Best Secrets Management Tools in 2026

This guide covers software that stores API keys, database passwords and tokens, then hands them to applications and pipelines at run time instead of leaving them in code.

We rank twelve tools on first-ninety-day effort, the bill once rotation and single sign-on are needed, exit, independence from partners, and fit.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. How that works.

In short

What secrets management tools software does

Secrets management tools store credentials such as API keys and certificates encrypted, release them to authenticated applications on demand, record every access, and rotate or expire them on a schedule.

01

The top three

12 tools reviewed
02

How we ranked these

5 criteria, in order

In this order: setup effort, what it really costs, how your data comes back out, whether you can leave, and who each secrets management tool is built for. Why those five, and why there is no score out of ten, is on the how we work page.

12tools reviewed
8publish a price
7have a free tier
3countries represented
03

Compared at a glance

12 tools
#ToolCountryPricingFree tier Right forNot for
#1InfisicalUnited StatesPer identity per month, published; free tier; 30-day trial on paid plansYesEngineering teams that want published per-identity prices and the option to run it themselvesTeams needing HSM or KMIP without an enterprise contract
#2PhaseNot stated by the vendorPer human user per month, published; free tier; 14-day trial on paid plansYesSmall teams with many service accounts and few human usersBuyers who need a stated legal entity and address
#3DopplerUnited StatesPer user per month, published; free for three users; 14-day trial on TeamYesProduct teams that want a hosted service and a bill that tracks headcountTeams that must run the software in their own network
#4OpenBaoUnited StatesFree, open source (MPL-2.0); you run it yourselfYesPlatform teams with Vault experience who want a licence no single company controlsTeams that want a vendor to carry the pager
#5AkeylessIsraelUsage-based annual contracts, quoted per organisation; no prices shownYesCompanies wanting a vendor-run service with gateways inside their own networkBuyers who need published prices before talking to sales
#6SOPSNot stated by the vendorFree, open source (MPL-2.0); no hosted plansYesTeams that keep infrastructure config in Git and want it encryptedOrganisations needing runtime access control and audit logs
#7Pulumi ESCUnited StatesPer secret per month by edition, published; free tier of 25 secretsYesTeams already on Pulumi that need to join secrets from several storesTeams wanting a standalone vault with no Pulumi account
#8Delinea Secret ServerUnited StatesQuoted per organisation; 30-day trial—IT security teams that control administrator, service and root account credentialsDevelopers wanting self-service secrets for each application environment
#9AWS Secrets ManagerUnited StatesPer secret per month plus per 10,000 API calls, published; new-customer credits—Teams whose workloads already run on AWS and need minimal setupMulti-cloud teams wanting one secret store across providers
#10HashiCorp VaultUnited StatesQuoted for Enterprise; source available Community edition; hosted trial credit—Large platform teams that need dynamic secrets and PKI with vendor supportTeams wanting a licence they can host for others
#11Azure Key VaultUnited StatesPer 10,000 transactions plus per-key HSM charges, published by tier—Teams running on Azure that already use Entra ID for sign-inTeams that may move workloads to another cloud provider
#12Idira Secrets ManagerUnited StatesQuoted per organisation; demo on request—Large organisations already buying identity security from the same vendorSmall teams wanting published prices and a free start

Country is where the vendor is headquartered or contracts from, which is a different question from where your data is hosted. Where the two tell different stories, the entry says so.

04

The 12 tools, reviewed

Ranked

1. Infisical · 2. Phase · 3. Doppler · 4. OpenBao · 5. Akeyless · 6. SOPS · 7. Pulumi ESC · 8. Delinea Secret Server · 9. AWS Secrets Manager · 10. HashiCorp Vault · 11. Azure Key Vault · 12. Idira Secrets Manager

#1 Infisical

Secrets manager with per-identity pricing and a perpetual free plan

Ranked #1 of 12 in Best Secrets Management Tools in 2026.

