{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "pulumi-esc",
    "name": "Pulumi ESC",
    "vendor": "Pulumi Corporation",
    "vendorUrl": "https://www.pulumi.com",
    "kind": "http-api",
    "category": "secrets",
    "summary": "Pulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs.",
    "url": "https://www.anchorterminal.com/tools/pulumi-esc",
    "markdownUrl": "https://www.anchorterminal.com/tools/pulumi-esc.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pulumi-esc.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pulumi-esc.json",
    "repo": "https://github.com/pulumi/esc-sdk",
    "license": "Proprietary service under Pulumi's Terms \u0026 Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.pulumi.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@pulumi/esc-sdk"
      },
      {
        "registry": "pypi",
        "name": "pulumi-esc-sdk"
      },
      {
        "registry": "go",
        "name": "github.com/pulumi/esc-sdk/sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. Every request sends `Authorization: token \u003ctoken\u003e` to https://api.pulumi.com. A personal token comes from the console and carries all of the user's permissions. Organisation tokens (Essentials and above) and team tokens (Pro and above) are machine tokens that take a role, and custom roles with environment scopes need Pro. A workload on a registered OIDC issuer (GitHub Actions, GitLab CI, EKS, GKE and others) exchanges its ID token for a short-lived Pulumi token with `pulumi login --oidc-token` or POST /api/oauth/token. Under an agent with no credentials the CLI creates an ephemeral account by itself.",
    "pricing": "freemium",
    "pricingNotes": "Free edition with 25 secrets and 10,000 API calls a month for one user, no card. Essentials is $40 a month, Pro $400 and Enterprise $2,000, each including that many credits, with a managed secret at $0.50, $0.75 or $1.00 a month and API calls at $0.10 per 10,000. An agent can start with no contract through the free edition or an agent account (https://www.pulumi.com/pricing/, checked 2026-10-08).",
    "priceSummary": "$0.01 / 1k req",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the ESC docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 20661,
      "pypiWeekly": 53903,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.pulumi.com/docs/esc/",
    "llmsTxt": "https://www.pulumi.com/llms.txt",
    "openapi": "https://api.pulumi.com/api/openapi/pulumi-spec.json",
    "capabilities": [
      "secrets.store",
      "secrets.rotate",
      "secrets.machine-identity",
      "secrets.audit"
    ],
    "tags": [
      "hosted",
      "closed-source",
      "freemium",
      "free-tier",
      "no-card",
      "openapi",
      "llms-txt",
      "oidc",
      "cli",
      "typescript",
      "python",
      "go",
      "dotnet",
      "status-page",
      "soc2",
      "enterprise"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 71.1,
      "grade": "BB",
      "agentReady": true,
      "rank": 114,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 75,
        "maintenance": 82,
        "payments": 55,
        "reliability": 60,
        "schema": 82,
        "security": 79,
        "transparency": 65
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 60,
          "points": 12,
          "reason": "Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "`pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and `pulumi api --paginate` follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and `pulumi api` writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and `--dry-run` validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 79,
          "points": 13.83,
          "reason": "OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in `pulumi env run`. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 55,
          "points": 6.88,
          "reason": "No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 82,
          "points": 7.18,
          "reason": "Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 65,
          "points": 5.69,
          "note": "editorial 48, provenance 82",
          "reason": "The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and `pulumi api --paginate` follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and `pulumi api` writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and `--dry-run` validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15).",
          "maintenance": "Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10).",
          "payments": "No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20).",
          "reliability": "Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10).",
          "schema": "OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15).",
          "security": "OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in `pulumi env run`. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20).",
          "transparency": "The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20)."
