KrypticKryptic

Zero-friction secrets for every developer, every stack

No prefix commands, no .env files, no Slack-DM'd credentials. The daemon injects secrets when you start the app.

Daemon, SSO, versioning, and org secrets

Core

Passive daemon

A background client authenticates once via SSO and serves secrets over a local socket. No wrapper commands, no per-session login.

DX

Zero workflow change

F5 in the IDE, npm run dev, and dotnet run still start the app. Secrets inject before it boots.

SDKs

Language-native SDKs

.Net, Node.js, Python, Java, Go, Ruby, C++, and Rust packages connect the app to the local daemon.

Identity

SSO on every plan

Google, Microsoft Entra, and GitHub from day one. SAML 2.0 and SCIM available on Business and Enterprise tiers.

Teams

Organization management

Projects, environments, a shared org catalog, default roles, and immutable audit logs. Built for teams from 2 to 2,000 developers. Custom RBAC on Enterprise.

Secrets

Secret versioning

Every change is versioned with full rollback. Bulk import and export from .env format, with every export audit-logged.

Secrets

Reference secrets

Alias one key to another in the same project. The server copies ciphertext only, so end-to-end encryption stays intact.

Secrets

Shared org secrets

Author AWS, Stripe, or other shared keys once in the organization catalog. Projects link per environment. Manage and create new links on Business and Enterprise.

Enterprise

Custom RBAC

Every organization gets Owner, Admin, Developer, and Viewer. Enterprise can edit those bags and create new roles, so a Finance or Auditor role is a set of ticked permissions, not a sales conversation. Owner stays locked.

CI pipelines, Kubernetes operator, REST API

CI/CD

CI/CD pipelines

Machine identities for GitHub Actions, GitLab CI, Azure DevOps, CircleCI, Jenkins, and more. Scoped, short-lived access tokens.

K8s

Kubernetes Operator

Sync secrets from Kryptic into Kubernetes Secret objects on a schedule you control. Included on every plan.

API

Public API

A versioned REST API for machine identities: fetch encrypted bundles and write envelopes from your own tooling. Decryption always happens on your side.

Kryptic SDKs

Lightweight, language-native SDKs that connect your app to the local daemon. If the daemon isn't running, your app still starts with existing env vars. Zero production dependency.

LanguageRegistryPackageInjection target
.Net / C#NuGetKryptic.Daemon.ClientIConfiguration
Node.jsnpm@krypticdev/daemon-clientprocess.env
PythonPyPIkryptic-daemon-clientos.environ
JavaMavendev.kryptic:daemon-clientsystem properties
Gopkg.go.devgithub.com/dev-kryptic/Kryptic.Goos.Environ
RubyRubyGemskryptic-daemon-clientENV
C++CMake / GitHubgithub.com/dev-kryptic/Kryptic.Cppgetenv
Rustcrates.iokryptic-daemon-clientstd::env
dotnet add package Kryptic.Daemon.Client
using Kryptic;

var builder = WebApplication.CreateBuilder(args);
builder.Configuration.AddKryptic();

var dbUrl = builder.Configuration["DATABASE_URL"];
Quick start ->

Security by design, not by checkbox

End-to-end encrypted, open source

Secrets are encrypted in your browser, daemon, or CI runner with AES-256-GCM under an org key our servers never hold. The open-source engine shows exactly how.

Local socket only

Daemon-to-SDK communication never leaves your machine. Tokens live in the OS keychain; secrets stay in memory only.

Secret scanning

222+ secret patterns detected via pre-commit hooks, CI steps, or the kryptic scan CLI command.

Immutable audit logs

Every action logged with timestamp, actor, and IP. Logs cannot be modified or deleted - exportable as CSV or JSON.

How teams use Kryptic

Developer onboarding

Invitation, install daemon, SSO login, clone repo, run. Under 10 minutes to a working local environment. No Slack DMs.

Multi-project developers

Freelancers and agency devs switch between client projects. The daemon fetches secrets for the project that is running.

Environment promotion

Override the environment for a single run with KRYPTIC_ENV=staging or a kryptic.json default - no config file changes needed.

Shared org secrets

Put org-wide keys in one catalog and let each project map its environments to it. New links need Business or Enterprise. Existing links keep resolving if the org falls back to Free or Team.

Secret rotation

Update a secret in the dashboard, or set a one-time or recurring reminder. Every daemon, CI pipeline, and K8s operator picks up the new value automatically. If no reminder recipients are selected, owners and admins are notified.

Incident response

Revoke a user's access instantly. Refresh tokens invalidate within 15 minutes. No secrets on disk - nothing to recover from a lost laptop.

Self-hosted compliance

Run the full platform in your infrastructure from Business up. Air-gapped deployment with offline licence validation on Enterprise, for regulated industries.

Custom RBAC

Keep Owner as break-glass, then give Finance billing, an auditor the audit log, or a lead only the projects they own. Custom roles and the permission editor are Enterprise, including self-hosted keys with Advanced RBAC.

Daemon versus a CLI wrapper

KrypticTypical CLI tools
Dev workflowPassive daemon - zero workflow changeCLI wrapper every run
SSO on free tierYesOften paid add-on
.Net integrationNative IConfigurationGeneric env injection
Open source clientGPL-3.0 daemon, Apache-2.0 SDKsVaries
Self-hostedBusiness and EnterpriseOften unavailable
Works in your IDEAny - no plugin neededCLI wrapper or plugin

See it in action

Walk through the get started guide, language SDKs, and CLI reference.