IN...LInfisical CLI is used to inject environment variables into any proIN...L(1) NAME infisical - Infisical CLI is used to inject environment variables into any process SYNOPSIS infisical [options...] [argument...] DESCRIPTION Infisical is a simple, end-to-end encrypted service that enables teams to sync and manage their environment variables across their development life cycle. OPTIONS --domain Point the CLI to your Infisical instance (e.g., https://eu.infisi- cal.com for EU Cloud, or https://your-instance.com for self-hosted). Can also set via INFISICAL_DOMAIN environment variable or the 'do- main' field in .infisical.json. Required for non-US Cloud users. --l --log-level log level (trace, debug, info, warn, error, fatal) --silent Disable output of tip/info messages. Useful when running in scripts or CI/CD pipelines. --telemetry Infisical collects non-sensitive telemetry data to enhance features and improve user experience. Participation is voluntary COMMANDS agent Used to launch a client daemon that streamlines authentication and se- cret retrieval processes in various environments OPTIONS --config The path to agent config yaml file bootstrap Used to bootstrap your Infisical instance OPTIONS --domain The domain of your self-hosted Infisical instance --email The desired email address of the instance admin --ignore-if-bootstrapped Whether to continue on error if the instance has already been bootstrapped --k8-secret-name The name of the Kubernetes secret to create --k8-secret-namespace The namespace to create the Kubernetes secret in --k8-secret-template The template to use for rendering the Kubernetes secret (entire secret JSON) --organization The name of the organization to create for the instance --output The type of output to use for the bootstrap command (json or k8-secret) --password The desired password of the instance admin cert-manager Certificate management commands COMMANDS agent Launch certificate management agent OPTIONS --config The path to certificate agent config yaml file --v --verbose Enable verbose logging for certificate management agent dynamic-secrets Used to list dynamic secrets OPTIONS --env Used to select the environment name on which actions should be taken on --o --output The output to format the dynamic secrets in. Supported formats are yaml, json, dotenv --path get dynamic secret within a folder path --project-slug Manually set the project-slug to fetch dynamic-secret from --projectId Manually set the projectId to fetch dynamic-secret when using machine identity based auth --token Fetch secrets using service token or machine identity access to- ken COMMANDS lease Manage leases for dynamic secrets COMMANDS create [dynamic-secret] Used to lease dynamic secret by name OPTIONS --kubernetes-namespace The namespace to create the lease in. Only used for Kubernetes dynamic secrets. --o --output The output to format the leased credentials in. Sup- ported formats are yaml, json, dotenv --p --path The path from where dynamic secret should be leased from --plain Print leased credentials without formatting, one per line --principals Comma-separated list of principals for SSH dynamic se- cret leases --project-slug Manually set the project-slug to create lease in --projectId Manually set the projectId to fetch leased from when us- ing machine identity based auth --token Create dynamic secret leases using machine identity ac- cess token --ttl The lease lifetime TTL. If not provided the default TTL of dynamic secret will be used. delete [lease-id] Used to delete dynamic secret lease by name OPTIONS --o --output The output to format the dynamic secret lease re- vocation in. Supported formats are yaml, json, dotenv --p --path The path from where dynamic secret should be leased from --project-slug Manually set the project-slug to revoke lease from --projectId Manually set the projectId to fetch leased from when us- ing machine identity based auth --token Delete dynamic secrets using machine identity access to- ken list [dynamic-secret] Used to list leases of a dynamic secret by name OPTIONS --o --output The output to format the dynamic secret leases in. Supported formats are yaml, json, dotenv --p --path The path from where dynamic secret should be leased from --project-slug Manually set the project-slug to list leases from --projectId Manually set the projectId to fetch leased from when us- ing machine identity based auth --token Fetch dynamic secret leases machine identity access to- ken renew [lease-id] Used to renew dynamic secret lease by name OPTIONS --o --output The output to format the dynamic secret lease re- newal in. Supported formats are yaml, json, dotenv --p --path The path from where dynamic secret should be leased from --project-slug Manually set the project-slug to renew lease in --projectId Manually set the projectId to fetch leased from when us- ing machine identity based auth --token Renew dynamic secrets machine identity access token --ttl The lease lifetime TTL. If not provided the default TTL of dynamic secret will be used. export Used to export environment variables to a file OPTIONS --e --env Set the environment (dev, prod, etc.) from which your secrets should be pulled from --expand Parse shell parameter expansions in your secrets --f --format