home | help
IN...LInfisical CLI is used to inject environment variables into any proIN...L(1)

NAME
     infisical	- Infisical CLI is used to inject environment variables into any
     process

SYNOPSIS
     infisical [options...] [argument...]

DESCRIPTION
     Infisical is a simple, end-to-end encrypted service that enables  teams  to
     sync  and	manage their environment variables across their development life
     cycle.

OPTIONS
     --domain
	    Point the CLI to your Infisical instance  (e.g.,  https://eu.infisi-
	    cal.com for EU Cloud, or https://your-instance.com for self-hosted).
	    Can  also  set via INFISICAL_DOMAIN environment variable or the 'do-
	    main' field in .infisical.json. Required for non-US Cloud users.

     --l --log-level
	    log level (trace, debug, info, warn, error, fatal)

     --silent
	    Disable output of tip/info messages. Useful when running in  scripts
	    or CI/CD pipelines.

     --telemetry
	    Infisical  collects non-sensitive telemetry data to enhance features
	    and improve user experience. Participation is voluntary

COMMANDS
     agent
	 Used to launch a client daemon that streamlines authentication and  se-
	 cret retrieval processes in various environments

     OPTIONS
	 --config The path to agent config yaml file

     bootstrap
	 Used to bootstrap your Infisical instance

     OPTIONS
	 --domain The domain of your self-hosted Infisical instance

	 --email
		The desired email address of the instance admin

	 --ignore-if-bootstrapped
		Whether  to  continue  on error if the instance has already been
		bootstrapped

	 --k8-secret-name
		The name of the Kubernetes secret to create

	 --k8-secret-namespace
		The namespace to create the Kubernetes secret in

	 --k8-secret-template
		The template to use for rendering the Kubernetes secret  (entire
		secret JSON)

	 --organization
		The name of the organization to create for the instance

	 --output
		The  type  of  output  to use for the bootstrap command (json or
		k8-secret)

	 --password
		The desired password of the instance admin

     cert-manager
	 Certificate management commands

     COMMANDS
	 agent
	     Launch certificate management agent

	 OPTIONS
	     --config The path to certificate agent config yaml file

	     --v --verbose
		    Enable verbose logging for certificate management agent

     dynamic-secrets
	 Used to list dynamic secrets

     OPTIONS
	 --env Used to select the environment name on which  actions  should  be
	 taken on

	 --o --output
		The  output  to format the dynamic secrets in. Supported formats
		are yaml, json, dotenv

	 --path
		get dynamic secret within a folder path

	 --project-slug
		Manually set the project-slug to fetch dynamic-secret from

	 --projectId
		Manually set the projectId to fetch  dynamic-secret  when  using
		machine identity based auth

	 --token
		Fetch secrets using service token or machine identity access to-
		ken

     COMMANDS
	 lease
	     Manage leases for dynamic secrets

	 COMMANDS
	     create [dynamic-secret]
		 Used to lease dynamic secret by name

	     OPTIONS
		 --kubernetes-namespace  The  namespace  to create the lease in.
		 Only used for Kubernetes dynamic secrets.

		 --o --output
			The output to format the  leased  credentials  in.  Sup-
			ported formats are yaml, json, dotenv

		 --p --path
			The path from where dynamic secret should be leased from

		 --plain
			Print  leased  credentials  without  formatting, one per
			line

		 --principals
			Comma-separated list of principals for SSH  dynamic  se-
			cret leases

		 --project-slug
			Manually set the project-slug to create lease in

		 --projectId
			Manually set the projectId to fetch leased from when us-
			ing machine identity based auth

		 --token
			Create	dynamic secret leases using machine identity ac-
			cess token

		 --ttl	The lease lifetime TTL. If not provided the default  TTL
			of dynamic secret will be used.

	     delete [lease-id]
		 Used to delete dynamic secret lease by name

	     OPTIONS
		 --o  --output The output to format the dynamic secret lease re-
		 vocation in. Supported formats are yaml, json, dotenv

		 --p --path
			The path from where dynamic secret should be leased from

		 --project-slug
			Manually set the project-slug to revoke lease from

		 --projectId
			Manually set the projectId to fetch leased from when us-
			ing machine identity based auth

		 --token
			Delete dynamic secrets using machine identity access to-
			ken

	     list [dynamic-secret]
		 Used to list leases of a dynamic secret by name

	     OPTIONS
		 --o --output The output to format the dynamic secret leases in.
		 Supported formats are yaml, json, dotenv

