LinuxWindowsmacOS

Where Does the Vault CLI Store Its Token?

Where the Vault CLI keeps its token file on each OS, and how login writes it.

Last updated

The Vault CLI caches its auth token in ~/.vault-token on Linux and macOS and %USERPROFILE%/.vault-token on Windows after every vault login. Later commands read that file silently.

VAULT_TOKEN env var overrides the file when set, which CI systems prefer. Locally the file is the session. A missing file means logged out, not broken; login recreates it in one step.

Where HashiCorp Vault stores this, by platform

Linux
~/.vault-token

Written by vault login, read by later CLI calls. VAULT_TOKEN env overrides it. Guard with 0600; delete to log out.

Windows
%USERPROFILE%\.vault-token

Same token role under the user profile. PowerShell and CMD both resolve the home path; WSL keeps its own separate file.

macOS
~/.vault-token

Same layout as Linux. Vault Agent setups may use a different sink path; check agent config when this file stays empty.

Frequently asked questions

How do I refresh the Vault token?

Run vault login -method=<m> to write a fresh token; the CLI stores it at the paths below automatically. Tokens expire server-side, so a stale file just fails closed. Delete the file to force re-login.

Is the token file sensitive?

The file holds a bearer token with whatever policies the login granted. Guard it like a password: 0600 permissions, no screenshots, no dotfile repos. Prefer short TTLs plus a helper (agent, env) over a permanent root token.

Notice an outdated path? Let us know.