Log inGet Vautir

Search the help center, features, guides and more.

Service accounts

Give a script, a server or CI its own Vautir login: making a service account, sharing vaults with it, using its token, and deleting it.

A service account is a login for a script, a server or a build: a Vautir account of its own, with its own keys, that opens only the vaults you share with it. Its token goes in your CI’s secrets. Nobody’s master password does.

Make one

In the web vault, open Account, Service accounts, New service account. Say what it’s for, and for each of your vaults choose Nothing, Read, or Read and save.

Or from the command line:

vautir service-account create --name Deploys --vault Production --vault Staging:editor

The token is shown once. Keep it in your CI’s secret store.

Use it

export VAUTIR_SERVICE_ACCOUNT_TOKEN=vtr_sa_…
vautir run -- ./deploy.sh
vautir read vautir://Production/Registry/password

With the token set, the command line keeps nothing on the machine: each command logs the service account in, keeps the vault in memory, and logs out when it’s done.

Give it more, or take it all back

Share another vault with the service account’s address, listed under Service accounts, as you would with a person. It picks the vault up at its next run.

Delete it to take everything back at once: its account goes, with its sessions, and the token opens nothing.

What to know

  • The token is the account. Whoever has it reads what it reads. If it leaks, delete the service account. Tokens start with vtr_sa_, so secret scanners can catch one.
  • It accepts vaults only from you. Anyone else who shares a vault with it is ignored.
  • Your own vaults only. An organization’s vaults can’t be granted to a service account.
  • Up to 50 for each account. Deleting your own account deletes them with it.
  • They’re made in the web vault and from the command line, not in the phone or desktop apps.

Last updated October 4, 2026