Free tierSelf-hostablePublished pricingNorth America

Three things are priced apart: secrets management per identity, privileged access per user, and certificates under their own plans. The free secrets plan stops at five identities and ten secret syncs, which a small team with several pipelines can reach quickly.

Pro adds SAML, rotation for public databases and 30 to 90 days of audit logs; KMIP, KMS and HSM support sit on Enterprise. Self-hosting is supported, but the vendor points licensed deployments to a consultation.

What stands out
  • Per-identity billing
  • MIT-licensed core
  • Cloud or self-hosted
Where it costs you
  • Dynamic secrets are limited to the Advanced plan and above, so database-credential workflows need the higher price.
  • Enterprise code sits under a separate licence, so the self-hosted route is not fully MIT.
Right for

Engineering teams that want published per-identity prices and the option to run it themselves

Wrong for

Teams needing HSM or KMIP without an enterprise contract

United StatesPer identity per month, published; free tier; 30-day trial on paid plans

#2 Phase

Per-user secrets manager where service accounts are not billed

Ranked #2 of 12 in Best Secrets Management Tools in 2026.

Free tierSelf-hostablePublished pricingElsewhere

The pricing model favours automation heavy teams: service accounts are unlimited and free, while each person on Pro costs a monthly fee. Cloud hosting is on AWS in Frankfurt, according to the pricing page.

Self-hosting is documented with minimum requirements of two CPU cores and 2 GB of RAM, and you take over backups, TLS and updates. The free plan has community support only, and Enterprise adds SLAs and a Slack channel.

What stands out
  • Humans billed only
  • MIT-licensed core
  • Cloud or self-hosted
Where it costs you
  • Dynamic secrets, OIDC single sign-on and SCIM sit on the Enterprise plan.
  • Neither the terms nor the privacy policy gives a company address or country.
Right for

Small teams with many service accounts and few human users

Wrong for

Buyers who need a stated legal entity and address

Not stated by the vendorPer human user per month, published; free tier; 14-day trial on paid plans

#3 Doppler

Hosted secrets manager priced per user with a small free plan

Ranked #3 of 12 in Best Secrets Management Tools in 2026.

Free tierSelf-hostablePublished pricingNorth America

Doppler's meter is people: three users free, then a per-user fee on Developer, and a higher per-user fee on Team with a 14-day trial. Team lifts limits to 250 projects and 100 configs per environment, and adds SAML SSO and automatic rotation.

The pricing page says AI agents and non-human identities are not charged. Enterprise pricing is custom and brings dynamic secrets, key management and the on-prem option.

What stands out
  • Per-user billing
  • Free for three users
  • On-prem on Enterprise
Where it costs you
  • Dynamic secrets and on-prem deployment are limited to Enterprise.
  • Developer plan allows 10 projects and 4 environments, with three days of activity logs.
Right for

Product teams that want a hosted service and a bill that tracks headcount

Wrong for

Teams that must run the software in their own network

United StatesPer user per month, published; free for three users; 14-day trial on Team

#4 OpenBao

Community fork of Vault under the Linux Foundation, licensed MPL-2.0

Ranked #4 of 12 in Best Secrets Management Tools in 2026.

Free tierOpen sourcePublished pricingNorth America

The licence and governance are the point. The repository is MPL-2.0 and the project is hosted by the Linux Foundation's OpenSSF as a Sandbox project, a status that signals an early stage.

Features match the Vault design: encrypted storage, dynamic secrets for systems such as AWS and databases, lease management and revocation of single secrets or whole trees. Sponsors listed include GitLab, SAP and Proton. No pricing page exists because the project sells nothing.

What stands out
  • Open source fork of Vault
  • MPL-2.0 licence
  • OpenSSF Sandbox project
Where it costs you
  • You run the cluster yourself, so the hours go into operations and not into licences.
  • It carries Sandbox status, and it follows Vault's design, so Vault knowledge transfers but a Vault vendor contract does not.
Right for

Platform teams with Vault experience who want a licence no single company controls

Wrong for

Teams that want a vendor to carry the pager

United StatesFree, open source (MPL-2.0); you run it yourself

#5 Akeyless

SaaS secrets platform with a starter tier and quoted enterprise plans

Ranked #5 of 12 in Best Secrets Management Tools in 2026.

