KrypticKryptic

Get started with Kryptic

Install the daemon, add an SDK, and run your app - secrets inject automatically. For the complete reference, open the documentation.

Four steps to inject secrets

  1. 01

    Install the daemon

    Open kryptic.dev/download. It detects your OS and serves the current installer. Linux: curl -fsSL https://kryptic.dev/install.sh | sh. Then kryptic login.

  2. 02

    Add kryptic.json

    Commit a kryptic.json with your project ID to the repo root. No secrets - safe for version control.

  3. 03

    Install the SDK

    Install the Kryptic SDK for your language as a dev dependency and call the inject method at application startup.

  4. 04

    Run your app

    dotnet run, npm run dev, python manage.py runserver - secrets inject automatically over a local socket.

kryptic.json

Safe to commit - contains only the project ID, no secrets or tokens.

{
  "projectId": "proj_a1b2c3d4e5f6",
  "defaultEnvironment": "development"
}

Language SDKs

Each SDK detects the daemon passively and injects secrets idiomatically for its runtime.

dotnet add package Kryptic.Daemon.Client
using Kryptic;

var builder = WebApplication.CreateBuilder(args);
builder.Configuration.AddKryptic();

var dbUrl = builder.Configuration["DATABASE_URL"];

Manage the background client

kryptic statusShow daemon status and authenticated user
kryptic loginRe-authenticate (opens browser)
kryptic logoutRevoke local token and stop daemon
kryptic whoamiPrint current authenticated user and org
kryptic secrets listList secrets for the current project
kryptic secrets get KEYPrint a specific secret value
kryptic scanScan the current directory for leaked secrets
kryptic scan --exportScan and write a Markdown report in the current directory

SDK configuration overrides

Environment variables take precedence over kryptic.json settings.

VariableDefaultDescription
KRYPTIC_ENVdevelopmentOverride the environment to fetch secrets from
KRYPTIC_PROJECT_ID(from kryptic.json)Override the project ID
KRYPTIC_SOCKET_PATH(OS default)Override the daemon socket path
KRYPTIC_TIMEOUT_MS2000Daemon connection timeout in milliseconds
KRYPTIC_DISABLEDfalseSet to 'true' to disable Kryptic entirely
KRYPTIC_SILENTfalseSuppress all Kryptic console output

Pipelines via machine identities

Store the client id and secret in GitHub (or any other runner). The job decrypts on the runner with kryptic ci export. Copy a ready-to-paste snippet from the dashboard Client generator.

- name: Load secrets from Kryptic
  env:
    KRYPTIC_CLIENT_ID: ${{ secrets.KRYPTIC_CLIENT_ID }}
    KRYPTIC_CLIENT_SECRET: ${{ secrets.KRYPTIC_CLIENT_SECRET }}
  run: |
    eval "$(kryptic ci export --project proj_a1b2c3 --env staging --format shell)"