The vautir command gives your terminal, your scripts and your builds what’s in your vault. It’s built on the same core as every app, and tested on macOS and Linux.
Log in, once
vautir login --server https://us.vault.vautir.com --email you@example.com
Use your account’s region: https://us.vault.vautir.com for the United States, https://eu.vault.vautir.com for the European Union, or your own server’s address. It asks for your Secret Key and your master password, and adds the computer as a device of its own. If your organization uses single sign-on, the terminal shows the page to open and the code that page should show.
Unlock a shell
eval "$(vautir unlock)"
That starts a session for this shell, so commands stop asking for your master password. It ends after 30 minutes unused, or with vautir lock. vautir unlock --minutes 240 lasts longer, up to a day. vautir lock --all ends every shell’s session.
Find and read
vautir vault list
vautir item list --search bank
vautir item get "Northwind Bank"
vautir item get "Northwind Bank" --field password
item get hides secrets unless you add --reveal, or ask for one field. Add --json for output a script can read.
Save a login
vautir item create --title "Staging database" --username deploy --generate
It saves the login with a new password, and prints its ID. Other kinds of item, editing and deleting are in the apps.
More
- Secrets in scripts and CI: references,
runandinject. - The SSH agent.
- Service accounts.
- Letting an AI agent sign in.
What to know
- One account on a computer. The apps keep several.
vautir logoutforgets the account on that computer: its vault, its Secret Key and every session.- In an organization, reading an item from one of its vaults goes in its audit log, and items shared with you as fill-only are refused.
Last updated October 4, 2026