Free tierPricing on requestMiddle East

The pricing page counts different things per module: clients and secrets for secrets management, connectors for the multi-vault product, managed certificates, transactions for encryption and KMS, and users for the password manager.

That makes a quote hard to compare with per-user competitors. The page offers pure SaaS or hybrid SaaS where gateways run on your premises, and the vendor describes its Distributed Fragments Cryptography as zero knowledge.

What stands out
  • SaaS with gateways
  • Usage-based contracts
  • Zero-knowledge option
Where it costs you
  • Enterprise features such as HSM integration, log forwarding and SAML sit behind a sales conversation.
  • The starter tier keeps audit logs for only three days.
Right for

Companies wanting a vendor-run service with gateways inside their own network

Wrong for

Buyers who need published prices before talking to sales

IsraelUsage-based annual contracts, quoted per organisation; no prices shown

#6 SOPS

Encrypts values inside YAML and JSON files, with no server

Ranked #6 of 12 in Best Secrets Management Tools in 2026.

Free tierOpen sourcePublished pricingElsewhere

SOPS fits configuration that already lives in a repository. It was started at Mozilla in 2015 and moved to the CNCF as a Sandbox project in 2023.

Offline use works with age or PGP, and online use works with the key services of AWS, Google Cloud, Azure and HuaweiCloud, plus HashiCorp Vault and OpenBao. It does not replace a server that issues short-lived credentials, but it removes plain text from Git.

What stands out
  • Encrypted config files
  • MPL-2.0 licence
  • CNCF Sandbox project
Where it costs you
  • The tool encrypts files; the project pages describe no server, access policy or read audit trail.
  • Rotation and revocation rely on re-encrypting files and on the key service you pick.
Right for

Teams that keep infrastructure config in Git and want it encrypted

Wrong for

Organisations needing runtime access control and audit logs

Not stated by the vendorFree, open source (MPL-2.0); no hosted plans

#7 Pulumi ESC

Environments and secrets layer that pulls from other secret stores

Ranked #7 of 12 in Best Secrets Management Tools in 2026.

Free tierPublished pricingNorth America

ESC is a layer over secret stores, not a vault with its own offline mode. The docs state it requires the Pulumi Cloud backend. Environments are opened with a command and return values with secrets decrypted, and providers import from the stores named above.

Billing is per secret per month by edition, plus 10 cents per 10,000 API calls after the first 10,000, on top of the Pulumi Cloud edition price.

What stands out
  • Per-secret billing
  • Needs Pulumi Cloud
  • Pulls from other stores
Where it costs you
  • ESC requires the Pulumi Cloud backend, so the vendor is part of every setup.
  • The standalone esc CLI repository is archived, with the commands moved into the main Pulumi CLI.
Right for

Teams already on Pulumi that need to join secrets from several stores

Wrong for

Teams wanting a standalone vault with no Pulumi account

United StatesPer secret per month by edition, published; free tier of 25 secrets

#8 Delinea Secret Server

Privileged credential vault for admin, service and root accounts

Ranked #8 of 12 in Best Secrets Management Tools in 2026.

Self-hostablePricing on requestNorth America

The product page lists the vault, account discovery, password rotation, session monitoring and approval workflows, in on-premises and cloud forms. A 30-day trial, interactive demos and quote requests are offered, but no price.

Because it is the base of a wider platform, adding modules to it changes the bill. Delinea Inc. gives a San Francisco mailing address and a London office for Delinea Europe Ltd.