		 --p --path
			The path from where dynamic secret should be leased from

		 --project-slug
			Manually set the project-slug to list leases from

		 --projectId
			Manually set the projectId to fetch leased from when us-
			ing machine identity based auth

		 --token
			Fetch dynamic secret leases machine identity access  to-
			ken

	     renew [lease-id]
		 Used to renew dynamic secret lease by name

	     OPTIONS
		 --o  --output The output to format the dynamic secret lease re-
		 newal in. Supported formats are yaml, json, dotenv

		 --p --path
			The path from where dynamic secret should be leased from

		 --project-slug
			Manually set the project-slug to renew lease in

		 --projectId
			Manually set the projectId to fetch leased from when us-
			ing machine identity based auth

		 --token
			Renew dynamic secrets machine identity access token

		 --ttl	The lease lifetime TTL. If not provided the default  TTL
			of dynamic secret will be used.

     export
	 Used to export environment variables to a file

     OPTIONS
	 --e --env Set the environment (dev, prod, etc.) from which your secrets
	 should be pulled from

	 --expand
		Parse shell parameter expansions in your secrets

	 --f --format
		Set  the  format  of  the  output  file  (dotenv, dotenv-export,
		dotenv-eval, json, csv, yaml)

	 --include-imports
		Imported linked secrets

	 --o --output-file
		The path to write the output file to. Can be a full  file  path,
		directory, or filename. If not specified, output will be printed
		to stdout

	 --path
		get secrets within a folder path

	 --projectId
		manually set the projectId to export secrets from

	 --secret-overriding
		Prioritizes  personal  secrets,  if any, with the same name over
		shared secrets

	 --t --tags
		filter secrets by tag slugs

	 --template
		The path to the template file used to render secrets

	 --token
		Fetch secrets using service token or machine identity access to-
		ken

     gateway
	 Run the Infisical gateway or manage its systemd service

     OPTIONS
	 --auth-method login method [universal-auth, kubernetes, azure,  gcp-id-
	 token,  gcp-iam, aws-iam, oidc-auth]. if not provided, you must set the
	 token flag

	 --client-id
		client id for universal auth

	 --client-secret
		client secret for universal auth

	 --jwt	JWT for jwt-based auth methods [oidc-auth, jwt-auth]

	 --machine-identity-id
		machine identity id for kubernetes,  azure,  gcp-id-token,  gcp-
		iam, and aws-iam auth methods

	 --service-account-key-file-path
		service account key file path for GCP IAM auth

	 --service-account-token-path
		service account token path for kubernetes auth

	 --token
		connect  with  Infisical using machine identity access token. if
		not provided, you must set the auth-method flag

     COMMANDS
	 install
	     Install and enable systemd service for the gateway (requires sudo)

	 OPTIONS
	     --domain Domain of your self-hosted Infisical instance

	     --token
		    Connect with Infisical using machine identity access token

	 relay
	     Used to run infisical gateway relay

	 OPTIONS
	     --config Relay config yaml file path

	 start [name]
	     Start the new Infisical gateway

	 OPTIONS
	     --auth-method login method [universal-auth, kubernetes, azure, gcp-
	     id-token, gcp-iam, aws-iam, oidc-auth]. if not provided,  you  must
	     set the token flag

	     --client-id
		    client id for universal auth

	     --client-secret
		    client secret for universal auth

	     --domain
		    domain  of	your  self-hosted  Infisical instance (used with
		    --enroll-method=token or --enroll-method=aws)

	     --enroll-method
		    gateway auth method [token, aws]. when set to 'token',  uses
		    --token  as  a one-time enrollment token. when set to 'aws',
		    authenticates via signed STS GetCallerIdentity using --gate-
		    way-id

	     --gateway-id
		    gateway id (required when --enroll-method=aws)

	     --jwt  JWT for jwt-based auth methods [oidc-auth, jwt-auth]

	     --machine-identity-id
		    machine identity id  for  kubernetes,  azure,  gcp-id-token,
		    gcp-iam, and aws-iam auth methods

	     --name
		    name of the gateway (deprecated, use positional argument in-
		    stead)

	     --organization-slug
		    When set, this will scope the login session to the specified
		    sub-organization the machine identity has access to. If left
		    empty,  the  session  defaults to the organization where the
		    machine identity was created in.

