This guide covers software that stores API keys, database passwords and tokens, then hands them to applications and pipelines at run time instead of leaving them in code.
We rank twelve tools on first-ninety-day effort, the bill once rotation and single sign-on are needed, exit, independence from partners, and fit.
AuthorHannah ReiterSenior Analyst, Business Applications
Vendors can pay for visibility on this page. It never changes what an entry
says about a product, including the criticism, and we earn nothing when you click through to a
vendor. How that works.
In short
What secrets management tools software does
Secrets management tools store credentials such as API keys and certificates encrypted, release them to authenticated applications on demand, record every access, and rotate or expire them on a schedule.
In this order: setup effort, what it really costs, how your data comes back out, whether
you can leave, and who each secrets management tool is built for. Why those five, and why there is no
score out of ten, is on the how we work page.
Large organisations already buying identity security from the same vendor
Small teams wanting published prices and a free start
Country is where the vendor is headquartered or contracts from, which is a
different question from where your data is hosted. Where the two tell different stories, the
entry says so.
Secrets manager with per-identity pricing and a perpetual free plan
Ranked #1 of 12 in Best Secrets Management Tools in 2026.
Free tierSelf-hostablePublished pricingNorth America
Three things are priced apart: secrets management per identity, privileged access per user, and certificates under their own plans. The free secrets plan stops at five identities and ten secret syncs, which a small team with several pipelines can reach quickly.
Pro adds SAML, rotation for public databases and 30 to 90 days of audit logs; KMIP, KMS and HSM support sit on Enterprise. Self-hosting is supported, but the vendor points licensed deployments to a consultation.
What stands out
Per-identity billing
MIT-licensed core
Cloud or self-hosted
Where it costs you
Dynamic secrets are limited to the Advanced plan and above, so database-credential workflows need the higher price.
Enterprise code sits under a separate licence, so the self-hosted route is not fully MIT.
Right for
Engineering teams that want published per-identity prices and the option to run it themselves
Wrong for
Teams needing HSM or KMIP without an enterprise contract
United StatesPer identity per month, published; free tier; 30-day trial on paid plans
Per-user secrets manager where service accounts are not billed
Ranked #2 of 12 in Best Secrets Management Tools in 2026.
Free tierSelf-hostablePublished pricingElsewhere
The pricing model favours automation heavy teams: service accounts are unlimited and free, while each person on Pro costs a monthly fee. Cloud hosting is on AWS in Frankfurt, according to the pricing page.
Self-hosting is documented with minimum requirements of two CPU cores and 2 GB of RAM, and you take over backups, TLS and updates. The free plan has community support only, and Enterprise adds SLAs and a Slack channel.
What stands out
Humans billed only
MIT-licensed core
Cloud or self-hosted
Where it costs you
Dynamic secrets, OIDC single sign-on and SCIM sit on the Enterprise plan.
Neither the terms nor the privacy policy gives a company address or country.
Right for
Small teams with many service accounts and few human users
Wrong for
Buyers who need a stated legal entity and address
Not stated by the vendorPer human user per month, published; free tier; 14-day trial on paid plans
Hosted secrets manager priced per user with a small free plan
Ranked #3 of 12 in Best Secrets Management Tools in 2026.
Free tierSelf-hostablePublished pricingNorth America
Doppler's meter is people: three users free, then a per-user fee on Developer, and a higher per-user fee on Team with a 14-day trial. Team lifts limits to 250 projects and 100 configs per environment, and adds SAML SSO and automatic rotation.
The pricing page says AI agents and non-human identities are not charged. Enterprise pricing is custom and brings dynamic secrets, key management and the on-prem option.
What stands out
Per-user billing
Free for three users
On-prem on Enterprise
Where it costs you
Dynamic secrets and on-prem deployment are limited to Enterprise.
Developer plan allows 10 projects and 4 environments, with three days of activity logs.
