Quickstart
Updated
Get Kryptic running locally in four steps. Total time: about three minutes.
1. Install the daemon
Open the download page. It detects your OS and architecture and serves the current installer from kryptic.dev.
- macOS: signed
.pkgfor Apple Silicon or Intel. Puts Kryptic in Applications and starts it at login. - Windows: signed setup
.exe. Installs the CLI, starts the tray app, and adds Kryptic to PATH. - Linux: the one-liner below. Installs to
~/.localand registers a systemd user service.
After the installer finishes, open a new terminal and sign in (or use the menu bar / tray):
kryptic login
Approve the code in your browser. The first time, an admin seals the organization key
to this machine. Later logins after idle expiry only need the browser step, not a
new grant, unless you run kryptic reset-device, uninstall, or sign in as a
different OS user. The rotating session token and device keys live in your OS
credential store (Keychain, Credential Manager, or libsecret). Access tokens
live in daemon memory only. The menu-bar and tray icon shows green when secrets
can be served, amber while connecting or waiting for that grant, and gray when
signed out. Add a second account (personal and work) with kryptic login --add
or Add Account in Open Kryptic (you pick that account's server
URI first). Switching does not sign the other out. Each profile keeps its own
config, so a self-hosted work account and a cloud account can live together.
Choose Open Kryptic from the menu-bar or tray menu. The window uses native
controls on each OS, with the same account, operations, settings, and help actions.
Optional, download from the terminal instead:
Install from the terminal
# Apple Silicon. Intel: https://kryptic.dev/dl/macos-intel.pkg
curl -fL -o Kryptic.pkg https://kryptic.dev/dl/macos-apple-silicon.pkg
open Kryptic.pkg
The Linux one-liner installs to ~/.local/bin. Add that directory to your
PATH if kryptic is not found after install.
2. Add kryptic.json
Commit a project config to your repo root. It contains no secrets - safe for version control. Your project's exact file is on the project page in the dashboard, one click to copy.
{
"projectId": "proj_a1b2c3d4e5f6",
"defaultEnvironment": "development"
}
3. Install the SDK for your language
One dev dependency, one line at startup. Every SDK is a thin Apache-2.0 client that
asks the daemon for your secrets over a local socket. Published package names are
Kryptic.Daemon.Client (.NET), @krypticdev/daemon-client (npm), and kryptic-daemon-client on the other registries.
Install the SDK
dotnet add package Kryptic.Daemon.Client
Startup code
using Kryptic;
var builder = WebApplication.CreateBuilder(args);
builder.Configuration.AddKryptic();
4. Run your app
Run command
dotnet run
That's it. Secrets are in process.env (or IConfiguration, os.environ, ENV, …)
before your code reads them. Existing environment variables are never overwritten, and in
production the SDK is a no-op.
Your workflow did not change: F5, npm run dev, dotnet run - everything just works,
and there is no .env file in your repo to leak.
The daemon serves secrets only for projects and environments your account can access - access is checked on the server for every bundle, and every read is audit-logged.