	     --pam-session-recording-path
		    directory path  for  PAM  session  recordings  (defaults  to
		    /var/lib/infisical/session_recordings)

	     --pkcs11-module
		    absolute   path   to   a  PKCS#11  driver  (e.g.  /opt/fort-
		    anix/pkcs11/fortanix_pkcs11.so). When set, the gateway loads
		    the driver and serves HSM operations through it.

	     --relay
		    name of the relay to connect to (deprecated,  use  --target-
		    relay-name)

	     --service-account-key-file-path
		    service account key file path for GCP IAM auth

	     --service-account-token-path
		    service account token path for kubernetes auth

	     --target-relay-name
		    name of the relay to connect to

	     --token
		    enrollment token or access token for authenticating with In-
		    fisical

	 systemd
	     Manage systemd service for Infisical gateway

	 COMMANDS
	     install [name]
		 Install  and  enable  systemd service for the gateway (v2) (re-
		 quires sudo)

	     OPTIONS
		 --domain Domain of your self-hosted Infisical instance

		 --enroll-method
			gateway auth method [token, aws]. when set  to	'token',
			uses --token as a one-time enrollment token. when set to
			'aws',	the  gateway  authenticates  via AWS STS on each
			service start (requires --gateway-id)

		 --gateway-id
			gateway id (required when --enroll-method=aws)

		 --log-file
			The  file  to  write  the  service  logs  to.	Example:
			/var/log/infisical/gateway.log.  If  not  provided, logs
			will not be written to a file.

		 --name
			The name of the gateway (deprecated, use positional  ar-
			gument instead)

		 --pkcs11-module
			absolute  path	to  a  PKCS#11	driver	(e.g. /opt/fort-
			anix/pkcs11/fortanix_pkcs11.so). When set,  the  systemd
			service  starts  the  gateway  with  the  PKCS#11 driver
			loaded for HSM operations.

		 --relay
			The name of the relay (deprecated,  use  --target-relay-
			name)

		 --target-relay-name
			The name of the relay

		 --token
			enrollment token or access token for authenticating with
			Infisical

	     uninstall [name]
		 Uninstall  and remove systemd service for the gateway (requires
		 sudo)

	 uninstall
	     Uninstall and remove systemd  service  for  the  gateway  (requires
	     sudo)

     help [command]
	 Help about any command

     init
	 Used to connect your local project with Infisical project

     kmip
	 Used to manage KMIP servers

     COMMANDS
	 start [server-name]
	     Used to start a KMIP server

	 OPTIONS
	     --certificate-ttl	The TTL duration for the server certificate. De-
	     faults to 1y

	     --domain
		    Domain of your self-hosted Infisical instance

	     --enroll-method
		    Enrollment method for the KMIP  server:  'token'  or  'aws'.
		    When set, machine-identity flags are ignored.

	     --hostnames-or-ips
		    Comma-separated list of hostnames or IPs

	     --identity-auth-method
		    The  auth method to use for authenticating the machine iden-
		    tity. Defaults to universal-auth.

	     --identity-client-id
		    Universal auth client ID of machine identity

	     --identity-client-secret
		    Universal auth client secret of machine identity

	     --kmip-server-id
		    KMIP server ID (when --enroll-method=aws)

	     --listen-address
		    The address for the KMIP server to listen  on.  Defaults  to
		    localhost:5696

	     --server-name
		    The  name of the KMIP server. Alternative to passing it as a
		    positional argument; required if not passed positionally

	     --token
		    Enrollment token (when --enroll-method=token)

	 systemd
	     Manage systemd service for Infisical KMIP server

	 COMMANDS
	     install [server-name]
		 Install and enable systemd service for  the  KMIP  server  (re-
		 quires sudo)

	     OPTIONS
		 --certificate-ttl The TTL duration for the server certificate

		 --domain
			Domain of your self-hosted Infisical instance

		 --enroll-method
			Enrollment method for the KMIP server: 'token' or 'aws'.
			When set, machine-identity flags are ignored.