        },
        "sources": [
          {
            "what": "ESC documentation",
            "url": "https://www.pulumi.com/docs/esc/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing, free edition and per-unit prices",
            "url": "https://www.pulumi.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI document",
            "url": "https://api.pulumi.com/api/openapi/pulumi-spec.json",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://www.pulumi.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "REST API basics, authentication and headers",
            "url": "https://www.pulumi.com/docs/reference/cloud-rest-api/api-basics/",
            "seen": "2026-10-08"
          },
          {
            "what": "pulumi api guide, pagination and error envelope",
            "url": "https://www.pulumi.com/docs/iac/cli/api/",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI exit codes",
            "url": "https://www.pulumi.com/docs/iac/cli/exit-codes/",
            "seen": "2026-10-08"
          },
          {
            "what": "agent accounts",
            "url": "https://www.pulumi.com/docs/administration/concepts/agent-accounts/",
            "seen": "2026-10-08"
          },
          {
            "what": "access tokens",
            "url": "https://www.pulumi.com/docs/administration/concepts/access-tokens/",
            "seen": "2026-10-08"
          },
          {
            "what": "OIDC issuers",
            "url": "https://www.pulumi.com/docs/administration/concepts/oidc-issuers/",
            "seen": "2026-10-08"
          },
          {
            "what": "environment RBAC scopes",
            "url": "https://www.pulumi.com/docs/administration/reference/rbac-scopes/environments/",
            "seen": "2026-10-08"
          },
          {
            "what": "audit log events",
            "url": "https://www.pulumi.com/docs/administration/reference/audit-log-events/",
            "seen": "2026-10-08"
          },
          {
            "what": "ESC audit logs",
            "url": "https://www.pulumi.com/docs/esc/administration/audit-logs/",
            "seen": "2026-10-08"
          },
          {
            "what": "approvals",
            "url": "https://www.pulumi.com/docs/esc/concepts/approvals/",
            "seen": "2026-10-08"
          },
          {
            "what": "rotators",
            "url": "https://www.pulumi.com/docs/esc/concepts/rotators/",
            "seen": "2026-10-08"
          },
          {
            "what": "migration from the standalone esc CLI",
            "url": "https://www.pulumi.com/docs/esc/guides/migrate-from-esc-cli/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server tools",
            "url": "https://www.pulumi.com/docs/ai/mcp-server/",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.pulumi.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.pulumi.com/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "security whitepaper",
            "url": "https://www.pulumi.com/security/pulumi-cloud-security-whitepaper/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms",
            "url": "https://www.pulumi.com/terms-and-conditions/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy statement",
            "url": "https://www.pulumi.com/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://www.pulumi.com/releases/changelog/",
            "seen": "2026-10-08"
          },
          {
            "what": "Pulumi CLI releases",
            "url": "https://github.com/pulumi/pulumi/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "standalone esc repository, README and changelog",
            "url": "https://github.com/pulumi/esc",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK repository, changelog and CI",
            "url": "https://github.com/pulumi/esc-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript SDK on npm",
            "url": "https://registry.npmjs.org/@pulumi/esc-sdk/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/pypi/pulumi-esc-sdk/json",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The lead named an `esc` CLI. The standalone esc CLI was retired at v0.26.0 on 9 July 2026 and ESC now ships only as `pulumi env` in the Pulumi CLI.",
          "No API rate limit with numbers was found in the docs we read or in the OpenAPI document.",
          "The pricing page lists an uptime commitment from Essentials up. We found no document giving the figure.",
          "No data processing addendum, subprocessor list or dated terms were found on www.pulumi.com.",
          "unchecked: GitHub star counts and the issue trackers of pulumi/pulumi and pulumi/esc-sdk, because the GitHub API refused us for its rate limit.",
          "unchecked: whether the Pulumi CLI sends telemetry and how to turn it off.",
          "unchecked: the self-hosted edition, which is Enterprise only and sold through sales. The grade is for the managed service."
        ]
      },
      "negative": 0,
      "verdict": "An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.",
      "bestFor": "Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.",
      "strengths": [
        "The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it",
        "Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page",
        "OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default",
        "Separate read, open and write scopes per environment, with open approvals and update approvals on Pro and Enterprise",
        "Prices published per unit, $0.50 a secret a month on Essentials and $0.10 per 10,000 API calls, with a free edition and no card"
      ],
      "weaknesses": [
        "Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise",
        "No API rate limit with numbers was found in the reviewed documentation",
        "No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date",
        "The official Pulumi MCP server lists no ESC tools, and the standalone esc CLI was retired at v0.26.0 on 9 July 2026",
