The vallkey command gives your terminal, your scripts and your builds what’s in your vault. It’s built on the same core as every app, and tested on macOS and Linux.
Log in, once
vallkey login --server https://us.vault.vallkey.com --email you@example.com
Use your account’s region: https://us.vault.vallkey.com for the United States, https://eu.vault.vallkey.com for the European Union, or your own server’s address. It asks for your Secret Key and your master password, and adds the computer as a device of its own. If your organization uses single sign-on, the terminal shows the page to open and the code that page should show.
Unlock a shell
eval "$(vallkey unlock)"
That starts a session for this shell, so commands stop asking for your master password. It ends after 30 minutes unused, or with vallkey lock. vallkey unlock --minutes 240 lasts longer, up to a day. vallkey lock --all ends every shell’s session.
Find and read
vallkey vault list
vallkey item list --search bank
vallkey item get "Northwind Bank"
vallkey item get "Northwind Bank" --field password
item get hides secrets unless you add --reveal, or ask for one field. Add --json for output a script can read.
Save a login
vallkey item create --title "Staging database" --username deploy --generate
It saves the login with a new password, and prints its ID. Other kinds of item, editing and deleting are in the apps.
More
- Secrets in scripts and CI: references,
runandinject. - The SSH agent.
- Service accounts.
- Letting an AI agent sign in.
What to know
- One account on a computer. The apps keep several.
vallkey logoutforgets the account on that computer: its vault, its Secret Key and every session.- In an organization, reading an item from one of its vaults goes in its audit log, and items shared with you as fill-only are refused.
Last updated October 4, 2026