What stands out
  • Privileged access vault
  • Cloud or on-premises
  • Quoted pricing
Where it costs you
  • The page lists no prices, so budgeting needs a sales quote.
  • It is a privileged access product, so developer workflows such as environment variables get less attention on its page.
Right for

IT security teams that control administrator, service and root account credentials

Wrong for

Developers wanting self-service secrets for each application environment

United StatesQuoted per organisation; 30-day trial

#9 AWS Secrets Manager

Pay-per-secret store inside AWS, billed per secret and per call

Ranked #9 of 12 in Best Secrets Management Tools in 2026.

Published pricingNorth America

The price list is simple: a per-secret monthly fee and a per-call fee, with versions created by rotation not charged.

AWS's own examples show the range, from a bill of roughly six dollars for 15 secrets to about 2,850 dollars a month for five million ephemeral secrets. The documentation tells you to use other AWS services for IAM credentials, encryption keys, SSH keys and certificates.

What stands out
  • Per-secret billing
  • AWS only
  • Rotation via Lambda
Where it costs you
  • Costs scale with the number of secrets, so many small ephemeral secrets become expensive.
  • Rotation functions are billed through Lambda, and customer-owned KMS keys are billed separately.
Right for

Teams whose workloads already run on AWS and need minimal setup

Wrong for

Multi-cloud teams wanting one secret store across providers

United StatesPer secret per month plus per 10,000 API calls, published; new-customer credits

#10 HashiCorp Vault

Long-established secrets server, now owned by IBM, source available

Ranked #10 of 12 in Best Secrets Management Tools in 2026.

Pricing on requestNorth America

Vault supports static and dynamic secrets, certificates, encryption keys and an audit log of activity, with tokens issued after authentication through methods such as LDAP, AWS or Azure.

Storage can be the integrated cluster, recommended in the docs, or an external system. HCP Vault Dedicated is described as a hosted version of Vault Enterprise operated by HashiCorp, and new HCP users receive a starter credit.

What stands out
  • Owned by IBM
  • Business Source Licence
  • Self-managed or HCP
Where it costs you
  • The licence is source available and bars competing hosted offerings, so it is not open source.
  • The pricing page lists no Vault prices, and the HCP offering is sold through sales.
Right for

Large platform teams that need dynamic secrets and PKI with vendor support

Wrong for

Teams wanting a licence they can host for others

United StatesQuoted for Enterprise; source available Community edition; hosted trial credit

#11 Azure Key Vault

Secrets, keys and certificates store tied to Microsoft Entra ID

Ranked #11 of 12 in Best Secrets Management Tools in 2026.

Published pricingNorth America

Key Vault does not limit the number of secrets, keys or certificates in a vault, but transaction limits apply: 4,000 for most operations and 300 collectively for secret creation and imports in 10 seconds.

Premium adds HSM keys validated to FIPS 140-3 Level 3. Billing is per 10,000 transactions, with extra charges for certificate renewals, HSM keys and Managed HSM pools. Access is managed with Azure RBAC.

What stands out
  • Standard and Premium tiers
  • Entra ID access
  • Same-geography restore
Where it costs you
  • Backup blobs cannot be decrypted outside Azure and restore only in the same subscription and geography.
  • Each vault is throttled, for example 300 secret creations per 10 seconds.
Right for

Teams running on Azure that already use Entra ID for sign-in

Wrong for

Teams that may move workloads to another cloud provider

United StatesPer 10,000 transactions plus per-key HSM charges, published by tier

#12 Idira Secrets Manager

Former CyberArk secrets product, now sold by Palo Alto Networks

Ranked #12 of 12 in Best Secrets Management Tools in 2026.

Self-hostablePricing on requestNorth America

The vendor page describes storing API keys, tokens, passwords, certificates and database credentials, rotating and expiring them by policy, and a universal cryptographic identity model.

It can run as managed SaaS or self-hosted in your data centre, for air-gapped or data residency needs. Palo Alto Networks says CyberArk's solutions stay available as a standalone platform while integration proceeds, though the press release does not mention this product by name.

