Passive daemon
A background client authenticates once via SSO and serves secrets over a local socket. No wrapper commands, no per-session login.
No prefix commands, no .env files, no Slack-DM'd credentials. The daemon injects secrets when you start the app.
A background client authenticates once via SSO and serves secrets over a local socket. No wrapper commands, no per-session login.
F5 in the IDE, npm run dev, and dotnet run still start the app. Secrets inject before it boots.
.Net, Node.js, Python, Java, Go, Ruby, C++, and Rust packages connect the app to the local daemon.
Google, Microsoft Entra, and GitHub from day one. SAML 2.0 and SCIM available on Business and Enterprise tiers.
Projects, environments, a shared org catalog, default roles, and immutable audit logs. Built for teams from 2 to 2,000 developers. Custom RBAC on Enterprise.
Every change is versioned with full rollback. Bulk import and export from .env format, with every export audit-logged.
Alias one key to another in the same project. The server copies ciphertext only, so end-to-end encryption stays intact.
Author AWS, Stripe, or other shared keys once in the organization catalog. Projects link per environment. Manage and create new links on Business and Enterprise.
Every organization gets Owner, Admin, Developer, and Viewer. Enterprise can edit those bags and create new roles, so a Finance or Auditor role is a set of ticked permissions, not a sales conversation. Owner stays locked.
Machine identities for GitHub Actions, GitLab CI, Azure DevOps, CircleCI, Jenkins, and more. Scoped, short-lived access tokens.
Sync secrets from Kryptic into Kubernetes Secret objects on a schedule you control. Included on every plan.
A versioned REST API for machine identities: fetch encrypted bundles and write envelopes from your own tooling. Decryption always happens on your side.
Lightweight, language-native SDKs that connect your app to the local daemon. If the daemon isn't running, your app still starts with existing env vars. Zero production dependency.
| Language | Registry | Package | Injection target |
|---|---|---|---|
| .Net / C# | NuGet | Kryptic.Daemon.Client | IConfiguration |
| Node.js | npm | @krypticdev/daemon-client | process.env |
| Python | PyPI | kryptic-daemon-client | os.environ |
| Java | Maven | dev.kryptic:daemon-client | system properties |
| Go | pkg.go.dev | github.com/dev-kryptic/Kryptic.Go | os.Environ |
| Ruby | RubyGems | kryptic-daemon-client | ENV |
| C++ | CMake / GitHub | github.com/dev-kryptic/Kryptic.Cpp | getenv |
| Rust | crates.io | kryptic-daemon-client | std::env |
Secrets are encrypted in your browser, daemon, or CI runner with AES-256-GCM under an org key our servers never hold. The open-source engine shows exactly how.
Daemon-to-SDK communication never leaves your machine. Tokens live in the OS keychain; secrets stay in memory only.
222+ secret patterns detected via pre-commit hooks, CI steps, or the kryptic scan CLI command.
Every action logged with timestamp, actor, and IP. Logs cannot be modified or deleted - exportable as CSV or JSON.
Invitation, install daemon, SSO login, clone repo, run. Under 10 minutes to a working local environment. No Slack DMs.
Freelancers and agency devs switch between client projects. The daemon fetches secrets for the project that is running.
Override the environment for a single run with KRYPTIC_ENV=staging or a kryptic.json default - no config file changes needed.
Put org-wide keys in one catalog and let each project map its environments to it. New links need Business or Enterprise. Existing links keep resolving if the org falls back to Free or Team.
Update a secret in the dashboard, or set a one-time or recurring reminder. Every daemon, CI pipeline, and K8s operator picks up the new value automatically. If no reminder recipients are selected, owners and admins are notified.
Revoke a user's access instantly. Refresh tokens invalidate within 15 minutes. No secrets on disk - nothing to recover from a lost laptop.
Run the full platform in your infrastructure from Business up. Air-gapped deployment with offline licence validation on Enterprise, for regulated industries.
Keep Owner as break-glass, then give Finance billing, an auditor the audit log, or a lead only the projects they own. Custom roles and the permission editor are Enterprise, including self-hosted keys with Advanced RBAC.
| Kryptic | Typical CLI tools | |
|---|---|---|
| Dev workflow | Passive daemon - zero workflow change | CLI wrapper every run |
| SSO on free tier | Yes | Often paid add-on |
| .Net integration | Native IConfiguration | Generic env injection |
| Open source client | GPL-3.0 daemon, Apache-2.0 SDKs | Varies |
| Self-hosted | Business and Enterprise | Often unavailable |
| Works in your IDE | Any - no plugin needed | CLI wrapper or plugin |