Sharing & webhooks
One-time share links, and workspace-level webhook subscriptions.
vaultic share
vaultic share <key>Generates a one-time/limited-view link to a secret's current value — no auth needed to view it. The link snapshots the resolved value at creation time, so rotating the underlying secret afterward doesn't change what an outstanding link reveals.
| Flag | Description |
|---|---|
-e, --env <environment> | |
--expires <duration> | e.g. 1h, 30m, 2d |
--max-views <n> | Number of times the link can be viewed |
Prints <serverUrl>/share/<token> with an expiry/max-views annotation.
Prefer a GUI? The web app has the same flow behind each secret row's Share link action — see Share links.
vaultic webhooks
Workspace-level webhook subscriptions — generic HMAC-signed JSON, or Slack-formatted.
webhooks create
webhooks create <url>| Flag | Description |
|---|---|
--events <events> | Required. Comma-separated event names, e.g. secret.created,secret.updated |
--slack | Format deliveries as a Slack message instead of signed JSON |
Prints the signing secret once, if one is returned — store it immediately.
webhooks list
No options.
webhooks delete
webhooks delete <id>No options.
webhooks deliveries
webhooks deliveries <id>Lists delivery attempts: timestamp, event, ok/FAILED, status code, duration, error. No options.
Event catalog
| Event | Fires on |
|---|---|
secret.created / secret.updated / secret.deleted / secret.restored | Writes to a secret, including restoring one from trash |
secret.revealed | Someone reveals a secret's real value (--reveal, or the web app's Reveal button) |
secret.rotated | A rotation provider successfully rotates a secret |
secret.expiring / secret.expired / secret.rotation_due | Lifecycle state changes, each firing at most once per state |
environment.created / environment.duplicated / environment.promoted / environment.expired | Environment lifecycle, including ephemeral-environment expiry |
token.created / token.revoked | Service token lifecycle |
member.invited / member.joined / member.removed / member.role_changed | Workspace membership changes |
cloudsync.applied / cloudsync.failed | A cloud secret store sync push succeeds or fails, automatic or manual |
Pass whichever you need to --events as a comma-separated list.
See Webhooks & audit log for the equivalent web app view and the workspace-wide audit log.