Right for
Product teams that want a hosted service and a bill that tracks headcount
Wrong for
Teams that must run the software in their own network
United StatesPer user per month, published; free for three users; 14-day trial on Team
Community fork of Vault under the Linux Foundation, licensed MPL-2.0
Ranked #4 of 12 in Best Secrets Management Tools in 2026.
Free tierOpen sourcePublished pricingNorth America
The licence and governance are the point. The repository is MPL-2.0 and the project is hosted by the Linux Foundation's OpenSSF as a Sandbox project, a status that signals an early stage.
Features match the Vault design: encrypted storage, dynamic secrets for systems such as AWS and databases, lease management and revocation of single secrets or whole trees. Sponsors listed include GitLab, SAP and Proton. No pricing page exists because the project sells nothing.
What stands out
Open source fork of Vault
MPL-2.0 licence
OpenSSF Sandbox project
Where it costs you
You run the cluster yourself, so the hours go into operations and not into licences.
It carries Sandbox status, and it follows Vault's design, so Vault knowledge transfers but a Vault vendor contract does not.
Right for
Platform teams with Vault experience who want a licence no single company controls
Wrong for
Teams that want a vendor to carry the pager
United StatesFree, open source (MPL-2.0); you run it yourself
SaaS secrets platform with a starter tier and quoted enterprise plans
Ranked #5 of 12 in Best Secrets Management Tools in 2026.
Free tierPricing on requestMiddle East
The pricing page counts different things per module: clients and secrets for secrets management, connectors for the multi-vault product, managed certificates, transactions for encryption and KMS, and users for the password manager.
That makes a quote hard to compare with per-user competitors. The page offers pure SaaS or hybrid SaaS where gateways run on your premises, and the vendor describes its Distributed Fragments Cryptography as zero knowledge.
What stands out
SaaS with gateways
Usage-based contracts
Zero-knowledge option
Where it costs you
Enterprise features such as HSM integration, log forwarding and SAML sit behind a sales conversation.
The starter tier keeps audit logs for only three days.
Right for
Companies wanting a vendor-run service with gateways inside their own network
Wrong for
Buyers who need published prices before talking to sales
IsraelUsage-based annual contracts, quoted per organisation; no prices shown
Encrypts values inside YAML and JSON files, with no server
Ranked #6 of 12 in Best Secrets Management Tools in 2026.
Free tierOpen sourcePublished pricingElsewhere
SOPS fits configuration that already lives in a repository. It was started at Mozilla in 2015 and moved to the CNCF as a Sandbox project in 2023.
Offline use works with age or PGP, and online use works with the key services of AWS, Google Cloud, Azure and HuaweiCloud, plus HashiCorp Vault and OpenBao. It does not replace a server that issues short-lived credentials, but it removes plain text from Git.
What stands out
Encrypted config files
MPL-2.0 licence
CNCF Sandbox project
Where it costs you
The tool encrypts files; the project pages describe no server, access policy or read audit trail.
Rotation and revocation rely on re-encrypting files and on the key service you pick.
Right for
Teams that keep infrastructure config in Git and want it encrypted
Wrong for
Organisations needing runtime access control and audit logs
Not stated by the vendorFree, open source (MPL-2.0); no hosted plans
Environments and secrets layer that pulls from other secret stores
Ranked #7 of 12 in Best Secrets Management Tools in 2026.
Free tierPublished pricingNorth America
ESC is a layer over secret stores, not a vault with its own offline mode. The docs state it requires the Pulumi Cloud backend. Environments are opened with a command and return values with secrets decrypted, and providers import from the stores named above.
Billing is per secret per month by edition, plus 10 cents per 10,000 API calls after the first 10,000, on top of the Pulumi Cloud edition price.
What stands out
Per-secret billing
Needs Pulumi Cloud
Pulls from other stores
Where it costs you
ESC requires the Pulumi Cloud backend, so the vendor is part of every setup.
The standalone esc CLI repository is archived, with the commands moved into the main Pulumi CLI.
