Get started with Kryptic
Install the daemon, add an SDK, and run your app - secrets inject automatically. For the complete reference, open the documentation.
Four steps to inject secrets
- 01
Install the daemon
Open kryptic.dev/download. It detects your OS and serves the current installer. Linux: curl -fsSL https://kryptic.dev/install.sh | sh. Then kryptic login.
- 02
Add kryptic.json
Commit a kryptic.json with your project ID to the repo root. No secrets - safe for version control.
- 03
Install the SDK
Install the Kryptic SDK for your language as a dev dependency and call the inject method at application startup.
- 04
Run your app
dotnet run, npm run dev, python manage.py runserver - secrets inject automatically over a local socket.
Safe to commit - contains only the project ID, no secrets or tokens.
{
"projectId": "proj_a1b2c3d4e5f6",
"defaultEnvironment": "development"
}Language SDKs
Each SDK detects the daemon passively and injects secrets idiomatically for its runtime.
dotnet add package Kryptic.Daemon.Clientusing Kryptic;
var builder = WebApplication.CreateBuilder(args);
builder.Configuration.AddKryptic();
var dbUrl = builder.Configuration["DATABASE_URL"];Manage the background client
kryptic statusShow daemon status and authenticated userkryptic loginRe-authenticate (opens browser)kryptic logoutRevoke local token and stop daemonkryptic whoamiPrint current authenticated user and orgkryptic secrets listList secrets for the current projectkryptic secrets get KEYPrint a specific secret valuekryptic scanScan the current directory for leaked secretskryptic scan --exportScan and write a Markdown report in the current directorySDK configuration overrides
Environment variables take precedence over kryptic.json settings.
| Variable | Default | Description |
|---|---|---|
| KRYPTIC_ENV | development | Override the environment to fetch secrets from |
| KRYPTIC_PROJECT_ID | (from kryptic.json) | Override the project ID |
| KRYPTIC_SOCKET_PATH | (OS default) | Override the daemon socket path |
| KRYPTIC_TIMEOUT_MS | 2000 | Daemon connection timeout in milliseconds |
| KRYPTIC_DISABLED | false | Set to 'true' to disable Kryptic entirely |
| KRYPTIC_SILENT | false | Suppress all Kryptic console output |
Pipelines via machine identities
Store the client id and secret in GitHub (or any other runner). The job decrypts on the runner with kryptic ci export. Copy a ready-to-paste snippet from the dashboard Client generator.
- name: Load secrets from Kryptic
env:
KRYPTIC_CLIENT_ID: ${{ secrets.KRYPTIC_CLIENT_ID }}
KRYPTIC_CLIENT_SECRET: ${{ secrets.KRYPTIC_CLIENT_SECRET }}
run: |
eval "$(kryptic ci export --project proj_a1b2c3 --env staging --format shell)"