		 --hostnames-or-ips
			Comma-separated list of hostnames or IPs

		 --identity-client-id
			Universal auth client ID of machine identity

		 --identity-client-secret
			Universal auth client secret of machine identity

		 --kmip-server-id
			KMIP server ID (when --enroll-method=aws)

		 --listen-address
			The address for the KMIP server to listen on

		 --server-name
			The  name  of the KMIP server. Alternative to passing it
			as a positional argument; required if not  passed  posi-
			tionally

		 --token
			Enrollment token (when --enroll-method=token)

	     uninstall
		 Uninstall  and  remove systemd service for the KMIP server (re-
		 quires sudo)

     login
	 Login into your Infisical account

     OPTIONS
	 --clear-domains clear all self-hosting domains from the config file

	 --client-id
		client id for universal auth

	 --client-secret
		client secret for universal auth

	 --email
		email for 'user' login method

	 --i --interactive
		login via the command line

	 --jwt	jwt for jwt-based login methods [oidc-auth, jwt-auth]

	 --machine-identity-id
		machine identity id for these login methods [kubernetes,  azure,
		gcp-id-token, gcp-iam, aws-iam]

	 --method
		login  method  [user, universal-auth, kubernetes, azure, gcp-id-
		token, gcp-iam, aws-iam, oidc-auth]

	 --oidc-jwt
		JWT for OIDC authentication. Deprecated, use --jwt instead

	 --organization-id
		organization id for 'user' login method

	 --organization-slug
		When set for machine identity login, this will scope  the  login
		session  to  the specified sub-organization the machine identity
		has access to. If left empty, the session defaults to the  orga-
		nization where the machine identity was created in.

	 --password
		password for 'user' login method

	 --plain
		only output the token without any formatting

	 --service-account-key-file-path
		service account key file path for GCP IAM auth

	 --service-account-token-path
		service account token path for kubernetes auth

     COMMANDS
	 status
	     View the current authentication status

	 OPTIONS
	     --json Output the login status as JSON

	     --token
		    Inspect  this  machine  identity access token instead of the
		    active session or environment variables

     pam
	 PAM-related commands

     COMMANDS
	 db
	     Database-related PAM commands

	 COMMANDS
	     access
		 Access PAM database accounts

	     OPTIONS
		 --account Name of the account within the resource

		 --duration
			Duration for database access session (e.g., '1h', '30m',
			'2h30m')

		 --port
			Port for the local database proxy server (0 for auto-as-
			sign)

		 --project-id
			Project ID of the account to access

		 --reason
			Reason for accessing the account (stored for audit  pur-
			poses)

		 --resource
			Name of the PAM resource to access

	 kubernetes
	     Kubernetes-related PAM commands

	 COMMANDS
	     access
		 Access Kubernetes PAM account

	     OPTIONS
		 --account Name of the account within the resource

		 --duration
			Duration  for  kubernetes  access  session  (e.g., '1h',
			'30m', '2h30m')

		 --port
			Port for the local kubernetes proxy server (0 for  auto-
			assign)

		 --project-id
			Project ID of the account to access

		 --reason
			Reason	for accessing the account (stored for audit pur-
			poses)

		 --resource
			Name of the PAM resource to access

	 rdp
	     RDP-related PAM commands

	 COMMANDS
	     access
		 Access PAM Windows/RDP accounts

	     OPTIONS
		 --account Name of the account within the resource

		 --duration
			Duration for RDP  access  session  (e.g.,  '1h',  '30m',
			'2h30m')

		 --no-launch
			Do  not auto-launch the system RDP client; print connec-
			tion details only

		 --port
			Port for the local RDP proxy server (0 for auto-assign)

		 --project-id
			Project ID of the account to access

		 --reason
			Reason for accessing the account (stored for audit  pur-
			poses)

		 --resource
			Name of the PAM resource to access

	 redis
	     Redis-related PAM commands

	 COMMANDS
	     access
		 Access PAM Redis accounts

	     OPTIONS
		 --account Name of the account within the resource

		 --duration
			Duration  for  Redis  access session (e.g., '1h', '30m',
			'2h30m')

		 --port
			Port for the local Redis proxy server  (0  for	auto-as-
			sign)

		 --project-id
			Project ID of the account to access

		 --reason
			Reason	for accessing the account (stored for audit pur-
			poses)

		 --resource
			Name of the PAM resource to access

	 ssh
	     SSH-related PAM commands

	 COMMANDS
	     access
		 Start interactive SSH session to PAM account

	     OPTIONS
		 --account Name of the account within the resource

		 --duration
			Duration for SSH  access  session  (e.g.,  '1h',  '30m',
			'2h30m')