Set the format of the output file (dotenv, dotenv-export, dotenv-eval, json, csv, yaml) --include-imports Imported linked secrets --o --output-file The path to write the output file to. Can be a full file path, directory, or filename. If not specified, output will be printed to stdout --path get secrets within a folder path --projectId manually set the projectId to export secrets from --secret-overriding Prioritizes personal secrets, if any, with the same name over shared secrets --t --tags filter secrets by tag slugs --template The path to the template file used to render secrets --token Fetch secrets using service token or machine identity access to- ken gateway Run the Infisical gateway or manage its systemd service OPTIONS --auth-method login method [universal-auth, kubernetes, azure, gcp-id- token, gcp-iam, aws-iam, oidc-auth]. if not provided, you must set the token flag --client-id client id for universal auth --client-secret client secret for universal auth --jwt JWT for jwt-based auth methods [oidc-auth, jwt-auth] --machine-identity-id machine identity id for kubernetes, azure, gcp-id-token, gcp- iam, and aws-iam auth methods --service-account-key-file-path service account key file path for GCP IAM auth --service-account-token-path service account token path for kubernetes auth --token connect with Infisical using machine identity access token. if not provided, you must set the auth-method flag COMMANDS install Install and enable systemd service for the gateway (requires sudo) OPTIONS --domain Domain of your self-hosted Infisical instance --token Connect with Infisical using machine identity access token relay Used to run infisical gateway relay OPTIONS --config Relay config yaml file path start [name] Start the new Infisical gateway OPTIONS --auth-method login method [universal-auth, kubernetes, azure, gcp- id-token, gcp-iam, aws-iam, oidc-auth]. if not provided, you must set the token flag --client-id client id for universal auth --client-secret client secret for universal auth --domain domain of your self-hosted Infisical instance (used with --enroll-method=token or --enroll-method=aws) --enroll-method gateway auth method [token, aws]. when set to 'token', uses --token as a one-time enrollment token. when set to 'aws', authenticates via signed STS GetCallerIdentity using --gate- way-id --gateway-id gateway id (required when --enroll-method=aws) --jwt JWT for jwt-based auth methods [oidc-auth, jwt-auth] --machine-identity-id machine identity id for kubernetes, azure, gcp-id-token, gcp-iam, and aws-iam auth methods --name name of the gateway (deprecated, use positional argument in- stead) --organization-slug When set, this will scope the login session to the specified sub-organization the machine identity has access to. If left empty, the session defaults to the organization where the machine identity was created in. --pam-session-recording-path directory path for PAM session recordings (defaults to /var/lib/infisical/session_recordings) --pkcs11-module absolute path to a PKCS#11 driver (e.g. /opt/fort- anix/pkcs11/fortanix_pkcs11.so). When set, the gateway loads the driver and serves HSM operations through it. --relay name of the relay to connect to (deprecated, use --target- relay-name) --service-account-key-file-path service account key file path for GCP IAM auth --service-account-token-path service account token path for kubernetes auth --target-relay-name name of the relay to connect to --token enrollment token or access token for authenticating with In- fisical systemd Manage systemd service for Infisical gateway COMMANDS install [name] Install and enable systemd service for the gateway (v2) (re- quires sudo) OPTIONS --domain Domain of your self-hosted Infisical instance --enroll-method gateway auth method [token, aws]. when set to 'token', uses --token as a one-time enrollment token. when set to 'aws', the gateway authenticates via AWS STS on each service start (requires --gateway-id) --gateway-id gateway id (required when --enroll-method=aws) --log-file The file to write the service logs to. Example: /var/log/infisical/gateway.log. If not provided, logs will not be written to a file. --name The name of the gateway (deprecated, use positional ar- gument instead) --pkcs11-module absolute path to a PKCS#11 driver (e.g. /opt/fort- anix/pkcs11/fortanix_pkcs11.so). When set, the systemd service starts the gateway with the PKCS#11 driver loaded for HSM operations. --relay The name of the relay (deprecated, use --target-relay- name) --target-relay-name The name of the relay --token enrollment token or access token for authenticating with Infisical uninstall [name] Uninstall and remove systemd service for the gateway (requires sudo) uninstall Uninstall and remove systemd service for the gateway (requires sudo) help [command] Help about any command init Used to connect your local project with Infisical project kmip Used to manage KMIP servers COMMANDS start [server-name] Used to start a KMIP server OPTIONS --certificate-ttl The TTL duration for the server certificate. De- faults to 1y --domain Domain of your self-hosted Infisical instance --enroll-method Enrollment method for the KMIP server: 'token' or 'aws'. When set, machine-identity flags are ignored. --hostnames-or-ips