Log inGet Vautir

Search the help center, features, guides and more.

Secrets, where your code needs them.

A password or an API key lives in Vautir, not in a .env file, a shell history or a CI setting. The command line hands it to the command that needs it, and to nothing else.

One command, on the same core as every app.

So the server still sees only ciphertext, whatever asks.

  • Secret references

    vautir://vault/item/field names a secret without holding it. Put references in your environment or your config templates, and commit them.

  • Run and inject

    vautir run starts a command with the real values in its environment. vautir inject writes a config file from a template.

  • SSH agent

    Signs with the Ed25519 and ECDSA keys in your vault, over OpenSSH's own agent protocol, so ssh and git work as they are.

  • Service accounts

    An account for a script or a build, with its own keys, that opens only the vaults you share with it.

  • MCP server for AI agents

    An agent asks for a login, you approve in the extension, and the extension fills the page. The agent never sees the password.

  • A fixer that reads unclear pages

    Where a change-password page's fields can't be told apart, the password fixer asks Chrome's on-device model which is which.

In CI

A token for the build. Nobody's master password.

A service account is a Vautir account of its own. It sees what you share with it, through the same sharing people use, and the server can't give it more.

  • Read, or read and save, for each vault you choose
  • It accepts vaults only from you: anyone else who shares with it is ignored
  • Its token is shown once, and deleting the account takes everything back
  • Made in the web vault, or from the command line
# Once, on your computer
vautir service-account create --name Deploys \
  --vault Production --vault Staging:editor

# In CI, with the token in its secrets
export VAUTIR_SERVICE_ACCOUNT_TOKEN=vtr_sa_…
export NPM_TOKEN=vautir://Production/npm/token
vautir run -- ./deploy.sh

What vautir does.

vautir login
Logs this computer in, once, as a device of its own.
vautir unlock
Starts a session for this shell: 30 minutes unused, or as long as you say, up to a day.
vautir read
Prints what a secret reference names.
vautir run
Runs a command with the references in its environment replaced by what they name.
vautir inject
Fills a template's references in, and writes a file only you can read.
vautir item
Lists and shows items, secrets hidden unless you ask, and saves new logins.
vautir ssh-agent
Signs with the SSH keys in your vault, until you stop it.
vautir service-account
Makes, lists and deletes service accounts.
vautir mcp
An MCP server for AI agents, which ask for logins you approve.

What the tools build on.

  • SSH keys and API credentials

    Kinds of item of their own, synced and end-to-end encrypted like everything else.

  • Key transparency

    Every key you share to, a service account's included, is checked against a public, append-only log.

Questions developers ask

How do I install it?

As a signed download for macOS, Linux and Windows, or with Homebrew.

Is a secret reference safe to commit?

Yes. vautir://Work/Database/password names a vault, an item and a field, and holds no secret. Only someone who can open that vault gets its value.

What does CI need?

A service account's token, in your CI's secret store. With it set, each command logs the service account in, keeps the vault in memory, and logs out when it's done. Nothing is left on the machine.

What happens if a token leaks?

Delete the service account: its account goes, with its sessions, and the token opens nothing. Tokens start with vtr_sa_ so secret scanners can catch one.

Does the SSH agent hold my keys?

While it runs, yes, decrypted, as any agent does. Stop it to forget them. Its socket is yours alone, and with --confirm it asks before each signature.

Can the command line read fill-only items?

No. An item shared with you as fill-only is refused: its secrets are never shown, by the command line either.

Want the command line first?

Join the waitlist, and tell us what you'd build with it.