CLI reference
Updated
The kryptic binary is both the daemon and its CLI - one file, no dependencies,
macOS/Linux/Windows. Source:
github.com/dev-kryptic/Kryptic.Daemon.
Install it from kryptic.dev/download.
Linux can also run curl -fsSL https://kryptic.dev/install.sh | sh. Then kryptic login.
Daemon lifecycle
kryptic start # run the daemon in the foreground (the service manager calls this)
kryptic stop # stop the running daemon (pidfile-based, graceful)
kryptic status # is the daemon up, and who is signed in
kryptic flush # drop the daemon's 5-minute in-memory secrets cache
kryptic logs # print the diagnostics log path (send this file to support)
kryptic logs --reveal # open the diagnostics log in the file manager
start refuses to run when another daemon already holds the pidfile; stop cleans up
stale pidfiles left by crashes. flush is what you want after rotating a secret and
needing the next local run to see it immediately.
kryptic logs points at …/kryptic/logs/kryptic.krypticlog (2 MiB, one rotated
backup). The file records function only: no secrets, tokens, or names. The menu
bar and tray also have Reveal Diagnostics Log.
Authentication
kryptic login # browser device flow - prints a code, you approve it in the browser
kryptic login --add # sign in another account without leaving the current one
kryptic login --add --api URL # new account on a different Daemon BFF (self-host vs cloud)
kryptic profile # list saved accounts on this install
kryptic profile switch EMAIL # switch the active account (email or profile id)
kryptic profile delete EMAIL # remove an account from this install
kryptic whoami # the signed-in user and organization (asks the platform directly)
kryptic logout # revoke the active account's session
kryptic reset-device # wipe the active profile's keys
kryptic reset-device --all # wipe every profile on this install
kryptic panel # Open Kryptic (Windows/Linux; on macOS use the menu)
login stores the rotating refresh token in the OS credential store: macOS Keychain,
Windows Credential Manager, or libsecret on Linux (0600 file fallback when no store
is available). One install can hold personal and work accounts at the same time.
Switching the active profile does not sign the other out. The menu bar and tray
icon shows a green, amber, or gray status dot: connected, connecting / awaiting
approval, or signed out.
Server URL
kryptic config # show the active profile's Daemon BFF URL
kryptic config set-api URL # point this profile at a self-hosted (or local) BFF
kryptic config reset-api # return this profile to https://daemon.kryptic.dev
Each profile stores its own server URL. Changing one signs that profile out
only. KRYPTIC_API overrides every profile for that process. Point it at
http://localhost:5237 when the Daemon BFF is running from the IDE, or
http://localhost:5211 when you are using the compose kit.
Secrets
kryptic secrets list # projects and environments you can pull
kryptic secrets get DATABASE_URL --project proj_x --env development
kryptic secrets export --project proj_x --env development # dotenv on stdout, decrypted locally
secrets get prints the value to stdout for piping into other tools. secrets export
prints a dotenv of the whole environment. Both go through the running daemon: the
platform only ever served ciphertext, and decryption happened on this machine.
Reads use the same server-side access checks and audit logging as every other client.
CI export
Pipelines do not talk to the daemon. They authenticate as a machine identity and decrypt locally:
export KRYPTIC_CLIENT_ID=kmi_...
export KRYPTIC_CLIENT_SECRET=...
kryptic ci export --project proj_x --env production [--format dotenv|shell|json]
KRYPTIC_PIPELINES_API overrides the Pipelines BFF URL (default
https://pipelines.kryptic.dev). There is no server-side plaintext export: the BFF
returns ciphertext plus the machine's sealed org-key grant, and kryptic ci opens
them with the Go encryption engine. Ready-to-paste snippets for
GitHub Actions, GitLab CI, Azure DevOps, Docker, Compose, and the rest live in
the dashboard Client generator and in CI/CD.
Dynamic keys are minted on the runner at export time. The job does not wait
for a desktop connector. End the job with kryptic ci revoke (export writes
KRYPTIC_DYNAMIC_LEASES) so the role is dropped. See
Dynamic secrets.
kryptic ci revoke [--lease ID]...
Connector
kryptic connector run [--name NAME]
Optional leftover reaper for leases this identity created and did not revoke
(crash, missed ci revoke). Uses the signed-in daemon session, or
KRYPTIC_CLIENT_ID / KRYPTIC_CLIENT_SECRET against the Secrets API
(KRYPTIC_SECRETS_API overrides https://secrets.kryptic.dev).
From the menu bar or tray, Operations → Start "Dynamic-Secrets" Connector (same button in Open Kryptic) opens that reaper in a terminal.
Secret scanning
kryptic scan # scan the working directory
kryptic scan path/to/dir # scan a specific path
kryptic scan --staged # scan only lines added in the git index (pre-commit hook)
kryptic scan --export # write kryptic-scan-report.md in the current directory
kryptic scan --export out/report.md
Runs the gitleaks default ruleset (222 rules) fully locally - nothing leaves your machine. On a terminal you get a 0-100% progress bar. Findings are printed redacted, and a non-zero exit code makes it a CI or pre-commit gate.
--export writes a Markdown report with the Kryptic logo, a summary, and redacted
findings. Omit the path to write kryptic-scan-report.md in the directory you ran
the command from. Pass a directory to write that filename inside it, or a .md
file to use that path.
# .git/hooks/pre-commit (local only: staged files never leave the laptop)
exec kryptic scan --staged
See Secret scanning for the full hook, Lefthook/Husky one-liners, and tray Scan…. There is no Kryptic-hosted hook.
Updating
kryptic version
kryptic update # replace this binary with the latest published build
kryptic update --check # report whether a newer release exists (exit 2 if so)
kryptic update --installer # download the signed installer and open it
update replaces this binary with the latest published build and verifies it against
checksums.txt before swapping the file. If you installed with the macOS .pkg or the
Windows setup, prefer kryptic.dev/download or
kryptic update --installer instead.
Reinstall on Linux
If a previous .deb is still on the machine (App Center shows Kryptic as
Installed), remove it first, then install again with the one-liner:
sudo apt remove kryptic
curl -fsSL https://kryptic.dev/install.sh | sh
The new copy lands in ~/.local. Existing sign-in is kept unless you also
delete ~/.config/kryptic.