Secrets management your team, your CI, and your agents can trust.
Versioned, envelope-encrypted secrets across workspaces, projects, and environments. A CLI that injects them straight into your process, and an MCP connector that gives agents the same scoped, audited access — never a plaintext file on disk. Approvals, audit logs, and rotation built in, not bolted on.
$ vaultic login ✓ Signed in as you@company.com $ vaultic secrets set STRIPE_KEY sk_live_••• ✓ Stored in production (v4) $ vaultic run -- node server.js ✓ Injected 12 secrets from production $
Everything a secrets store should do
Workspaces → projects → environments, with versioned, encrypted values at every level and a matrix view to see what's set where.
Core
Versioned, encrypted secrets
Every write is a new version. Nothing is ever silently overwritten or lost.
Environment matrix
See every secret across every environment in one view — and what's missing.
Inheritance & promote
Personal or preview environments fall through to their parent for anything they don't override, then promote up when ready.
References & interpolation
Point one secret at another instead of copy-pasting values across environments.
Expiry & rotation reminders
Set an expiry or rotation interval and get nagged — in the CLI and the dashboard — before a secret goes stale.
Grace-window rotation
Rotate a secret and still serve the previous value for a grace window, so in-flight deploys don't break.
Trust & safety
Locking & change approvals
Lock an environment and require a second set of eyes before a change to production takes effect.
Write/reveal audit log
Every write — and every reveal — is logged separately from a masked list, so you know exactly who saw what.
30-day trash & restore
Deleted a secret by mistake? It's recoverable for 30 days, not gone.
One-time share links
Hand a single secret to someone outside the team without adding them as a member.
Secrets Health dashboard
Stale secrets, expired reminders, and inactive configs, all in one place.
Scoped access & roles
Workspace-wide roles plus per-project and per-environment grants, with link-based invites.
Automation & integrations
Webhooks & Slack
secret.rotated, secret.expiring, and other events fire
webhooks and Slack notifications.
GitHub Actions & Vercel sync
Push secrets straight into the platforms your deploys already run on.
Ephemeral preview environments
An inbound GitHub webhook spins up a preview environment per branch or PR, and tears it down after.
Terraform provider
Manage workspaces, projects, and secrets as code alongside the rest of your infra.
Kubernetes operator
Sync secrets into cluster resources natively, without a sidecar.
Service tokens
Scoped, revocable tokens for CI and services — no human credentials in a pipeline.
Simple, per-seat pricing
Free to start. €6 per seat a month (excl. VAT) once your team needs more — machine identities are always unlimited, on every plan.
Free
€0/mo
Core secrets, environments, CLI, API, MCP agent access, and rotation reminders.
- Owned workspaces2
- Projects / workspace3
- Members / workspace5
- Base environments / project3
- Audit log retention30 days
- Service tokensUnlimited
- —Provider-assisted rotation execution
- —Change requests & approvals
- —Webhooks & syncs
- —Trusted IPs
- —Secret share links
- —SSO
Team
€6/seat/mo
excl. VAT (HT)
Everything in Free, unlimited, plus the workflow features a growing team needs.
- Owned workspacesUnlimited
- Projects / workspaceUnlimited
- Members / workspaceUnlimited
- Base environments / projectUnlimited
- Audit log retention90 days
- Service tokensUnlimited
- Provider-assisted rotation execution
- Change requests & approvals
- Webhooks & syncs
- Trusted IPs
- Secret share links
- SSO
Enterprise
Contact us
Everything in Team, deployed the way your compliance team requires.
- DeploymentSelf-hosted or our cloud
- InfrastructureYours, or fully managed by us
- SupportDedicated, contract-backed
- Everything in Team, unlimited
- Self-hosted on your own infrastructure
- Or fully managed, hosted in our cloud
- Custom contract & support terms
Prices shown are excl. VAT (HT) — VAT or local sales tax is calculated automatically at checkout based on your billing location. Billed monthly through Stripe — manage seats or cancel anytime from workspace settings. Seat count follows your member count automatically. Full plan comparison →
Give your agents secrets, not your .env file
Vaultic hosts an MCP connector so Claude — or any other MCP client — connects over HTTPS with OAuth and reads/writes secrets through the same scoped, audited path as your CLI and web UI. No JSON config, no token pasted into a dotfile, no agent ever opening a local secrets file.
- Add it from Settings → Connectors with a URL — the same way you'd add any remote MCP connector.
- Scoped service tokens — read-only by default, pinned to one project and one environment.
-
Every agent call is tagged
source: mcpin the audit log — distinct fromcli,ui, andapiactivity. - Reveals are audited separately from masked listings — an agent that lists secrets isn't the same log line as one that reads a value.
Paste your workspace's Vaultic connector URL.
Pick a workspace, project, environment, and read-only or write.
Vaultic mints it behind the OAuth exchange — Claude never sees it, and it's never written to a file.
Tagged source: mcp in the audit log, same as the CLI and web UI.
Encrypted at every layer, not behind a single shared key
Every secret you store goes through three layers of encryption before it ever touches disk — each layer scoped narrower than the last.
Three separate keys, three separate jobs — compromising one layer never hands over the others. Change proposals on locked environments get their own fresh key before an approver ever sees the value.
A CLI that fits your existing workflow
Init a project, and secrets flow into your process with one command — locally and in CI.
$ vaultic init ✓ Linked ./my-app to acme/api/development $ vaultic run --watch -- npm run dev ✓ Watching for secret changes, live-reloading $ vaultic export --check ✓ .env matches the server — safe to deploy $
Start free. Upgrade when your team needs it.
No credit card for Free. Team is €6/seat/mo excl. VAT, billed through Stripe.