		 --project-id
			Project ID of the account to access

		 --reason
			Reason	for accessing the account (stored for audit pur-
			poses)

		 --resource
			Name of the PAM resource to access

	     exec [command]
		 Execute a command on a PAM SSH account

	     OPTIONS
		 --account Name of the account within the resource

		 --duration
			Duration for SSH  access  session  (e.g.,  '1h',  '30m',
			'2h30m')

		 --project-id
			Project ID of the account to access

		 --reason
			Reason	for accessing the account (stored for audit pur-
			poses)

		 --resource
			Name of the PAM resource to access

	     proxy
		 Start SSH proxy for SCP, SFTP, or rsync

	     OPTIONS
		 --account Name of the account within the resource

		 --duration
			Duration for SSH  access  session  (e.g.,  '1h',  '30m',
			'2h30m')

		 --project-id
			Project ID of the account to access

		 --reason
			Reason	for accessing the account (stored for audit pur-
			poses)

		 --resource
			Name of the PAM resource to access

     proxy
	 Used to run Infisical proxy server

     COMMANDS
	 start
	     Start the Infisical proxy server

	 OPTIONS
	     --access-token-check-interval How often to validate that access to-
	     kens are still valid (e.g., 5m, 1h). Defaults to 5m.

	     --client-id
		    Machine identity universal auth client ID. This is	required
		    when using event subscriptions.

	     --client-secret
		    Machine  identity  universal auth client secret. This is re-
		    quired when using event subscriptions.

	     --domain
		    Domain of your Infisical instance (e.g., https://app.infisi-
		    cal.com for cloud,	https://my-self-hosted-instance.com  for
		    self-hosted)

	     --enable-event-subscriptions
		    Enable Event Subscription mode for real-time cache invalida-
		    tion.  When enabled, the static secrets refresh loop is dis-
		    abled. If event subscriptions  are	unavailable,  the  proxy
		    will  fall	back  to a polling mechanism.  `--client id` and
		    `--client-secret` are required when this is set to true

	     --eviction-strategy
		    Cache eviction strategy. 'optimistic' keeps cached data when
		    Infisical is unreachable for  high	availability.  Currently
		    only 'optimistic' is supported.

	     --listen-address
		    The  address  for the proxy server to listen on. Defaults to
		    localhost:8081

	     --polling-fallback-interval
		    How often to poll for secret changes when SSE is unavailable
		    (e.g., 1m, 5m). Defaults to 5m.  Only  used  when  --enable-
		    event-subscriptions is set.

	     --static-secrets-refresh-interval
		    How often to refresh cached secrets (e.g., 30m, 1h, 1d). De-
		    faults to 1h.

	     --tls-cert-file
		    The  path  to the TLS certificate file for the proxy server.
		    Required when `tls-enabled` is set to true (default)

	     --tls-enabled
		    Whether to enable TLS for the proxy server. Defaults to true

	     --tls-key-file
		    The path to the TLS key file for the proxy server.	Required
		    when `tls-enabled` is set to true (default)

     relay
	 Relay-related commands

     COMMANDS
	 start
	     Start the Infisical relay component

	 OPTIONS
	     --auth-method login method [universal-auth, kubernetes, azure, gcp-
	     id-token,	gcp-iam,  aws-iam, oidc-auth]. if not provided, you must
	     set the token flag

	     --client-id
		    client id for universal auth

	     --client-secret
		    client secret for universal auth

	     --domain
		    domain of your self-hosted	Infisical  instance  (used  with
		    --enroll-method)

	     --enroll-method
		    relay  auth  method  [token, aws]. when set to 'token', uses
		    --token as a one-time enrollment token. when set  to  'aws',
		    authenticates  via	signed STS GetCallerIdentity using --re-
		    lay-id

	     --host
		    The IP or hostname for the relay

	     --jwt  JWT for jwt-based auth methods [oidc-auth, jwt-auth]

	     --machine-identity-id
		    machine identity id  for  kubernetes,  azure,  gcp-id-token,
		    gcp-iam, and aws-iam auth methods

	     --name
		    The name of the relay

	     --relay-id
		    relay id (required when --enroll-method=aws)

	     --service-account-key-file-path
		    service account key file path for GCP IAM auth

	     --service-account-token-path
		    service account token path for kubernetes auth

	     --token
		    connect  with Infisical using machine identity access token,
		    or a one-time enrollment token when --enroll-method=token

	     --type
		    The type of relay to run. Defaults to 'org'

	 systemd
	     Manage systemd service for Infisical relay

	 COMMANDS
	     install
		 Install and enable systemd  service  for  the	relay  (requires
		 sudo)

	     OPTIONS
		 --domain Domain of your self-hosted Infisical instance

		 --host
			The IP or hostname for the relay

		 --log-file
			The   file  to	write  the  service  logs  to.	Example:
			/var/log/infisical/relay.log. If not provided, logs will
			not be written to a file.

