KrypticKryptic

Log in once, then press run

No wrapper command and no .env file. A local daemon injects secrets when you start the app the way you already do.

What each role gets

Developers

F5, npm run dev, dotnet run

Log in once, hit F5 or npm run dev, and your app just has its secrets. No prefix, no ritual, no .env.

DevOps

Pipelines and pods are not seats

Pipelines, operators, and containers get their own free identities. Your life just got simpler, and your bill did not grow with your infrastructure.

DevSecOps

Nothing on disk to police

Nothing on disk, end-to-end encrypted, and no wrapper command to chase across teams.

Security & compliance

You audit who did what, when.

Every mutation and every fetch is logged and exportable; secret values never are.

IT admins

You onboard people in two clicks.

SSO and SCIM handle joiners and leavers automatically, and one deactivation revokes every session instantly.

What this platform exists to do

Every engineering team has the same three problems. New developers wait days for someone to paste them the right .env file. Secrets drift through Slack threads, wikis, and Git history. And the tools built to fix this ask developers to change their habits: prefix every command, template every config, learn another CLI.

You set it up, paste your secrets into a dialog once, and then leave it alone. Your app starts the way it always did, with the secrets it needs, and there is nothing on disk to steal.

How it works, precisely

1 · Login once

The daemon runs quietly in the background (LaunchAgent, systemd, or Windows tray) and keeps its refresh token in the OS keychain. You sign in once per device.

2 · One line, committed once

Your repo carries a commit-safe kryptic.json and a single package call at startup: .NET, Node.js, Python, Java, Go, Ruby, or C++.

3 · Local decrypt, local socket

At startup the package connects to the daemon over an OS-level socket restricted to your user. The daemon fetches ciphertext, decrypts it locally with the org key grant, and injects values into your process. Nothing touches disk.

4 · Passive by design

Explicit environment variables always win, the package is a no-op in production and staging, and if the daemon is not running your app still starts. Zero runtime dependency in production.

That is the whole developer experience. dotnet run, npm run dev, or F5 in your IDE just work. There is no vendor run -- prefix to remember, and no crash when someone forgets it, because there is nothing to forget.

How we make it secure

Keys live with you, not us

The 32-byte organization key is generated in your admin's browser and exists in plaintext only on your devices, runners, and clusters. It reaches authorized people and machines as P-256 sealed-box grants; passphrases are hardened with Argon2id.

AES-256-GCM envelopes, audited fetches

Every value is sealed in an authenticated envelope bound to its secret and environment. Every mutation and every ciphertext fetch lands in the audit log. Values are never logged, anywhere.

Nothing on disk, ever

Decrypted values live in daemon memory for at most five minutes and inside your running process. There is no .env file for malware, backups, or AI coding agents to find.

Open source on the plaintext path

Encryption engines are Apache-2.0, the daemon and CLI are GPL-3.0. Built-in secret scanning with 222 detection rules catches keys before they reach Git. Cloud is hosted in the EU (Germany), and Business and Enterprise can self-host entirely.

Onboarding 1,000 developers is one instruction

IT admins stop distributing credentials. DevSecOps managers stop wondering which ex-employee still has a copy of production keys in a dotfile. Developers get access to exactly the projects and environments they were assigned, through roles, groups, and per-environment grants, and request more access in-product instead of over tickets. Every organization gets Owner, Admin, Developer, and Viewer. Enterprise can edit those bags or create new roles (custom RBAC); Owner stays locked.

Connect SCIM to your directory and joiners are provisioned automatically, while leavers lose every browser and daemon session the moment HR deactivates them. Google, Microsoft, and GitHub SSO are included on every plan, including Free. SAML 2.0, SCIM 2.0, and shared org secrets are included at Business, at 22 euros per developer per month, a tier where much of the industry still points you to a sales call.

Humans are the only seats

Modern infrastructure pairs every developer with dozens of machines: CI pipelines, preview deployments, Kubernetes pods, background services. Platforms that bill per identity turn every new container into a line item. Kryptic never charges for machine identities, on any plan. They authenticate with their own short-lived credentials, they are scoped, rotatable, and audited, and they cost nothing.

The Free plan covers up to 3 developers with unlimited machine identities and SSO included. Team is 12 euros per developer for up to 25 seats, Business is 22 for up to 200 seats with SAML, SCIM, and shared org secrets, and Enterprise is unlimited seats plus custom RBAC. Both paid self-serve plans come with a 14-day trial that starts without a credit card; add a payment method before it ends or the organization returns to Free.

Where Kryptic sits among secrets tools

Three different problems, three different tools

Kryptic (daemon-first)CLI-wrapper platformsAI agent proxies
Built forDevelopers, DevOps, IT adminsDevelopers willing to change workflowUntrusted autonomous AI agents
Daily usageRun apps as usual, F5 includedPrefix every command or embed an SDK API callRoute agent traffic through a proxy
Delivery mechanismLocal daemon + one-line package over a local socketWrapper process or cloud API callFake tokens swapped at the network edge
Server can read secretsNo: ciphertext only, no decrypt pathVaries by vendor and configurationYes: the proxy holds real credentials
Machine identity costFree and unlimited, never a seatOften billed per identityVaries
Protects against.env leakage, repo and chat sprawl, stale offboardingSame goals, with workflow frictionPrompt-injection exfiltration by agents

If the problem is autonomous AI agents holding their own outbound API credentials, an agent proxy is the right category and complements Kryptic. If the problem is people, laptops, pipelines, and clusters, that is the job Kryptic does.

