.infisical.json links a directory to an Infisical project. When you run a command such as infisical run or infisical secrets in that directory, the CLI reads the project from the file, so you don’t have to pass --projectId.
The file can also choose an environment for you and pin the Infisical instance the project lives on.
The
.infisical.json file doesn’t include any sensitive values and is safe to commit to version control.Create the file
In the root of your codebase, run:.infisical.json to the current directory:
.infisical.json
workspaceId is the project’s ID. The other fields are empty until you set them, as described in the sections that follow. If you run infisical init again, the CLI replaces the file with a new one that holds only the project ID, so you lose any settings you added.
If you authenticate as a machine identity,
infisical run, infisical export, and infisical secrets don’t read workspaceId. Pass the project with --projectId or the INFISICAL_PROJECT_ID environment variable instead.Set the environment
Without an environment setting, commands read secrets from your project’sdev environment unless you pass --env. To use a different environment by default, set defaultEnvironment to the environment’s slug:
.infisical.json
gitBranchToEnvironmentMapping:
.infisical.json
/. For example, the branch release/staging matches the key staging. If your current branch has no mapping, or you aren’t on a branch (such as when you check out a specific commit), the CLI falls back to defaultEnvironment.
The CLI picks the environment in this order:
- The
--envflag - The environment mapped to your current Git branch
defaultEnvironmentdev
Set the Infisical instance
If your project is on EU Cloud, a dedicated instance, or a self-hosted instance, setdomain to the instance’s address:
.infisical.json
domain must be a URL that starts with https:// or http://, or the CLI ignores it and prints a warning.
We recommend using
https://, since over http://, the CLI sends secrets and credentials unencrypted.- The
--domainflag - The
INFISICAL_DOMAINenvironment variable, or the olderINFISICAL_API_URLifINFISICAL_DOMAINisn’t set domainin.infisical.json- US Cloud (
https://app.infisical.com)
infisical login uses domain to choose the instance to log in to. After that:
- Any commands you run will connect to the instance you logged in to, even if
domainspecifies a different one - If you pass
--domainor setINFISICAL_DOMAINto a different instance than the one you logged in to, the command fails
Use the file from another directory
The CLI looks for.infisical.json in the current directory, then in each parent directory up to the root of the file system. This means that if you have an .infisical.json file in the root of your codebase, that configuration applies to every directory under it.
To read the project from a file somewhere else, such as one package’s directory in a monorepo, pass the directory to infisical run with --project-config-dir:
--project-config-dir only sets the project. The environment and instance settings still come from the .infisical.json the CLI finds from your current directory.Field reference
string
The ID of the project to read secrets from. Not used when you authenticate as a machine identity.
string
The environment slug to use when
--env isn’t passed and no branch mapping matches.object
Maps branch names to environment slugs, such as
{ "main": "prod" }. Keys match only the last part of a branch name, after the final /.string
The folder to read secrets from when
--path and INFISICAL_SECRET_PATH aren’t set. Only the infisical secrets agent-proxy commands read it.string
The Infisical instance to connect to, such as
https://eu.infisical.com. Must start with https:// or http://.