		 --name
			The name of the relay

		 --relay-auth-secret
			Relay auth secret (required for type=instance if env not
			set)

		 --token
			Connect with Infisical using machine identity access to-
			ken (org type)

		 --type
			The type of relay to run. Defaults to 'org'

	     uninstall
		 Uninstall and remove systemd service for  the	relay  (requires
		 sudo)

     reset
	 Used to delete all Infisical related data on your machine

     run [any infisical run command flags] -- [your application start command]
	 Used to inject environments variables into your application process

     OPTIONS
	 --c --command chained commands to execute (e.g. "npm install && npm run
	 dev; echo ...")

	 --e --env
		set  the  environment  (dev, prod, etc.) from which your secrets
		should be pulled from

	 --expand
		parse shell parameter expansions in your secrets

	 --include-imports
		import linked secrets

	 --path
		get secrets within a folder  path  (can  be  specified	multiple
		times)

	 --project-config-dir
		explicitly set the directory where the .infisical.json resides

	 --projectId
		manually set the project ID to fetch secrets from when using ma-
		chine identity based auth

	 --recursive
		fetch secrets from all sub-folders

	 --secret-overriding
		prioritizes  personal  secrets,  if any, with the same name over
		shared secrets

	 --t --tags
		filter secrets by tag slugs

	 --token
		fetch secrets using service token or machine identity access to-
		ken

	 --watch
		enable reload of application when secrets change

	 --watch-interval
		interval in seconds to check for secret changes

     scan
	 Scan for leaked secrets in git history, directories, and files

     OPTIONS
	 --b --baseline-path path to baseline with issues that can be ignored

	 --c --config
		config file path order of precedence: 1. --config  flag  2.  env
		var  INFISICAL_SCAN_CONFIG 3. (--source/-s)/.infisical-scan.toml
		If none of the three options are used, then Infisical  will  use
		the default scan config

	 --exit-code
		exit code when leaks have been encountered

	 --follow-symlinks
		scan files that are symlinks to other files

	 --log-opts
		git log options

	 --max-target-megabytes
		files larger than this will be skipped

	 --no-color
		turn off color for verbose output

	 --no-git
		treat  git  repo  as  a  regular directory and scan those files,
		--log-opts has no effect on the scan when --no-git is set

	 --pipe
		scan input from stdin,	ex:  `cat  some_file  |  infisical  scan
		--pipe`

	 --redact
		redact secrets from logs and stdout

	 --f --report-format
		output format (json, csv, sarif)

	 --r --report-path
		report file

	 --s --source
		path to source

	 --v --verbose
		show  verbose  output  from scan (which file, where in the file,
		what secret)

     COMMANDS
	 git-changes
	     Scan for secrets in uncommitted changes in a git repo

	 OPTIONS
	     --log-opts git log options

	     --staged
		    detect secrets in a --staged state

	 install
	     Install scanning scripts and tools. Use --help flag to see all  op-
	     tions

	 OPTIONS
	     --pre-commit-hook installs pre commit hook for Git repository

     secrets
	 Used to create, read update and delete secrets

     OPTIONS
	 --env	Used  to  select the environment name on which actions should be
	 taken on

	 --expand
		Parse shell parameter expansions in your  secrets,  and  process
		your referenced secrets

	 --include-imports
		Imported linked secrets

	 --o --output
		The output to format the secrets in. Supported formats are yaml,
		json, dotenv

	 --path
		get secrets within a folder path

	 --plain
		print  values  without formatting, one per line (deprecated, use
		--output instead)

	 --projectId
		manually set the projectId to fetch secrets when  using  machine
		identity based auth

	 --recursive
		Fetch secrets from all sub-folders

	 --secret-overriding
		Prioritizes  personal  secrets,  if any, with the same name over
		shared secrets

