Quickstart
Install the CLI, log in, and inject your first secret into a running process.
Install the CLI
npm install -g @vaultic-dev/cli
vaultic --helpRequires Node.js 20 or later. See CLI overview if you need to point the CLI at a self-hosted server instead of the default.
Log in
vaultic loginOpens a browser to approve the login. Use --no-browser for an email/password prompt, or
--token <token> to paste a session or service token directly.
Initialize a project
mkdir my-app && cd my-app
vaultic initInteractive: pick or create a workspace, then a project, then a default environment. Writes a
.vaultic.yaml file — safe to commit, since it only holds slugs and export preferences, never
secret values.
Set and read a secret
vaultic secrets set FOO bar
vaultic secrets listsecrets set stores the value encrypted, server-side, as a new version. secrets list shows
it masked by default — pass --reveal to see the real value, which is audited as its own
event, separate from listing.
Inject it into a process
vaultic run -- printenv FOOvaultic run fetches secrets and injects them as env vars directly into the subprocess —
nothing is written to disk. Prefer it over export + a .env-reading app when you can.
Or, sync to a local file
If your app reads a .env file instead of taking injected env vars directly:
vaultic export # writes .env (dotenv by default), with a checksum header
vaultic status # compares your local .env against the server
vaultic sync # pulls latest values, regenerates .env, runs your post_sync hookvaultic export --check fails with a nonzero exit code if the local file is stale against the
server — drop it into a CI step as a drift guard.
A few things worth knowing up front
Masking is the default everywhere
secrets list / get / history show •••••••• plus the last 4 characters unless you pass
--reveal. Revealing is always audited as its own event, distinct from listing.
.vaultic.yaml is safe to commit
It only stores your workspace/project/environment slugs and export preferences — never secret values. See Configuration for the full schema.
Environment resolution, when you don't pass -e/--env
Vaultic checks your local (gitignored) .vaultic.local.yaml's default_environment first,
falling back to .vaultic.yaml's default_environment.
Next steps
Core concepts
The workspace → project → environment → secret model, inheritance, and versioning.
Command line reference
Every command group: secrets, environments, workspace & access, sharing, sync.
CI/CD & production
Service tokens, export --check, and locking production against direct writes.
Web app
The dashboard view of everything above — the environment matrix, team, and audit log.