Configuration reference
Updated
kryptic.json
The per-repository project file. It contains no secrets and is committed to version control. Every SDK finds it by walking up from the current working directory, so it also works from subdirectories and monorepo packages.
{
"projectId": "proj_a1b2c3d4e5f6",
"defaultEnvironment": "development"
}
- Name
projectId- Type
- string
- Required
- required
- Accepted values
- Description
The project's public id (
proj_+ 12 hex characters), shown on the project page in the dashboard. Identifies which project's secrets to fetch.
- Name
defaultEnvironment- Type
- string
- Required
- optional
- Accepted values
- Description
The environment the daemon serves when nothing overrides it. Defaults to
development.
Environment variables (SDKs)
Every language SDK honors the same set. Environment variables always win over
kryptic.json and over options passed in code.
- Name
KRYPTIC_PROJECT_ID- Type
- string
- Required
- optional
- Accepted values
- Description
Override the project id from kryptic.json.
- Name
KRYPTIC_ENV- Type
- string
- Required
- optional
- Accepted values
- Description
Override the environment to fetch (e.g.
staging).
- Name
KRYPTIC_SOCKET_PATH- Type
- string
- Required
- optional
- Accepted values
- Description
Override the daemon endpoint. Default:
~/Library/Application Support/kryptic/kryptic-daemon.sockon macOS,$XDG_RUNTIME_DIR/kryptic-daemon.sockon Linux (fallback~/.config/kryptic/kryptic-daemon.sock),\\.\pipe\kryptic-daemonon Windows. Tests use this to point SDKs at a mock daemon.
- Name
KRYPTIC_TIMEOUT_MS- Type
- number
- Required
- optional
- Accepted values
- Description
Daemon connection timeout in milliseconds. Default
2000.
- Name
KRYPTIC_DISABLED- Type
- boolean
- Required
- optional
- Accepted values
- Description
trueforce-disables injection everywhere, before any socket I/O.
- Name
KRYPTIC_SILENT- Type
- boolean
- Required
- optional
- Accepted values
- Description
truesuppresses the one-line warning when the daemon is absent.
SDKs are development-only by design. Each one checks its runtime's idiomatic environment signal and becomes a no-op outside development:
- Node.js:
NODE_ENVset to anything other thandevelopment - .NET:
ASPNETCORE_ENVIRONMENT/DOTNET_ENVIRONMENTnotDevelopment - Python / Go / Ruby / C++ / Rust / Java:
production,prod, orstagingin the language's usual env vars (RAILS_ENV,GO_ENV,RUST_ENV,SPRING_PROFILES_ACTIVE, …)
Daemon and CLI
- Name
KRYPTIC_API- Type
- string
- Required
- optional
- Accepted values
- Description
Point the daemon at a self-hosted (or local) Daemon BFF. Overrides the URL saved by
kryptic config set-api. Defaulthttps://daemon.kryptic.dev. Local compose useshttp://localhost:5211.dotnet run/ the IDE listens onhttp://localhost:5237.
- Name
KRYPTIC_CLIENT_ID- Type
- string
- Required
- optional
- Accepted values
- Description
Machine identity client id (
kmi_…). Required bykryptic ci export.
- Name
KRYPTIC_CLIENT_SECRET- Type
- string
- Required
- optional
- Accepted values
- Description
Machine identity client secret. Required by
kryptic ci export. Shown once at creation in the dashboard.
- Name
KRYPTIC_PIPELINES_API- Type
- string
- Required
- optional
- Accepted values
- Description
Override the Pipelines BFF URL used by
kryptic ci export. Defaulthttps://pipelines.kryptic.dev. Self-hosted compose useshttp://localhost:5212.