Comma-separated list of hostnames or IPs --identity-auth-method The auth method to use for authenticating the machine iden- tity. Defaults to universal-auth. --identity-client-id Universal auth client ID of machine identity --identity-client-secret Universal auth client secret of machine identity --kmip-server-id KMIP server ID (when --enroll-method=aws) --listen-address The address for the KMIP server to listen on. Defaults to localhost:5696 --server-name The name of the KMIP server. Alternative to passing it as a positional argument; required if not passed positionally --token Enrollment token (when --enroll-method=token) systemd Manage systemd service for Infisical KMIP server COMMANDS install [server-name] Install and enable systemd service for the KMIP server (re- quires sudo) OPTIONS --certificate-ttl The TTL duration for the server certificate --domain Domain of your self-hosted Infisical instance --enroll-method Enrollment method for the KMIP server: 'token' or 'aws'. When set, machine-identity flags are ignored. --hostnames-or-ips Comma-separated list of hostnames or IPs --identity-client-id Universal auth client ID of machine identity --identity-client-secret Universal auth client secret of machine identity --kmip-server-id KMIP server ID (when --enroll-method=aws) --listen-address The address for the KMIP server to listen on --server-name The name of the KMIP server. Alternative to passing it as a positional argument; required if not passed posi- tionally --token Enrollment token (when --enroll-method=token) uninstall Uninstall and remove systemd service for the KMIP server (re- quires sudo) login Login into your Infisical account OPTIONS --clear-domains clear all self-hosting domains from the config file --client-id client id for universal auth --client-secret client secret for universal auth --email email for 'user' login method --i --interactive login via the command line --jwt jwt for jwt-based login methods [oidc-auth, jwt-auth] --machine-identity-id machine identity id for these login methods [kubernetes, azure, gcp-id-token, gcp-iam, aws-iam] --method login method [user, universal-auth, kubernetes, azure, gcp-id- token, gcp-iam, aws-iam, oidc-auth] --oidc-jwt JWT for OIDC authentication. Deprecated, use --jwt instead --organization-id organization id for 'user' login method --organization-slug When set for machine identity login, this will scope the login session to the specified sub-organization the machine identity has access to. If left empty, the session defaults to the orga- nization where the machine identity was created in. --password password for 'user' login method --plain only output the token without any formatting --service-account-key-file-path service account key file path for GCP IAM auth --service-account-token-path service account token path for kubernetes auth COMMANDS status View the current authentication status OPTIONS --json Output the login status as JSON --token Inspect this machine identity access token instead of the active session or environment variables pam PAM-related commands COMMANDS db Database-related PAM commands COMMANDS access Access PAM database accounts OPTIONS --account Name of the account within the resource --duration Duration for database access session (e.g., '1h', '30m', '2h30m') --port Port for the local database proxy server (0 for auto-as- sign) --project-id Project ID of the account to access --reason Reason for accessing the account (stored for audit pur- poses) --resource Name of the PAM resource to access kubernetes Kubernetes-related PAM commands COMMANDS access Access Kubernetes PAM account OPTIONS --account Name of the account within the resource --duration Duration for kubernetes access session (e.g., '1h', '30m', '2h30m') --port Port for the local kubernetes proxy server (0 for auto- assign) --project-id Project ID of the account to access --reason Reason for accessing the account (stored for audit pur- poses) --resource Name of the PAM resource to access rdp RDP-related PAM commands COMMANDS access Access PAM Windows/RDP accounts OPTIONS --account Name of the account within the resource --duration Duration for RDP access session (e.g., '1h', '30m', '2h30m') --no-launch Do not auto-launch the system RDP client; print connec- tion details only --port Port for the local RDP proxy server (0 for auto-assign) --project-id Project ID of the account to access --reason Reason for accessing the account (stored for audit pur- poses) --resource Name of the PAM resource to access redis Redis-related PAM commands COMMANDS access Access PAM Redis accounts OPTIONS --account Name of the account within the resource --duration Duration for Redis access session (e.g., '1h', '30m', '2h30m') --port Port for the local Redis proxy server (0 for auto-as- sign) --project-id Project ID of the account to access --reason Reason for accessing the account (stored for audit pur- poses) --resource Name of the PAM resource to access ssh SSH-related PAM commands COMMANDS access Start interactive SSH session to PAM account OPTIONS --account Name of the account within the resource --duration Duration for SSH access session (e.g., '1h', '30m', '2h30m') --project-id Project ID of the account to access --reason Reason for accessing the