Named matchups: Kryptic vs Doppler, Kryptic vs Infisical, Kryptic vs HashiCorp Vault, Kryptic vs AWS Secrets Manager, and the Doppler / Infisical alternative pages. See the 2026 ranking.

Questions teams ask when comparing

How is Kryptic different from Infisical, Doppler, or HashiCorp Vault?

Kryptic is daemon-first: after one login, a background daemon and a one-line language package inject secrets into your app at startup over a local socket, so plain "npm run dev" or F5 in your IDE just works. Infisical and Doppler deliver local secrets primarily through a wrapper command (like "infisical run --" or "doppler run --") or a cloud SDK call, and HashiCorp Vault is low-level infrastructure that needs a platform team to operate. Kryptic is also end-to-end encrypted with no server-side decryption path, includes SSO on the free plan, and never bills machine identities.

Does Kryptic charge for machine identities?

No. Machine identities for CI/CD pipelines, Kubernetes operators, containers, servers, and AI agents are unlimited and free on the Free, Team, and Business plans, and included org-wide on Enterprise. They never consume a developer seat, so the bill scales with headcount instead of infrastructure size.

Do I need to prefix my commands with a CLI wrapper to get secrets?

No. There is no wrapper command in Kryptic. You log in once, your repo carries a commit-safe kryptic.json plus one line of package code, and every normal way of starting your app (dotnet run, npm run dev, F5 in the IDE) receives its secrets automatically from the local daemon.

Can Kryptic servers read my secrets?

No. Kryptic is end-to-end encrypted. Secret values are sealed with AES-256-GCM using an organization key that is generated in your browser and only ever exists in plaintext on your devices, CI runners, and clusters. The servers store ciphertext and have no decryption path for secret values. The encryption engines, daemon, and CLI are open source so this is verifiable.

Does Kryptic protect secrets from AI coding agents?

Yes, at the filesystem level. Coding assistants and autonomous agents index repositories, dotfiles, and shell history. With Kryptic there is no .env file on disk to read or leak: secrets exist as ciphertext in the cloud and as short-lived plaintext inside your running process. This is complementary to network-edge agent proxies (such as Infisical Agent Proxy), which solve a different problem: giving untrusted autonomous agents fake tokens and swapping them at an outbound HTTP boundary.

Is SSO an enterprise feature in Kryptic?

No. Google, Microsoft, and GitHub single sign-on are included on every plan, including the free tier. SAML 2.0, SCIM 2.0 provisioning, and shared org secrets are included in the Business plan at 22 euros per developer per month and in Enterprise, without requiring a custom enterprise contract.

Is custom RBAC an enterprise feature in Kryptic?

Yes. Every organization gets four default roles: Owner, Admin, Developer, and Viewer. Owner is locked and always has every permission. Enterprise can edit Admin, Developer, and Viewer, and can create new roles from the action-level permission catalog. Business and lower plans assign the four defaults only. Self-hosted Enterprise licences include Advanced RBAC on the signed key.

What are shared org secrets in Kryptic?

The organization catalog holds keys many projects can point at, such as AWS or Stripe credentials. Owners and admins author that catalog. A project key of type Org reference maps each project environment to a catalog environment. Managing the catalog and creating new project links is included on Business and Enterprise. If the organization falls back to Free or Team, existing links keep resolving and you can still unlink them, but you cannot add new catalog keys or new project links until you upgrade again.

How does onboarding and offboarding work at scale?

Onboarding is one instruction: install Kryptic and log in. The developer immediately has the secrets of exactly the projects and environments they were assigned. With SCIM connected to your directory, provisioning and deprovisioning are automatic, and deactivating a user instantly revokes every browser and daemon session. No .env files were ever distributed, so nothing needs to be rotated in a panic when someone leaves.

What happens in production? Does Kryptic add a runtime dependency?

No. The language packages are automatic no-ops in production and staging, and explicitly set environment variables always win. Production and CI delivery run through machine identities, the CI export command, the Kubernetes operator, and the REST API, with decryption happening on your runner or in your cluster.

Where is Kryptic hosted, and can I self-host it?

Kryptic cloud runs in the EU (Hetzner, Germany) as the default and only cloud deployment, operated by Theka.dev, an EU company. Business and Enterprise plans can self-host the full platform with Docker Compose or Helm, including air-gapped deployments on Enterprise. The daemon, CLI, and encryption engines are open source.

What does Kryptic cost compared to other secrets managers?

Free covers up to 3 developers with unlimited machine identities and SSO. Team is 12 euros per developer per month for up to 25 developers, Business is 22 euros for up to 200 developers with SAML, SCIM, and shared org secrets, and Enterprise is unlimited seats plus custom RBAC. There is a 14-day trial that starts without a credit card; add a payment method before it ends or the organization returns to Free. Machine identities are never billed, and SSO is on every plan including Free.

Starting with Kryptic is free

Free for up to 3 developers with unlimited machine identities and SSO included.