@vaultic-dev/cli
v0.1.12
Published
Command-line client for Vaultic — encrypted, versioned secrets management with environment inheritance, rotation, and audit logging.
Readme
@vaultic-dev/cli
Command-line client for Vaultic — encrypted,
versioned secrets management with environment inheritance, rotation, and audit logging. This
package installs the vaultic binary; it talks to a Vaultic server over the REST API and never
handles crypto itself beyond decrypting values already fetched over the wire.
This repo holds the CLI only. The server, web app, and the rest of Vaultic live in the (private, for now) main vaultic-dev/vaultic repo.
Install
npm install -g @vaultic-dev/cli
vaultic --helpRequires Node.js >= 20. You'll also need a Vaultic server to talk to — either your own self-hosted instance, or one your team runs (see the main repo README for self-hosting instructions).
Quick start
vaultic login # opens a browser to approve the login (--no-browser for the
# email/password prompt, --token to paste one)
vaultic init # interactive: pick/create workspace -> project -> default env
# writes .vaultic.yaml in the current directory
vaultic secrets set FOO bar # stored encrypted server-side, versioned
vaultic secrets list # masked by default
vaultic secrets list --reveal # explicit reveal, audited separately from list/read
vaultic run -- printenv FOO # injects secrets as env vars into the subprocess -> "bar"
vaultic export # writes .env (dotenv format) with a checksum header
vaultic status # compares local .env vs the server
vaultic sync # pulls latest values, regenerates .env, runs post_sync hookBy default, vaultic --server <url> (or the VAULTIC_API_URL env var) points at your server;
otherwise it defaults to http://localhost:4000.
Command reference
| Group | Commands |
|---|---|
| Auth | login, logout, whoami |
| Project setup | init (writes .vaultic.yaml) |
| Secrets | secrets list/get/set/delete/history/rollback/rename/rotate/substitute, secrets override set/clear, rotation-providers |
| Local file sync | run, export, import, status, sync |
| Environments | env list/create/duplicate/diff/promote/lock/unlock/proposals/approve/reject |
| Workspace | workspace invite/invites/revoke-invite/members/set-role/remove-member/accept-invite |
| Access grants | access grant/list/revoke |
| Service tokens | tokens create/list/revoke |
| Sharing | share <key> — one-time/limited-view unauthenticated link |
| Webhooks | webhooks create/list/delete/deliveries |
| Third-party push | push github, push vercel |
| Git integration | git-integration setup/show/remove — ephemeral preview environments |
Run vaultic <command> --help for a command's full options.
Development
npm install
npm run dev -- --help # run from source via tsx, no build step
npm run build # bundles to dist/index.js (tsup)
npm test
npm run typecheckReleasing (maintainers): node scripts/release.mjs [patch|minor|major] bumps the version,
commits, tags, and pushes to main. That push runs the single pipeline in
.github/workflows/ci.yml — typecheck/build/test on every push and PR, plus (only on this kind
of push to main) a publish-to-npm step via OIDC trusted publishing.