What stands out
  • Owned by Palo Alto Networks
  • SaaS or self-hosted
  • Quoted pricing
Where it costs you
  • The page shows no pricing, trial or plan limits.
  • Ownership moved to Palo Alto Networks in 2026 and the product brand changed to Idira.
Right for

Large organisations already buying identity security from the same vendor

Wrong for

Small teams wanting published prices and a free start

United StatesQuoted per organisation; demo on request
06

How to choose secrets management tools software

Secrets management tools store credentials such as API keys and certificates encrypted, release them to authenticated applications on demand, record every access, and rotate or expire them on a schedule. The differences that matter are rarely in the feature list, so this is the order we would work through them.

  1. 01

    Decide whether you need a published price

    8 of the 12 tools here publish what they cost; the other 4 quote per organisation. The ones you can compare without a sales call: Infisical, Phase, Doppler, OpenBao, SOPS, Pulumi ESC, AWS Secrets Manager, Azure Key Vault.

  2. 02

    Decide how much the jurisdiction matters

    These 12 vendors are established in 3 countries across 3 regions (North America 9, Elsewhere 2, Middle East 1). That decides whose disclosure law applies to what the vendor holds, wherever the servers are.

  3. 03

    Consider whether you want the source

    2 of these are open source: OpenBao, SOPS. Hosting one yourself trades a subscription for maintenance.

Run it yourself or rent it: Infisical, OpenBao and HashiCorp Vault

The first decision is who carries the operations. OpenBao is MPL-2.0 software that you operate yourself, and HashiCorp Vault is also run by you unless you buy HCP Vault Dedicated, the hosted version operated by HashiCorp. Infisical and Phase can be self-hosted, but their enterprise features sit in a separate ee directory under a vendor licence, so a self-hosted install is rarely the whole product.

Doppler offers on-prem deployment only on Enterprise. In every self-run case you take over backups, upgrades and availability, and a secrets store that is down stops deployments, because pipelines cannot read the credentials they need. Count those hours in the first ninety days, not the licence line, and decide who is on call for the store before the first application depends on it.

  • Ask who restores the store after a failed upgrade and how long it takes.
  • Check which features sit in the licensed ee directory.
  • Price the hosted version of the same product before choosing to run it.

Three different meters: per identity, per user and per secret

Prices cannot be compared until the meter is known. Infisical bills per identity, Doppler per user, and Phase only for human users, with service accounts free. Pulumi ESC and AWS Secrets Manager bill per secret per month: AWS lists a per-secret monthly fee plus a fee per 10,000 API calls, and ESC lists 0.50, 0.75 or 1.00 per secret depending on edition.

A company with ten engineers and three hundred microservices pays very differently under each, and the ranking of cheap and expensive can flip when the headcount or the service count doubles. Count people, pipelines, applications and secrets separately, then run the same estimate through every meter before you compare headline prices.

  • Count humans, machine identities and secrets as three separate numbers.
  • Check whether API calls are charged on top of the stored secrets.
  • Ask whether AI agents and service accounts count as users.

Rotation and dynamic secrets are where the plans split

Most free plans store secrets; the features that remove standing passwords sit higher up. Infisical starts dynamic secrets at Advanced, and Doppler keeps them on Enterprise while rotation arrives on Team. Phase adds rotation on Pro and dynamic secrets on Enterprise. Akeyless gives the starter tier five dynamic and five rotated secrets.

AWS Secrets Manager rotates through Lambda functions that are billed at Lambda rates. Rotation was probably the reason you wanted a manager, so price the plan that includes it, not the plan on the front of the page. Ask what the free or entry plan keeps for audit logs, too: Doppler's Developer plan keeps three days of activity logs, and Akeyless's starter tier also keeps three, which is short for an incident review.

  • Write down which credentials must rotate automatically.
  • Find the plan that includes dynamic secrets for your database.
  • Check whether rotation runs inside the product or in a function you pay for.

Licences and lock-in: BSL, MPL-2.0 and cloud-bound stores

Licences differ more than the feature lists suggest. HashiCorp Vault uses the Business Source Licence 1.1 and is owned by IBM, which bars offering it as a competing hosted product. OpenBao forked from Vault and is MPL-2.0 under the OpenSSF, and SOPS is MPL-2.0 under the CNCF.

