Skip to main content
Every Infisical product that has a CLI workflow starts the same way: install the CLI, log in, and check that the CLI can reach your Infisical instance. This page covers those steps, then links to the command reference.

Prerequisites

Step 1: Install the CLI

Install the CLI with the package manager for your operating system.
Check that the installation worked:

Step 2: Log in

Log in with your own account when you run the CLI yourself, such as on your laptop during local development. Log in as a machine identity when the CLI runs without you, such as in a CI/CD pipeline, a container, a scheduled job, or a script on a shared server.
If your Infisical instance is behind a service that requires its own headers, such as Cloudflare Access, set those up first.
Authenticate the CLI with your Infisical account.
The prompt asks which instance you want to use. Select Infisical Cloud (US Region), Infisical Cloud (EU Region), or Self-Hosting or Dedicated Instance, then finish signing in through your browser.
On a machine with no browser, such as a remote SSH session, WSL 2, or Codespaces, run infisical login -i to log in from the terminal instead.
The CLI saves the instance you select with your login, so later commands use it without asking again.

Step 3: Check that you’re logged in

The CLI asks your Infisical instance whether your login is valid. If it is, the output starts with the account or machine identity you’re logged in as, followed by the instance the CLI connected to:
The lines after Domain include when your login expires and which organization it belongs to. If the output says You are not authenticated, log in again. If it says Failed to authenticate, check that the Domain line shows your instance, then log in again.
You successfully installed and logged into the Infisical CLI.

Next steps

Now that you’ve installed the CLI and logged in, you can start using its commands.

Command reference

See every CLI command, with its arguments, flags, and examples