Vaultic

Quickstart

Install the CLI, log in, and inject your first secret into a running process.

Install the CLI

npm install -g @vaultic-dev/cli
vaultic --help

Requires Node.js 20 or later. See CLI overview if you need to point the CLI at a self-hosted server instead of the default.

Log in

vaultic login

Opens a browser to approve the login. Use --no-browser for an email/password prompt, or --token <token> to paste a session or service token directly.

Initialize a project

mkdir my-app && cd my-app
vaultic init

Interactive: pick or create a workspace, then a project, then a default environment. Writes a .vaultic.yaml file — safe to commit, since it only holds slugs and export preferences, never secret values.

Set and read a secret

vaultic secrets set FOO bar
vaultic secrets list

secrets set stores the value encrypted, server-side, as a new version. secrets list shows it masked by default — pass --reveal to see the real value, which is audited as its own event, separate from listing.

Inject it into a process

vaultic run -- printenv FOO

vaultic run fetches secrets and injects them as env vars directly into the subprocess — nothing is written to disk. Prefer it over export + a .env-reading app when you can.

Or, sync to a local file

If your app reads a .env file instead of taking injected env vars directly:

vaultic export      # writes .env (dotenv by default), with a checksum header
vaultic status      # compares your local .env against the server
vaultic sync         # pulls latest values, regenerates .env, runs your post_sync hook

vaultic export --check fails with a nonzero exit code if the local file is stale against the server — drop it into a CI step as a drift guard.

A few things worth knowing up front

Masking is the default everywhere

secrets list / get / history show •••••••• plus the last 4 characters unless you pass --reveal. Revealing is always audited as its own event, distinct from listing.

.vaultic.yaml is safe to commit

It only stores your workspace/project/environment slugs and export preferences — never secret values. See Configuration for the full schema.

Environment resolution, when you don't pass -e/--env

Vaultic checks your local (gitignored) .vaultic.local.yaml's default_environment first, falling back to .vaultic.yaml's default_environment.

Next steps

On this page