CLI reference

Updated

The kryptic binary is both the daemon and its CLI - one file, no dependencies, macOS/Linux/Windows. Source: github.com/dev-kryptic/Kryptic.Daemon. Install it from kryptic.dev/download. Linux can also run curl -fsSL https://kryptic.dev/install.sh | sh. Then kryptic login.

Daemon lifecycle

kryptic start    # run the daemon in the foreground (the service manager calls this)
kryptic stop     # stop the running daemon (pidfile-based, graceful)
kryptic status   # is the daemon up, and who is signed in
kryptic flush    # drop the daemon's 5-minute in-memory secrets cache
kryptic logs     # print the diagnostics log path (send this file to support)
kryptic logs --reveal  # open the diagnostics log in the file manager

start refuses to run when another daemon already holds the pidfile; stop cleans up stale pidfiles left by crashes. flush is what you want after rotating a secret and needing the next local run to see it immediately.

kryptic logs points at …/kryptic/logs/kryptic.krypticlog (2 MiB, one rotated backup). The file records function only: no secrets, tokens, or names. The menu bar and tray also have Reveal Diagnostics Log.

Authentication

kryptic login                 # browser device flow - prints a code, you approve it in the browser
kryptic login --add           # sign in another account without leaving the current one
kryptic login --add --api URL # new account on a different Daemon BFF (self-host vs cloud)
kryptic profile               # list saved accounts on this install
kryptic profile switch EMAIL  # switch the active account (email or profile id)
kryptic profile delete EMAIL  # remove an account from this install
kryptic whoami                # the signed-in user and organization (asks the platform directly)
kryptic logout                # revoke the active account's session
kryptic reset-device          # wipe the active profile's keys
kryptic reset-device --all    # wipe every profile on this install
kryptic panel                 # Open Kryptic (Windows/Linux; on macOS use the menu)

login stores the rotating refresh token in the OS credential store: macOS Keychain, Windows Credential Manager, or libsecret on Linux (0600 file fallback when no store is available). One install can hold personal and work accounts at the same time. Switching the active profile does not sign the other out. The menu bar and tray icon shows a green, amber, or gray status dot: connected, connecting / awaiting approval, or signed out.

Server URL

kryptic config                 # show the active profile's Daemon BFF URL
kryptic config set-api URL     # point this profile at a self-hosted (or local) BFF
kryptic config reset-api       # return this profile to https://daemon.kryptic.dev

Each profile stores its own server URL. Changing one signs that profile out only. KRYPTIC_API overrides every profile for that process. Point it at http://localhost:5237 when the Daemon BFF is running from the IDE, or http://localhost:5211 when you are using the compose kit.

Secrets

kryptic secrets list                                   # projects and environments you can pull
kryptic secrets get DATABASE_URL --project proj_x --env development
kryptic secrets export --project proj_x --env development   # dotenv on stdout, decrypted locally

secrets get prints the value to stdout for piping into other tools. secrets export prints a dotenv of the whole environment. Both go through the running daemon: the platform only ever served ciphertext, and decryption happened on this machine. Reads use the same server-side access checks and audit logging as every other client.

CI export

Pipelines do not talk to the daemon. They authenticate as a machine identity and decrypt locally:

export KRYPTIC_CLIENT_ID=kmi_...
export KRYPTIC_CLIENT_SECRET=...
kryptic ci export --project proj_x --env production [--format dotenv|shell|json]

KRYPTIC_PIPELINES_API overrides the Pipelines BFF URL (default https://pipelines.kryptic.dev). There is no server-side plaintext export: the BFF returns ciphertext plus the machine's sealed org-key grant, and kryptic ci opens them with the Go encryption engine. Ready-to-paste snippets for GitHub Actions, GitLab CI, Azure DevOps, Docker, Compose, and the rest live in the dashboard Client generator and in CI/CD.

Dynamic keys are minted on the runner at export time. The job does not wait for a desktop connector. End the job with kryptic ci revoke (export writes KRYPTIC_DYNAMIC_LEASES) so the role is dropped. See Dynamic secrets.

kryptic ci revoke [--lease ID]...

Connector

kryptic connector run [--name NAME]

Optional leftover reaper for leases this identity created and did not revoke (crash, missed ci revoke). Uses the signed-in daemon session, or KRYPTIC_CLIENT_ID / KRYPTIC_CLIENT_SECRET against the Secrets API (KRYPTIC_SECRETS_API overrides https://secrets.kryptic.dev).

From the menu bar or tray, Operations → Start "Dynamic-Secrets" Connector (same button in Open Kryptic) opens that reaper in a terminal.

Secret scanning

kryptic scan               # scan the working directory
kryptic scan path/to/dir   # scan a specific path
kryptic scan --staged      # scan only lines added in the git index (pre-commit hook)
kryptic scan --export      # write kryptic-scan-report.md in the current directory
kryptic scan --export out/report.md

Runs the gitleaks default ruleset (222 rules) fully locally - nothing leaves your machine. On a terminal you get a 0-100% progress bar. Findings are printed redacted, and a non-zero exit code makes it a CI or pre-commit gate.

--export writes a Markdown report with the Kryptic logo, a summary, and redacted findings. Omit the path to write kryptic-scan-report.md in the directory you ran the command from. Pass a directory to write that filename inside it, or a .md file to use that path.

# .git/hooks/pre-commit (local only: staged files never leave the laptop)
exec kryptic scan --staged

See Secret scanning for the full hook, Lefthook/Husky one-liners, and tray Scan…. There is no Kryptic-hosted hook.

Updating

kryptic version
kryptic update              # replace this binary with the latest published build
kryptic update --check      # report whether a newer release exists (exit 2 if so)
kryptic update --installer  # download the signed installer and open it

update replaces this binary with the latest published build and verifies it against checksums.txt before swapping the file. If you installed with the macOS .pkg or the Windows setup, prefer kryptic.dev/download or kryptic update --installer instead.

Reinstall on Linux

If a previous .deb is still on the machine (App Center shows Kryptic as Installed), remove it first, then install again with the one-liner:

sudo apt remove kryptic
curl -fsSL https://kryptic.dev/install.sh | sh

The new copy lands in ~/.local. Existing sign-in is kept unless you also delete ~/.config/kryptic.