleted / secret.restoredWrites to a secret, including restoring one from trash
secret.revealedSomeone reveals a secret's real value (--reveal, or the web app's Reveal button)
secret.rotatedA rotation provider successfully rotates a secret
secret.expiring / secret.expired / secret.rotation_dueLifecycle state changes, each firing at most once per state
environment.created / environment.duplicated / environment.promoted / environment.expiredEnvironment lifecycle, including ephemeral-environment expiry
token.created / token.revokedService token lifecycle
member.invited / member.joined / member.removed / member.role_changedWorkspace membership changes
cloudsync.applied / cloudsync.failedA cloud secret store sync push succeeds or fails, automatic or manual

Pass whichever you need to --events as a comma-separated list.

See Webhooks & audit log for the equivalent web app view and the workspace-wide audit log.

On this page