	 --t --tags
		filter secrets by tag slugs

	 --token
		Fetch secrets using service token or machine identity access to-
		ken

     COMMANDS
	 delete [secrets]
	     Used to delete secrets by name

	 OPTIONS
	     --o --output The output to format the secrets in. Supported formats
	     are yaml, json, dotenv

	     --path
		    get secrets within a folder path

	     --projectId
		    manually set the projectId to delete secrets from when using
		    machine identity based auth

	     --token
		    Fetch secrets using service token or machine identity access
		    token

	     --type
		    the type of secret to delete: personal or shared   (default:
		    personal)

	 folders
	     Create, delete, and list folders

	 OPTIONS
	     --env  Used  to select the environment name on which actions should
	     be taken on

	 COMMANDS
	     create
		 Create a folder

	     OPTIONS
		 --n --name Name  of  the  folder  to  be  created  in	selected
		 `--path`

		 --o --output
			The  output  to format the folders in. Supported formats
			are yaml, json, dotenv

		 --p --path
			Path to where the folder should be created

		 --projectId
			manually set the project ID for creating folders in when
			using machine identity based auth

		 --token
			Fetch secrets using service token  or  machine	identity
			access token

	     delete
		 Delete a folder

	     OPTIONS
		 --n  --name  Name  of	the folder to be deleted within selected
		 `--path`

		 --o --output
			The output to format the folders in.  Supported  formats
			are yaml, json, dotenv

		 --p --path
			Path to the folder to be deleted

		 --projectId
			manually  set the projectId to delete folders when using
			machine identity based auth

		 --token
			Fetch secrets using service token  or  machine	identity
			access token

	     get
		 Get folders in a directory

	     OPTIONS
		 --o  --output	The  output  to format the folders in. Supported
		 formats are yaml, json, dotenv

		 --p --path
			The path from where folders should be fetched from

		 --projectId
			manually set the projectId to fetch  folders  from  when
			using machine identity based auth

		 --token
			Fetch  secrets	using  service token or machine identity
			access token

	 generate-example-env
	     Used to generate a example .env file

	 OPTIONS
	     --path Fetch secrets from within a folder path

	     --projectId
		    manually set the projectId when using machine identity based
		    auth

	     --token
		    Fetch secrets using service token or machine identity access
		    token

	 get [secrets]
	     Used to retrieve secrets by name

	 OPTIONS
	     --expand Parse shell parameter  expansions  in  your  secrets,  and
	     process your referenced secrets

	     --include-imports
		    Imported linked secrets

	     --o --output
		    The  output  to format the secrets in. Supported formats are
		    yaml, json, dotenv

	     --path
		    get secrets within a folder path

	     --plain
		    print values without formatting, one per line

	     --projectId
		    manually set the project ID to fetch secrets from when using
		    machine identity based auth

	     --raw-value
		    deprecated. Returns only the value	of  secret,  only  works
		    with one secret. Use --plain instead

	     --recursive
		    Fetch secrets from all sub-folders

	     --secret-overriding
		    Prioritizes  personal  secrets,  if  any, with the same name
		    over shared secrets

	     --token
		    Fetch secrets using service token or machine identity access
		    token

	 set [secrets]
	     Used set secrets

	 OPTIONS
	     --file Load secrets from the specified file. File format:	.env  or
	     YAML  (comments:  #  or //). This option is mutually exclusive with
	     command-line secrets arguments.

	     --o --output
		    The output to format the secrets in. Supported  formats  are
		    yaml, json, dotenv

	     --path
		    set secrets within a folder path

	     --projectId
		    manually  set the project ID to for setting secrets when us-
		    ing machine identity based auth

	     --tag  Tags to associate with the secret. Can be specified multiple
		    times (e.g. --tag backend --tag production).  When	updating
		    an	existing  secret, the provided tags will replace any ex-
		    isting tags

	     --token
		    Fetch secrets using service token or machine identity access
		    token

	     --type
		    the type of secret to create: personal or shared

     service-token
	 Manage service tokens

     COMMANDS
	 create
	     Used to create service tokens

	 OPTIONS
	     --a --access-level The type of  access  the  service  token  should
	     have. Can be 'read' and or 'write'

	     --e --expiry-seconds
		    Set the service token's expiration time in seconds from now.
		    To never expire set to zero. Default: 1 day

	     --n --name
		    Service token name

	     --projectId
		    The  project  ID you'd like to create the service token for.
		    Default: will  use	linked	Infisical  project  in	.infisi-
		    cal.json

