A secret reference names a secret without holding it. It’s safe to commit, to paste in a chat, and to keep in a .env file.
vautir://<vault>/<item>/<field>
Each part is a name or an ID. The field is a field’s label, such as password, username or API key, or one of notes, website, title, and otp for the one-time code at that moment. If two items share a name, name the item by its ID.
Read one
vautir read vautir://Work/Database/password
Run a command with them
export DATABASE_PASSWORD=vautir://Work/Database/password
vautir run -- ./migrate
vautir run starts the command with every reference in its environment replaced by what it names. The command gets those secrets, and never your session. Its exit code is passed on.
From a file of NAME=value lines:
vautir run --env-file .env.vautir -- npm start
Fill a config file
vautir inject -i config.yml.tpl -o config.yml
Each {{ vautir://… }} in the template is replaced, and the file is written so that only you can read it. Anything else in braces is left as it is.
In CI
Give the build a service account’s token, and the same commands work with nobody’s master password:
export VAUTIR_SERVICE_ACCOUNT_TOKEN=vtr_sa_…
vautir run -- ./deploy.sh
What to know
vautir rundoesn’t mask secrets in what its command prints: what the command prints, it prints.--password-stdinreads the master password from standard input, where a session or a service account won’t do.--offlineskips the sync each command otherwise tries first.
Last updated October 4, 2026