Vaultic
Command Line

Workspace, access & tokens

Workspace membership and roles, per-project access grants, and service tokens.

Workspace: vaultic workspace

Workspace-wide membership and roles.

workspace invite

workspace invite <email>
FlagDescription
-r, --role <role>admin | developer | read-only (default developer)

Prints an accept-invite link built from the server's own configured web app URL (the same webAppUrl the browser-login flow uses, from /auth/providers — so it already includes any path prefix the server is served under, e.g. the hosted instance's /app), or VAULTIC_WEB_URL if set, or http://localhost:5173 as a last resort.

workspace invites

Lists pending invites. No options.

workspace revoke-invite

workspace revoke-invite <inviteId>

No options.

workspace members

Lists workspace members. No options.

workspace set-role

workspace set-role <email> <role>

Positional role: owner | admin | developer | read-only. No flags.

workspace remove-member

workspace remove-member <email>

No options.

workspace accept-invite

workspace accept-invite <token>

Redeems an invite link as the currently logged-in user. No options.

Access grants: vaultic access

Per-project/per-environment access, layered on top of workspace-wide roles — for giving someone access to one project (or even one environment within it) without making them a full workspace member-level role everywhere.

access grant

access grant <email>
FlagDescription
-r, --role <role>developer | read-only (default developer)
-e, --env <environment>Scope the grant to a single environment (default: whole project)

access list

Lists access grants for the current project. No options.

access revoke

access revoke <grantId>

No options.

Service tokens: vaultic tokens

Scoped tokens for CI/deploys — used by export/run without a human login. Service-token reads never consult personal overrides.

tokens create

tokens create <name>
FlagDescription
-e, --env <environment>Scope to a single environment
--read-onlyRead-only token (default is read/write)
--expires <days>e.g. 90d

Prints the token once — store it immediately, it isn't retrievable again.

tokens list

Shows id/name/access/status (revoked / expired / active). No options.

tokens revoke

tokens revoke <tokenId>

No options.

Agents: vaultic agent

Registered AI/MCP agent identities — a standing scope ceiling plus short-lived, task-scoped sessions that attribute every action to both the agent and the human who authorised it. Every agent connected through the MCP Server's HTTP connector gets one of these automatically on approval; these commands are for managing them directly, or for registering one by hand with a specific scope. See Access, Team & Tokens for the concepts. Everything here requires ADMIN/OWNER.

agent create

agent create <name> --owner <email>
FlagDescription
--owner <email>Required — the human accountable for this agent
-p, --project <slug>Scope to a single project
-e, --env <environment>Scope to a single environment (requires --project)
--writeWrite access (default is read-only)
--keys <patterns...>Key allowlist globs, e.g. DEPLOY_*
--max-session <duration>Ceiling on a session's duration, e.g. 30m (default 1h)
--max-actions <n>Ceiling on a session's action count (default 500)

agent list

Shows id/name/owner/scope/access/active session count/status. No options.

agent disable

agent disable <name>

Immediately invalidates the agent's active sessions. No options.

agent sessions

agent sessions <name>

Lists the agent's sessions — active and recent history. No options.

agent session start

agent session start <agent>
FlagDescription
--purpose <text>Shown in the sessions panel
--duration <duration>e.g. 15m — clamped to the agent's configured ceiling
-p, --project <slug>Narrow the agent's standing scope for this session
-e, --env <environment>Narrow the agent's standing scope for this session
--keys <patterns...>Narrow the agent's key allowlist for this session

Prints the session token once — store it immediately, it isn't retrievable again.

agent session end

agent session end <agent> <sessionId>

No options.

Access reviews: vaultic access-review

Periodic, evidence-producing reviews of every member, access grant, and service token in the workspace — see Access reviews for the concepts and web UI. Workspace-scoped, same as tokens/access above.

access-review list

Lists campaigns with id, name, status, and reviewed/total progress. No options.

access-review create

access-review create
FlagDescription
--name <name>Required, e.g. "Q3 2026"
--project <slug>Narrow to a project — repeatable; omit for the whole workspace
--due <date>ISO date, e.g. 2026-09-30
--recurrence <recurrence>quarterly | annually — recreates the campaign automatically once it completes

Creates a DRAFT campaign — nothing is enumerated for review until start.

access-review start

access-review start <campaignId>

Notifies every assigned reviewer (in-app + email) and moves the campaign to ACTIVE.

access-review items

access-review items <campaignId>
FlagDescription
--mineOnly items assigned to you

The --mine view is what makes CLI-based review practical for engineering-led teams who won't open the dashboard.

access-review certify

access-review certify <campaignId> <itemId>
FlagDescription
--note <note>Optional

Records the item as reviewed and still needed. No side effect on the underlying access.

access-review revoke

access-review revoke <campaignId> <itemId>
FlagDescription
--note <note>Optional

Immediately removes the underlying access (deletes the grant, revokes the token, or removes the member) through the same code paths — and the same protections, including that a workspace can never be left without an owner — as managing access directly. If execution fails (e.g. that protection triggers), the decision is still recorded with the failure reason attached rather than silently succeeding.

access-review complete

access-review complete <campaignId>

Force-completes an ACTIVE campaign. Items still pending stay pending in the evidence record rather than being silently certified.

access-review export

access-review export <campaignId>
FlagDescription
--format <format>csv | json (default csv)

Prints the campaign's evidence record — every item's snapshot, decision, reviewer, and execution result — to stdout.

On this page