account (stored for audit pur- poses) --resource Name of the PAM resource to access exec [command] Execute a command on a PAM SSH account OPTIONS --account Name of the account within the resource --duration Duration for SSH access session (e.g., '1h', '30m', '2h30m') --project-id Project ID of the account to access --reason Reason for accessing the account (stored for audit pur- poses) --resource Name of the PAM resource to access proxy Start SSH proxy for SCP, SFTP, or rsync OPTIONS --account Name of the account within the resource --duration Duration for SSH access session (e.g., '1h', '30m', '2h30m') --project-id Project ID of the account to access --reason Reason for accessing the account (stored for audit pur- poses) --resource Name of the PAM resource to access proxy Used to run Infisical proxy server COMMANDS start Start the Infisical proxy server OPTIONS --access-token-check-interval How often to validate that access to- kens are still valid (e.g., 5m, 1h). Defaults to 5m. --client-id Machine identity universal auth client ID. This is required when using event subscriptions. --client-secret Machine identity universal auth client secret. This is re- quired when using event subscriptions. --domain Domain of your Infisical instance (e.g., https://app.infisi- cal.com for cloud, https://my-self-hosted-instance.com for self-hosted) --enable-event-subscriptions Enable Event Subscription mode for real-time cache invalida- tion. When enabled, the static secrets refresh loop is dis- abled. If event subscriptions are unavailable, the proxy will fall back to a polling mechanism. `--client id` and `--client-secret` are required when this is set to true --eviction-strategy Cache eviction strategy. 'optimistic' keeps cached data when Infisical is unreachable for high availability. Currently only 'optimistic' is supported. --listen-address The address for the proxy server to listen on. Defaults to localhost:8081 --polling-fallback-interval How often to poll for secret changes when SSE is unavailable (e.g., 1m, 5m). Defaults to 5m. Only used when --enable- event-subscriptions is set. --static-secrets-refresh-interval How often to refresh cached secrets (e.g., 30m, 1h, 1d). De- faults to 1h. --tls-cert-file The path to the TLS certificate file for the proxy server. Required when `tls-enabled` is set to true (default) --tls-enabled Whether to enable TLS for the proxy server. Defaults to true --tls-key-file The path to the TLS key file for the proxy server. Required when `tls-enabled` is set to true (default) relay Relay-related commands COMMANDS start Start the Infisical relay component OPTIONS --auth-method login method [universal-auth, kubernetes, azure, gcp- id-token, gcp-iam, aws-iam, oidc-auth]. if not provided, you must set the token flag --client-id client id for universal auth --client-secret client secret for universal auth --domain domain of your self-hosted Infisical instance (used with --enroll-method) --enroll-method relay auth method [token, aws]. when set to 'token', uses --token as a one-time enrollment token. when set to 'aws', authenticates via signed STS GetCallerIdentity using --re- lay-id --host The IP or hostname for the relay --jwt JWT for jwt-based auth methods [oidc-auth, jwt-auth] --machine-identity-id machine identity id for kubernetes, azure, gcp-id-token, gcp-iam, and aws-iam auth methods --name The name of the relay --relay-id relay id (required when --enroll-method=aws) --service-account-key-file-path service account key file path for GCP IAM auth --service-account-token-path service account token path for kubernetes auth --token connect with Infisical using machine identity access token, or a one-time enrollment token when --enroll-method=token --type The type of relay to run. Defaults to 'org' systemd Manage systemd service for Infisical relay COMMANDS install Install and enable systemd service for the relay (requires sudo) OPTIONS --domain Domain of your self-hosted Infisical instance --host The IP or hostname for the relay --log-file The file to write the service logs to. Example: /var/log/infisical/relay.log. If not provided, logs will not be written to a file. --name The name of the relay --relay-auth-secret Relay auth secret (required for type=instance if env not set) --token Connect with Infisical using machine identity access to- ken (org type) --type The type of relay to run. Defaults to 'org' uninstall Uninstall and remove systemd service for the relay (requires sudo) reset Used to delete all Infisical related data on your machine run [any infisical run command flags] -- [your application start command] Used to inject environments variables into your application process OPTIONS --c --command chained commands to execute (e.g. "npm install && npm run dev; echo ...") --e --env set the environment (dev, prod, etc.) from which your secrets should be pulled from --expand parse shell parameter expansions in your secrets --include-imports import linked secrets --path get secrets within a folder path (can be specified multiple times) --project-config-dir explicitly set the directory where the .infisical.json resides --projectId manually set the project ID to fetch secrets from when using ma- chine identity based auth --recursive fetch secrets from all