Right for
Teams already on Pulumi that need to join secrets from several stores
Wrong for
Teams wanting a standalone vault with no Pulumi account
United StatesPer secret per month by edition, published; free tier of 25 secrets
Privileged credential vault for admin, service and root accounts
Ranked #8 of 12 in Best Secrets Management Tools in 2026.
Self-hostablePricing on requestNorth America
The product page lists the vault, account discovery, password rotation, session monitoring and approval workflows, in on-premises and cloud forms. A 30-day trial, interactive demos and quote requests are offered, but no price.
Because it is the base of a wider platform, adding modules to it changes the bill. Delinea Inc. gives a San Francisco mailing address and a London office for Delinea Europe Ltd.
What stands out
Privileged access vault
Cloud or on-premises
Quoted pricing
Where it costs you
The page lists no prices, so budgeting needs a sales quote.
It is a privileged access product, so developer workflows such as environment variables get less attention on its page.
Right for
IT security teams that control administrator, service and root account credentials
Wrong for
Developers wanting self-service secrets for each application environment
United StatesQuoted per organisation; 30-day trial
Pay-per-secret store inside AWS, billed per secret and per call
Ranked #9 of 12 in Best Secrets Management Tools in 2026.
Published pricingNorth America
The price list is simple: a per-secret monthly fee and a per-call fee, with versions created by rotation not charged.
AWS's own examples show the range, from a bill of roughly six dollars for 15 secrets to about 2,850 dollars a month for five million ephemeral secrets. The documentation tells you to use other AWS services for IAM credentials, encryption keys, SSH keys and certificates.
What stands out
Per-secret billing
AWS only
Rotation via Lambda
Where it costs you
Costs scale with the number of secrets, so many small ephemeral secrets become expensive.
Rotation functions are billed through Lambda, and customer-owned KMS keys are billed separately.
Right for
Teams whose workloads already run on AWS and need minimal setup
Wrong for
Multi-cloud teams wanting one secret store across providers
United StatesPer secret per month plus per 10,000 API calls, published; new-customer credits
Long-established secrets server, now owned by IBM, source available
Ranked #10 of 12 in Best Secrets Management Tools in 2026.
Pricing on requestNorth America
Vault supports static and dynamic secrets, certificates, encryption keys and an audit log of activity, with tokens issued after authentication through methods such as LDAP, AWS or Azure.
Storage can be the integrated cluster, recommended in the docs, or an external system. HCP Vault Dedicated is described as a hosted version of Vault Enterprise operated by HashiCorp, and new HCP users receive a starter credit.
What stands out
Owned by IBM
Business Source Licence
Self-managed or HCP
Where it costs you
The licence is source available and bars competing hosted offerings, so it is not open source.
The pricing page lists no Vault prices, and the HCP offering is sold through sales.
Right for
Large platform teams that need dynamic secrets and PKI with vendor support
Wrong for
Teams wanting a licence they can host for others
United StatesQuoted for Enterprise; source available Community edition; hosted trial credit
Secrets, keys and certificates store tied to Microsoft Entra ID
Ranked #11 of 12 in Best Secrets Management Tools in 2026.
Published pricingNorth America
Key Vault does not limit the number of secrets, keys or certificates in a vault, but transaction limits apply: 4,000 for most operations and 300 collectively for secret creation and imports in 10 seconds.
Premium adds HSM keys validated to FIPS 140-3 Level 3. Billing is per 10,000 transactions, with extra charges for certificate renewals, HSM keys and Managed HSM pools. Access is managed with Azure RBAC.
What stands out
Standard and Premium tiers
Entra ID access
Same-geography restore
Where it costs you
Backup blobs cannot be decrypted outside Azure and restore only in the same subscription and geography.
Each vault is throttled, for example 300 secret creations per 10 seconds.
Right for
Teams running on Azure that already use Entra ID for sign-in
Wrong for
Teams that may move workloads to another cloud provider
United StatesPer 10,000 transactions plus per-key HSM charges, published by tier
Former CyberArk secrets product, now sold by Palo Alto Networks
Ranked #12 of 12 in Best Secrets Management Tools in 2026.