Azure Key Vault backups restore only within the same Azure subscription and geography, and Pulumi ESC requires the Pulumi Cloud backend. Check what leaves with you: a plain export of values is the only exit that works everywhere, and the licence decides who is allowed to host it for others. Test the export during the trial, with a real secret, before any application is wired to the store.

  • Export a test secret and confirm that it reads back outside the product.
  • Read the licence for hosting or embedding limits.
  • Check where backups can be restored.

What goes wrong most often when buying secrets management tools software

  • Buying a per-user plan for a platform where machine identities and AI agents outnumber people, or the reverse.
  • Treating a free plan as production-ready when Infisical's stops at five identities and Doppler's keeps three days of activity logs.
  • Choosing a cloud-bound store such as AWS Secrets Manager or Azure Key Vault for a workload that may move clouds.
  • Skipping the exit test and discovering that backups restore only in one subscription or geography.
07

Frequently asked questions

8 answers
What is the best secrets management tools in 2026?

Infisical leads our ranking of 12. Infisical Inc. is a single-product company whose core code is MIT licensed, with paid enterprise code kept in a separate directory. The free plan allows five identities and three environments, and paid plans bill per identity.

Dynamic secrets start on the Advanced plan, and audit logs and SAML need Pro or above. Privileged access and certificate management are priced separately, so the full bill can span three products.

Which secrets management tools publish their pricing?

8 of the 12, with the pricing model each one publishes:

  • Infisical: Per identity per month, published; free tier; 30-day trial on paid plans.
  • Phase: Per human user per month, published; free tier; 14-day trial on paid plans.
  • Doppler: Per user per month, published; free for three users; 14-day trial on Team.
  • OpenBao: Free, open source (MPL-2.0); you run it yourself.
  • SOPS: Free, open source (MPL-2.0); no hosted plans.
  • Pulumi ESC: Per secret per month by edition, published; free tier of 25 secrets.
  • AWS Secrets Manager: Per secret per month plus per 10,000 API calls, published; new-customer credits.
  • Azure Key Vault: Per 10,000 transactions plus per-key HSM charges, published by tier.

The other 4 quote per organisation.

Is there a free secrets management tool?

Infisical, Phase, Doppler, OpenBao, Akeyless, SOPS, Pulumi ESC offer a free tier or a free self-hosted edition.

Where are these secrets management tool vendors established?

In 3 countries across 3 regions: North America 9, Elsewhere 2, Middle East 1.

  • Infisical: United States.
  • Phase: Not stated by the vendor.
  • Doppler: United States.
  • OpenBao: United States.
  • Akeyless: Israel.
  • SOPS: Not stated by the vendor.
  • Pulumi ESC: United States.
  • Delinea Secret Server: United States.
  • AWS Secrets Manager: United States.
  • HashiCorp Vault: United States.
  • Azure Key Vault: United States.
  • Idira Secrets Manager: United States.
Which secrets management tools are open source?

OpenBao, SOPS.

Which secrets management tools can you host yourself?

Infisical, Phase, Doppler, Delinea Secret Server, Idira Secrets Manager. The other 7 are hosted by the vendor only.

What should you use instead of Infisical?

Phase and Doppler are the next two on this page. Phase is for small teams with many service accounts and few human users; Doppler is for Product teams that want a hosted service and a bill that tracks headcount.

Who should not buy Infisical?

Teams needing HSM or KMIP without an enterprise contract. Dynamic secrets are limited to the Advanced plan and above, so database-credential workflows need the higher price..

—

Tools reviewed

12 products
—

More Data & IT software advice

16 guides

For software vendors

Not on this list?

If your secrets management tools product belongs among these 12, tell us what it does and who it is for. Inclusion is an editorial call; what a listing is and is not is set out under software advice.

Suggest a product →