sub-folders --secret-overriding prioritizes personal secrets, if any, with the same name over shared secrets --t --tags filter secrets by tag slugs --token fetch secrets using service token or machine identity access to- ken --watch enable reload of application when secrets change --watch-interval interval in seconds to check for secret changes scan Scan for leaked secrets in git history, directories, and files OPTIONS --b --baseline-path path to baseline with issues that can be ignored --c --config config file path order of precedence: 1. --config flag 2. env var INFISICAL_SCAN_CONFIG 3. (--source/-s)/.infisical-scan.toml If none of the three options are used, then Infisical will use the default scan config --exit-code exit code when leaks have been encountered --follow-symlinks scan files that are symlinks to other files --log-opts git log options --max-target-megabytes files larger than this will be skipped --no-color turn off color for verbose output --no-git treat git repo as a regular directory and scan those files, --log-opts has no effect on the scan when --no-git is set --pipe scan input from stdin, ex: `cat some_file | infisical scan --pipe` --redact redact secrets from logs and stdout --f --report-format output format (json, csv, sarif) --r --report-path report file --s --source path to source --v --verbose show verbose output from scan (which file, where in the file, what secret) COMMANDS git-changes Scan for secrets in uncommitted changes in a git repo OPTIONS --log-opts git log options --staged detect secrets in a --staged state install Install scanning scripts and tools. Use --help flag to see all op- tions OPTIONS --pre-commit-hook installs pre commit hook for Git repository secrets Used to create, read update and delete secrets OPTIONS --env Used to select the environment name on which actions should be taken on --expand Parse shell parameter expansions in your secrets, and process your referenced secrets --include-imports Imported linked secrets --o --output The output to format the secrets in. Supported formats are yaml, json, dotenv --path get secrets within a folder path --plain print values without formatting, one per line (deprecated, use --output instead) --projectId manually set the projectId to fetch secrets when using machine identity based auth --recursive Fetch secrets from all sub-folders --secret-overriding Prioritizes personal secrets, if any, with the same name over shared secrets --t --tags filter secrets by tag slugs --token Fetch secrets using service token or machine identity access to- ken COMMANDS delete [secrets] Used to delete secrets by name OPTIONS --o --output The output to format the secrets in. Supported formats are yaml, json, dotenv --path get secrets within a folder path --projectId manually set the projectId to delete secrets from when using machine identity based auth --token Fetch secrets using service token or machine identity access token --type the type of secret to delete: personal or shared (default: personal) folders Create, delete, and list folders OPTIONS --env Used to select the environment name on which actions should be taken on COMMANDS create Create a folder OPTIONS --n --name Name of the folder to be created in selected `--path` --o --output The output to format the folders in. Supported formats are yaml, json, dotenv --p --path Path to where the folder should be created --projectId manually set the project ID for creating folders in when using machine identity based auth --token Fetch secrets using service token or machine identity access token delete Delete a folder OPTIONS --n --name Name of the folder to be deleted within selected `--path` --o --output The output to format the folders in. Supported formats are yaml, json, dotenv --p --path Path to the folder to be deleted --projectId manually set the projectId to delete folders when using machine identity based auth --token Fetch secrets using service token or machine identity access token get Get folders in a directory OPTIONS --o --output The output to format the folders in. Supported formats are yaml, json, dotenv --p --path The path from where folders should be fetched from --projectId manually set the projectId to fetch folders from when using machine identity based auth --token Fetch secrets using service token or machine identity access token generate-example-env Used to generate a example .env file OPTIONS --path Fetch secrets from within a folder path --projectId manually set the projectId when using machine identity based auth --token Fetch secrets using service token or machine identity access token get [secrets] Used to retrieve secrets by name OPTIONS --expand Parse shell parameter expansions in your secrets, and process your referenced secrets --include-imports Imported linked secrets --o --output The output to format the secrets in. Supported formats are yaml, json, dotenv --path get secrets within a folder path --plain print values without formatting, one per line --projectId manually set the project ID to fetch secrets from when using machine identity based auth --raw-value deprecated. Returns only the value of secret, only works with one secret. Use --plain instead --recursive Fetch secrets from all sub-folders --secret-overriding Prioritizes