Self-hostablePricing on requestNorth America
The vendor page describes storing API keys, tokens, passwords, certificates and database credentials, rotating and expiring them by policy, and a universal cryptographic identity model.
It can run as managed SaaS or self-hosted in your data centre, for air-gapped or data residency needs. Palo Alto Networks says CyberArk's solutions stay available as a standalone platform while integration proceeds, though the press release does not mention this product by name.
What stands out
Owned by Palo Alto Networks
SaaS or self-hosted
Quoted pricing
Where it costs you
The page shows no pricing, trial or plan limits.
Ownership moved to Palo Alto Networks in 2026 and the product brand changed to Idira.
Right for
Large organisations already buying identity security from the same vendor
Wrong for
Small teams wanting published prices and a free start
United StatesQuoted per organisation; demo on request
Secrets management tools store credentials such as API keys and certificates encrypted, release them to authenticated applications on demand, record every access, and rotate or expire them on a schedule. The differences that matter are rarely in the feature list, so this is
the order we would work through them.
01
Decide whether you need a published price
8 of the 12 tools here publish what they cost; the other 4 quote per organisation. The ones you can compare without a sales call: Infisical, Phase, Doppler, OpenBao, SOPS, Pulumi ESC, AWS Secrets Manager, Azure Key Vault.
02
Decide how much the jurisdiction matters
These 12 vendors are established in 3 countries across 3 regions (North America 9, Elsewhere 2, Middle East 1). That decides whose disclosure law applies to what the vendor holds, wherever the servers are.
03
Consider whether you want the source
2 of these are open source: OpenBao, SOPS. Hosting one yourself trades a subscription for maintenance.
Run it yourself or rent it: Infisical, OpenBao and HashiCorp Vault
The first decision is who carries the operations. OpenBao is MPL-2.0 software that you operate yourself, and HashiCorp Vault is also run by you unless you buy HCP Vault Dedicated, the hosted version operated by HashiCorp. Infisical and Phase can be self-hosted, but their enterprise features sit in a separate ee directory under a vendor licence, so a self-hosted install is rarely the whole product.
Doppler offers on-prem deployment only on Enterprise. In every self-run case you take over backups, upgrades and availability, and a secrets store that is down stops deployments, because pipelines cannot read the credentials they need. Count those hours in the first ninety days, not the licence line, and decide who is on call for the store before the first application depends on it.
Ask who restores the store after a failed upgrade and how long it takes.
Check which features sit in the licensed ee directory.
Price the hosted version of the same product before choosing to run it.
Three different meters: per identity, per user and per secret
Prices cannot be compared until the meter is known. Infisical bills per identity, Doppler per user, and Phase only for human users, with service accounts free. Pulumi ESC and AWS Secrets Manager bill per secret per month: AWS lists a per-secret monthly fee plus a fee per 10,000 API calls, and ESC lists 0.50, 0.75 or 1.00 per secret depending on edition.
A company with ten engineers and three hundred microservices pays very differently under each, and the ranking of cheap and expensive can flip when the headcount or the service count doubles. Count people, pipelines, applications and secrets separately, then run the same estimate through every meter before you compare headline prices.
Count humans, machine identities and secrets as three separate numbers.
Check whether API calls are charged on top of the stored secrets.
Ask whether AI agents and service accounts count as users.
Rotation and dynamic secrets are where the plans split
Most free plans store secrets; the features that remove standing passwords sit higher up. Infisical starts dynamic secrets at Advanced, and Doppler keeps them on Enterprise while rotation arrives on Team. Phase adds rotation on Pro and dynamic secrets on Enterprise. Akeyless gives the starter tier five dynamic and five rotated secrets.
AWS Secrets Manager rotates through Lambda functions that are billed at Lambda rates. Rotation was probably the reason you wanted a manager, so price the plan that includes it, not the plan on the front of the page. Ask what the free or entry plan keeps for audit logs, too: Doppler's Developer plan keeps three days of activity logs, and Akeyless's starter tier also keeps three, which is short for an incident review.
Write down which credentials must rotate automatically.
