An SSH agent
vautir ssh-agent signs with the Ed25519 and ECDSA P-256 keys in your vault, speaking OpenSSH's own agent protocol, so ssh and git use it as they are. With --confirm, it asks before each signature.
The vautir command gives scripts, shells and CI what's in your vault, so a password or an API key lives in Vautir and not in a .env file, a shell history or a CI setting.
$ eval "$(vautir unlock)"
$ export DB_PASSWORD=vautir://Work/Database/password
$ vautir run -- ./migrate
$ vautir inject -i config.yml.tpl -o config.yml
$ vautir ssh-agent
SSH_AUTH_SOCK=…/com.vautir.cli/ssh-agent.sock
vautir login adds the computer as a device of its own. vautir unlock starts a session for that shell, which ends after 30 minutes unused.
A reference such as vautir://Work/Database/password names a vault, an item and a field. It's safe to commit: it holds no secret.
vautir run starts a command with the references in its environment replaced by what they name. vautir inject fills a config file's template the same way.
vautir ssh-agent signs with the Ed25519 and ECDSA P-256 keys in your vault, speaking OpenSSH's own agent protocol, so ssh and git use it as they are. With --confirm, it asks before each signature.
An account of its own for a script or a build, with its own keys, that opens only the vaults you share with it. Its token goes in your CI's secrets; nobody's master password does. Delete it to take everything back at once.
Each shell has its own session, kept going by use and ended by vautir lock. A command started with vautir run gets the secrets it names, and never the session.
Reading an item from an organization's vault goes in its audit log, as opening it in an app does. Items shared as fill-only are refused: their secrets are never shown, by the command line either.
The SSH agent runs on macOS and Linux, and leaves RSA keys out. vautir run doesn't mask secrets in what its command prints. It keeps one account on a computer, and saves new logins only: other kinds of item are made in the apps.
Availability
As a signed download for macOS, Linux and Windows, or with Homebrew.
Everything the service account logs in with, so treat it as a secret. It starts with vtr_sa_, so secret scanners can catch one that leaks.
Yes. The terminal shows the page to open and the code that page should show, as the apps do.
Free forever for unlimited passwords and devices. No card needed.