Configuration reference

Updated

kryptic.json

The per-repository project file. It contains no secrets and is committed to version control. Every SDK finds it by walking up from the current working directory, so it also works from subdirectories and monorepo packages.

{
  "projectId": "proj_a1b2c3d4e5f6",
  "defaultEnvironment": "development"
}
  • Name
    projectId
    Type
    string
    Required
    required
    Accepted values
    Description

    The project's public id (proj_ + 12 hex characters), shown on the project page in the dashboard. Identifies which project's secrets to fetch.

  • Name
    defaultEnvironment
    Type
    string
    Required
    optional
    Accepted values
    Description

    The environment the daemon serves when nothing overrides it. Defaults to development.

Environment variables (SDKs)

Every language SDK honors the same set. Environment variables always win over kryptic.json and over options passed in code.

  • Name
    KRYPTIC_PROJECT_ID
    Type
    string
    Required
    optional
    Accepted values
    Description

    Override the project id from kryptic.json.

  • Name
    KRYPTIC_ENV
    Type
    string
    Required
    optional
    Accepted values
    Description

    Override the environment to fetch (e.g. staging).

  • Name
    KRYPTIC_SOCKET_PATH
    Type
    string
    Required
    optional
    Accepted values
    Description

    Override the daemon endpoint. Default: ~/Library/Application Support/kryptic/kryptic-daemon.sock on macOS, $XDG_RUNTIME_DIR/kryptic-daemon.sock on Linux (fallback ~/.config/kryptic/kryptic-daemon.sock), \\.\pipe\kryptic-daemon on Windows. Tests use this to point SDKs at a mock daemon.

  • Name
    KRYPTIC_TIMEOUT_MS
    Type
    number
    Required
    optional
    Accepted values
    Description

    Daemon connection timeout in milliseconds. Default 2000.

  • Name
    KRYPTIC_DISABLED
    Type
    boolean
    Required
    optional
    Accepted values
    Description

    true force-disables injection everywhere, before any socket I/O.

  • Name
    KRYPTIC_SILENT
    Type
    boolean
    Required
    optional
    Accepted values
    Description

    true suppresses the one-line warning when the daemon is absent.

SDKs are development-only by design. Each one checks its runtime's idiomatic environment signal and becomes a no-op outside development:

  • Node.js: NODE_ENV set to anything other than development
  • .NET: ASPNETCORE_ENVIRONMENT / DOTNET_ENVIRONMENT not Development
  • Python / Go / Ruby / C++ / Rust / Java: production, prod, or staging in the language's usual env vars (RAILS_ENV, GO_ENV, RUST_ENV, SPRING_PROFILES_ACTIVE, …)

Daemon and CLI

  • Name
    KRYPTIC_API
    Type
    string
    Required
    optional
    Accepted values
    Description

    Point the daemon at a self-hosted (or local) Daemon BFF. Overrides the URL saved by kryptic config set-api. Default https://daemon.kryptic.dev. Local compose uses http://localhost:5211. dotnet run / the IDE listens on http://localhost:5237.

  • Name
    KRYPTIC_CLIENT_ID
    Type
    string
    Required
    optional
    Accepted values
    Description

    Machine identity client id (kmi_…). Required by kryptic ci export.

  • Name
    KRYPTIC_CLIENT_SECRET
    Type
    string
    Required
    optional
    Accepted values
    Description

    Machine identity client secret. Required by kryptic ci export. Shown once at creation in the dashboard.

  • Name
    KRYPTIC_PIPELINES_API
    Type
    string
    Required
    optional
    Accepted values
    Description

    Override the Pipelines BFF URL used by kryptic ci export. Default https://pipelines.kryptic.dev. Self-hosted compose uses http://localhost:5212.