Quickstart

Updated

Get Kryptic running locally in four steps. Total time: about three minutes.

1. Install the daemon

Open the download page. It detects your OS and architecture and serves the current installer from kryptic.dev.

  • macOS: signed .pkg for Apple Silicon or Intel. Puts Kryptic in Applications and starts it at login.
  • Windows: signed setup .exe. Installs the CLI, starts the tray app, and adds Kryptic to PATH.
  • Linux: the one-liner below. Installs to ~/.local and registers a systemd user service.

After the installer finishes, open a new terminal and sign in (or use the menu bar / tray):

kryptic login

Approve the code in your browser. The first time, an admin seals the organization key to this machine. Later logins after idle expiry only need the browser step, not a new grant, unless you run kryptic reset-device, uninstall, or sign in as a different OS user. The rotating session token and device keys live in your OS credential store (Keychain, Credential Manager, or libsecret). Access tokens live in daemon memory only. The menu-bar and tray icon shows green when secrets can be served, amber while connecting or waiting for that grant, and gray when signed out. Add a second account (personal and work) with kryptic login --add or Add Account in Open Kryptic (you pick that account's server URI first). Switching does not sign the other out. Each profile keeps its own config, so a self-hosted work account and a cloud account can live together. Choose Open Kryptic from the menu-bar or tray menu. The window uses native controls on each OS, with the same account, operations, settings, and help actions.

Optional, download from the terminal instead:

Install from the terminal

# Apple Silicon. Intel: https://kryptic.dev/dl/macos-intel.pkg
curl -fL -o Kryptic.pkg https://kryptic.dev/dl/macos-apple-silicon.pkg
open Kryptic.pkg

The Linux one-liner installs to ~/.local/bin. Add that directory to your PATH if kryptic is not found after install.

2. Add kryptic.json

Commit a project config to your repo root. It contains no secrets - safe for version control. Your project's exact file is on the project page in the dashboard, one click to copy.

{
  "projectId": "proj_a1b2c3d4e5f6",
  "defaultEnvironment": "development"
}

3. Install the SDK for your language

One dev dependency, one line at startup. Every SDK is a thin Apache-2.0 client that asks the daemon for your secrets over a local socket. Published package names are Kryptic.Daemon.Client (.NET), @krypticdev/daemon-client (npm), and kryptic-daemon-client on the other registries.

Install the SDK

dotnet add package Kryptic.Daemon.Client

Startup code

using Kryptic;

var builder = WebApplication.CreateBuilder(args);
builder.Configuration.AddKryptic();

4. Run your app

Run command

dotnet run

That's it. Secrets are in process.env (or IConfiguration, os.environ, ENV, …) before your code reads them. Existing environment variables are never overwritten, and in production the SDK is a no-op.

Your workflow did not change: F5, npm run dev, dotnet run - everything just works, and there is no .env file in your repo to leak.

The daemon serves secrets only for projects and environments your account can access - access is checked on the server for every bundle, and every read is audit-logged.