personal secrets, if any, with the same name over shared secrets --token Fetch secrets using service token or machine identity access token set [secrets] Used set secrets OPTIONS --file Load secrets from the specified file. File format: .env or YAML (comments: # or //). This option is mutually exclusive with command-line secrets arguments. --o --output The output to format the secrets in. Supported formats are yaml, json, dotenv --path set secrets within a folder path --projectId manually set the project ID to for setting secrets when us- ing machine identity based auth --tag Tags to associate with the secret. Can be specified multiple times (e.g. --tag backend --tag production). When updating an existing secret, the provided tags will replace any ex- isting tags --token Fetch secrets using service token or machine identity access token --type the type of secret to create: personal or shared service-token Manage service tokens COMMANDS create Used to create service tokens OPTIONS --a --access-level The type of access the service token should have. Can be 'read' and or 'write' --e --expiry-seconds Set the service token's expiration time in seconds from now. To never expire set to zero. Default: 1 day --n --name Service token name --projectId The project ID you'd like to create the service token for. Default: will use linked Infisical project in .infisi- cal.json --s --scope Environment and secret path. Example format: <env- slug>:<folder-path> --token-only When true, only the service token will be printed ssh Used to issue SSH credentials COMMANDS add-host Register a new SSH host with Infisical OPTIONS --alias Alias for the SSH host --configure-sshd Update `TrustedUserCAKeys`, `HostKey`, and `HostCertificate` in the `/etc/ssh/sshd_config` file --force Force overwrite of existing certificate files as part of `--write-user-ca-to-file` and `--write-host-cert-to-file` --hostname Hostname of the SSH host (required) --projectId Project ID the host belongs to (required) --token Use a machine identity access token --user-ca-out-file-path Custom file path to write the User CA public key --write-host-cert-to-file Write SSH host certificate to /etc/ssh/ssh_host_<type>_key- cert.pub --write-user-ca-to-file Write User CA public key to /etc/ssh/infisical_user_ca.pub connect Connect to an SSH host using issued credentials OPTIONS --hostname Hostname of the SSH host to connect to --login-user Login user for the SSH connection --out-file-path The path to write the SSH credentials to such as ~/.ssh, ./some_folder, ./some_folder/id_rsa-cert.pub. If not pro- vided, the credentials will be added to the SSH agent and used to establish an interactive SSH connection --token Use a machine identity access token --write-host-ca-to-file Write Host CA public key to ~/.ssh/known_hosts as a separate entry if doesn't already exist issue-credentials Used to issue SSH credentials against a certificate template OPTIONS --addToAgent Whether to add issued SSH credentials to the SSH agent --certType The cert type to issue SSH credentials for --certificateTemplateId The ID of the SSH certificate template to issue SSH creden- tials for --keyAlgorithm The key algorithm to issue SSH credentials for --keyId The keyId to issue SSH credentials for --outFilePath The path to write the SSH credentials to such as ~/.ssh, ./some_folder, ./some_folder/id_rsa-cert.pub. If not pro- vided, the credentials will be saved to the current working directory --principals The principals to issue SSH credentials for --token Issue SSH credentials using machine identity access token --ttl The ttl to issue SSH credentials for sign-key Used to sign a SSH public key against a certificate template OPTIONS --certType The cert type for the created certificate --certificateTemplateId The ID of the SSH certificate template to issue the SSH cer- tificate for --keyId The keyId that the created certificate should have --outFilePath The path to write the SSH certificate to such as ~/.ssh/id_rsa-cert.pub. If not provided, the credentials will be saved to the directory of the specified public key file path or the current working directory --principals The principals that the certificate should be signed for --publicKey The public key to sign --publicKeyFilePath The file path to the public key file to sign --token Issue SSH certificate using machine identity access token --ttl The ttl for the created certificate token Manage your access tokens COMMANDS renew [token] Used to renew your universal auth access token user Used to manage local user credentials COMMANDS get Used to get properties of an Infisical profile COMMANDS token Used to get the access token of an Infisical user OPTIONS --plain print token without formatting switch Used to switch between Infisical profiles update Used to update properties of an Infisical profile COMMANDS domain Used to update the domain of an Infisical profile vault Used to manage where your Infisical login token is saved on your ma- chine COMMANDS set [file|auto] Used to configure the vault backends infisical 2026-08-29 IN...L(1)
NAME | SYNOPSIS | DESCRIPTION | OPTIONS | COMMANDS
Want to link to this manual page? Use this URL:
<https://man.FreeBSD.org/cgi/man.cgi?query=infisical&sektion=1&manpath=FreeBSD+Ports+15.1.quarterly>