Find the plan that includes dynamic secrets for your database.
Check whether rotation runs inside the product or in a function you pay for.
Licences and lock-in: BSL, MPL-2.0 and cloud-bound stores
Licences differ more than the feature lists suggest. HashiCorp Vault uses the Business Source Licence 1.1 and is owned by IBM, which bars offering it as a competing hosted product. OpenBao forked from Vault and is MPL-2.0 under the OpenSSF, and SOPS is MPL-2.0 under the CNCF.
Azure Key Vault backups restore only within the same Azure subscription and geography, and Pulumi ESC requires the Pulumi Cloud backend. Check what leaves with you: a plain export of values is the only exit that works everywhere, and the licence decides who is allowed to host it for others. Test the export during the trial, with a real secret, before any application is wired to the store.
Export a test secret and confirm that it reads back outside the product.
Read the licence for hosting or embedding limits.
Check where backups can be restored.
What goes wrong most often when buying secrets management tools software
Buying a per-user plan for a platform where machine identities and AI agents outnumber people, or the reverse.
Treating a free plan as production-ready when Infisical's stops at five identities and Doppler's keeps three days of activity logs.
Choosing a cloud-bound store such as AWS Secrets Manager or Azure Key Vault for a workload that may move clouds.
Skipping the exit test and discovering that backups restore only in one subscription or geography.
07
Frequently asked questions
8 answers
What is the best secrets management tools in 2026?
Infisical leads our ranking of 12. Infisical Inc. is a single-product company whose core code is MIT licensed, with paid enterprise code kept in a separate directory. The free plan allows five identities and three environments, and paid plans bill per identity.
Dynamic secrets start on the Advanced plan, and audit logs and SAML need Pro or above. Privileged access and certificate management are priced separately, so the full bill can span three products.
Which secrets management tools publish their pricing?
8 of the 12, with the pricing model each one publishes:
Infisical: Per identity per month, published; free tier; 30-day trial on paid plans.
Phase: Per human user per month, published; free tier; 14-day trial on paid plans.
Doppler: Per user per month, published; free for three users; 14-day trial on Team.
OpenBao: Free, open source (MPL-2.0); you run it yourself.
SOPS: Free, open source (MPL-2.0); no hosted plans.
Pulumi ESC: Per secret per month by edition, published; free tier of 25 secrets.
AWS Secrets Manager: Per secret per month plus per 10,000 API calls, published; new-customer credits.
Azure Key Vault: Per 10,000 transactions plus per-key HSM charges, published by tier.
The other 4 quote per organisation.
Is there a free secrets management tool?
Infisical, Phase, Doppler, OpenBao, Akeyless, SOPS, Pulumi ESC offer a free tier or a free self-hosted edition.
Where are these secrets management tool vendors established?
In 3 countries across 3 regions: North America 9, Elsewhere 2, Middle East 1.
Infisical: United States.
Phase: Not stated by the vendor.
Doppler: United States.
OpenBao: United States.
Akeyless: Israel.
SOPS: Not stated by the vendor.
Pulumi ESC: United States.
Delinea Secret Server: United States.
AWS Secrets Manager: United States.
HashiCorp Vault: United States.
Azure Key Vault: United States.
Idira Secrets Manager: United States.
Which secrets management tools are open source?
OpenBao, SOPS.
Which secrets management tools can you host yourself?
Infisical, Phase, Doppler, Delinea Secret Server, Idira Secrets Manager. The other 7 are hosted by the vendor only.
What should you use instead of Infisical?
Phase and Doppler are the next two on this page. Phase is for small teams with many service accounts and few human users; Doppler is for Product teams that want a hosted service and a bill that tracks headcount.
Who should not buy Infisical?
Teams needing HSM or KMIP without an enterprise contract. Dynamic secrets are limited to the Advanced plan and above, so database-credential workflows need the higher price..
If your secrets management tools product belongs among these 12, tell us what it does and who it is for. Inclusion is an editorial call; what a listing is and is not is set out under software advice.