Skip to main content
The Relic CLI handles authentication, project initialization, and secret injection. For interactive use, see the TUI.

Commands

relic

Opens the TUI. This is the default command when no arguments are provided.

relic login

Authenticate via device authorization. A browser window opens for you to sign in with Google or GitHub.

relic logout

Clear your session, cached encryption keys, and stored password.

relic whoami

Show the currently authenticated user.

relic projects

List all projects you own or have been shared with, including their environments and folders.

relic init

Initialize Relic in the current project. Creates relic.toml and .relic/ directory.
Run this at the root of the project where you want to inject secrets.
Add .relic/ to your .gitignore. See Introduction for details.

relic run

Run a command with secrets injected as environment variables.
Examples:

relic telemetry

Manage anonymous usage telemetry.
See Telemetry for details on what is collected.

Configuration File

relic.toml is created by relic init at your project root:
The CLI walks up from the current directory to find relic.toml. You can override the project ID with --project or RELIC_PROJECT_ID.

Caching

The CLI caches data locally at .relic/cache.db (relative to relic.toml) to reduce API calls.
  • Session mode: Cache is used. Validated against the server’s updatedAt timestamp on each run.
  • API key mode: Cache is not used. Secrets are always fetched fresh.
  • Scope filtering (--scope): Applied locally against cached data. No extra API call needed.
To clear the cache, delete .relic/cache.db. The next run will fetch fresh data.

CI/CD

For non-interactive environments, use API keys instead of relic login.

GitHub Actions

See Environment Variables for the full list.
Last modified on May 2, 2026