	     --s --scope
		    Environment   and	secret	 path.	 Example  format:  <env-
		    slug>:<folder-path>

	     --token-only
		    When true, only the service token will be printed

     ssh
	 Used to issue SSH credentials

     COMMANDS
	 add-host
	     Register a new SSH host with Infisical

	 OPTIONS
	     --alias Alias for the SSH host

	     --configure-sshd
		    Update `TrustedUserCAKeys`, `HostKey`, and `HostCertificate`
		    in the `/etc/ssh/sshd_config` file

	     --force
		    Force overwrite of existing certificate  files  as	part  of
		    `--write-user-ca-to-file` and `--write-host-cert-to-file`

	     --hostname
		    Hostname of the SSH host (required)

	     --projectId
		    Project ID the host belongs to (required)

	     --token
		    Use a machine identity access token

	     --user-ca-out-file-path
		    Custom file path to write the User CA public key

	     --write-host-cert-to-file
		    Write  SSH host certificate to /etc/ssh/ssh_host_<type>_key-
		    cert.pub

	     --write-user-ca-to-file
		    Write User CA public key to /etc/ssh/infisical_user_ca.pub

	 connect
	     Connect to an SSH host using issued credentials

	 OPTIONS
	     --hostname Hostname of the SSH host to connect to

	     --login-user
		    Login user for the SSH connection

	     --out-file-path
		    The path to write the SSH credentials  to  such  as  ~/.ssh,
		    ./some_folder,  ./some_folder/id_rsa-cert.pub.  If	not pro-
		    vided, the credentials will be added to the  SSH  agent  and
		    used to establish an interactive SSH connection

	     --token
		    Use a machine identity access token

	     --write-host-ca-to-file
		    Write Host CA public key to ~/.ssh/known_hosts as a separate
		    entry if doesn't already exist

	 issue-credentials
	     Used to issue SSH credentials against a certificate template

	 OPTIONS
	     --addToAgent Whether to add issued SSH credentials to the SSH agent

	     --certType
		    The cert type to issue SSH credentials for

	     --certificateTemplateId
		    The  ID of the SSH certificate template to issue SSH creden-
		    tials for

	     --keyAlgorithm
		    The key algorithm to issue SSH credentials for

	     --keyId
		    The keyId to issue SSH credentials for

	     --outFilePath
		    The path to write the SSH credentials  to  such  as  ~/.ssh,
		    ./some_folder,  ./some_folder/id_rsa-cert.pub.  If	not pro-
		    vided, the credentials will be saved to the current  working
		    directory

	     --principals
		    The principals to issue SSH credentials for

	     --token
		    Issue SSH credentials using machine identity access token

	     --ttl  The ttl to issue SSH credentials for

	 sign-key
	     Used to sign a SSH public key against a certificate template

	 OPTIONS
	     --certType The cert type for the created certificate

	     --certificateTemplateId
		    The ID of the SSH certificate template to issue the SSH cer-
		    tificate for

	     --keyId
		    The keyId that the created certificate should have

	     --outFilePath
		    The   path	 to   write  the  SSH  certificate  to	such  as
		    ~/.ssh/id_rsa-cert.pub. If	not  provided,	the  credentials
		    will  be  saved to the directory of the specified public key
		    file path or the current working directory

	     --principals
		    The principals that the certificate should be signed for

	     --publicKey
		    The public key to sign

	     --publicKeyFilePath
		    The file path to the public key file to sign

	     --token
		    Issue SSH certificate using machine identity access token

	     --ttl  The ttl for the created certificate

     token
	 Manage your access tokens

     COMMANDS
	 renew [token]
	     Used to renew your universal auth access token

     user
	 Used to manage local user credentials

     COMMANDS
	 get
	     Used to get properties of an Infisical profile

	 COMMANDS
	     token
		 Used to get the access token of an Infisical user

	     OPTIONS
		 --plain print token without formatting

	 switch
	     Used to switch between Infisical profiles

	 update
	     Used to update properties of an Infisical profile

	 COMMANDS
	     domain
		 Used to update the domain of an Infisical profile

     vault
	 Used to manage where your Infisical login token is saved  on  your  ma-
	 chine

     COMMANDS
	 set [file|auto]
	     Used to configure the vault backends

infisical			   2026-08-29			       IN...L(1)

home | help