        "A 42-minute major incident on 6 October 2026 affected inbound OIDC on the API and ESC, with no detail published",
        "The free edition has personal tokens only, which carry all of the user's permissions"
      ],
      "agentNotes": [
        "Use `pulumi env`, not `esc`. The standalone CLI stopped at v0.26.0 and gets no security fixes",
        "Read one value with `pulumi env open \u003corg\u003e/\u003cproject\u003e/\u003cenv\u003e \u003cproperty path\u003e` so the whole environment doesn't enter context",
        "Run tools with `pulumi env run \u003cenv\u003e -- \u003ccmd\u003e`, which filters secret values from the command's output unless -i is set",
        "Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk",
        "Send `Authorization: token \u003ctoken\u003e` and `Accept: application/vnd.pulumi+8` on REST calls, and expect 409 when an environment changed since it was read",
        "Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 71.1
        }
      ],
      "editorialScores": {
        "ergonomics": 75,
        "maintenance": 82,
        "payments": 55,
        "reliability": 60,
        "schema": 82,
        "security": 79,
        "transparency": 48
      },
      "provenanceScore": 82
    },
    "connect": {
      "install": "curl -fsSL https://get.pulumi.com | sh",
      "http": "curl -H \"Authorization: token $PULUMI_ACCESS_TOKEN\" \\\n     -H \"Accept: application/vnd.pulumi+8\" \\\n     https://api.pulumi.com/api/user"
    },
    "letme": {
      "capability": "https://letme.dev/secrets.store",
      "tool": "https://letme.dev/pulumi-esc"
    },
    "notable": [
      "Agent accounts give an AI agent a free ephemeral Pulumi Cloud account with ESC and no signup. Write access lasts 72 hours and a person has 30 days to claim it (https://www.pulumi.com/docs/administration/concepts/agent-accounts/)",
      "The standalone esc CLI was retired with v0.26.0 on 9 July 2026. Every command is now `pulumi env` in the Pulumi CLI (https://www.pulumi.com/docs/esc/guides/migrate-from-esc-cli/)",
      "`pulumi api` calls any REST endpoint with the CLI's credentials, lists the OpenAPI operations as JSON and writes errors as a one-line JSON envelope (https://www.pulumi.com/docs/iac/cli/api/)",
      "Rotated secrets keep two valid credentials at a time, so instances that haven't picked up the new one keep working (https://www.pulumi.com/docs/esc/concepts/rotators/)",
      "Audit logs record every environment open, read and decrypt with user, time and source IP, on Pro and Enterprise (https://www.pulumi.com/docs/esc/administration/audit-logs/)",
      "A major incident on 6 October 2026 affected inbound OIDC on the API and ESC for 42 minutes (https://status.pulumi.com)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Surface graded",
        "value": "Managed Pulumi Cloud at https://api.pulumi.com, reached through `pulumi env`, the REST API and the ESC SDKs"
      },
      {
        "label": "Free edition",
        "value": "1 user, 25 secrets, 10,000 API calls a month, no card. Personal tokens only"
      },
      {
        "label": "Paid editions",
        "value": "Essentials $40 a month, Pro $400, Enterprise $2,000, each including the same number of credits at $1 a credit"
      },
      {
        "label": "Unit prices",
        "value": "Managed secret $0.50 a month on Essentials, $0.75 on Pro, $1.00 on Enterprise. API calls $0.10 per 10,000. Plaintext config free"
      },
      {
        "label": "Agent accounts",
        "value": "The CLI creates an ephemeral individual account when run under an agent with no credentials. Write access for 72 hours, claim within 30 days"
      },
      {
        "label": "Credentials",
        "value": "Personal, organisation (Essentials up) and team (Pro up) tokens with expiry up to two years, and OIDC token exchange with a 25-hour default maximum"
      },
      {
        "label": "Dynamic credentials",
        "value": "Login providers for AWS, Azure, Google Cloud, GitHub, Snowflake, Vault, Doppler and Infisical"
      },
      {
        "label": "External stores",
        "value": "AWS Secrets Manager and Parameter Store, Azure Key Vault, Google Secret Manager, HashiCorp Vault, 1Password, Doppler and Infisical"
      },
      {
        "label": "Rotation",
        "value": "Rotators for AWS IAM, Azure app secrets, MySQL, Postgres, Snowflake users and passwords, run by `pulumi env rotate` or on a schedule, keeping two valid secrets"
      },
      {
        "label": "Audit",
        "value": "environment-open, environment-read-open and environment-decrypted events with user, time and source IP. Pro and Enterprise"
      },
      {
        "label": "Approvals",
        "value": "Update approvals and open approvals by ruleset. Pro and Enterprise"
      },
      {
        "label": "SDKs",
        "value": "TypeScript @pulumi/esc-sdk, Python pulumi-esc-sdk, Go github.com/pulumi/esc-sdk/sdk and .NET Pulumi.Esc.Sdk, all 0.14.0 (15 June 2026), Apache-2.0"
      },
      {
        "label": "MCP server",
        "value": "The Pulumi MCP server at https://mcp.ai.pulumi.com/mcp lists no ESC tools in its docs"
      },
      {
        "label": "Self-hosting",
        "value": "Enterprise edition only, through sales"
      },
      {
        "label": "Status",
        "value": "status.pulumi.com on Atlassian Statuspage, with an ESC component"
      }
    ],
    "unitPrices": [
      {
        "item": "ESC API calls",
        "unit": "1k-requests",
        "usd": 0.01,
        "note": "$0.10 per 10,000. First 10,000 a month free on the free edition"
      },
      {
        "item": "Essentials edition",
        "unit": "month",
        "usd": 40,
        "note": "Includes 40 credits. A managed secret is $0.50 a month"
      },
      {
        "item": "Pro edition",
        "unit": "month",
        "usd": 400,
        "note": "Includes 400 credits. A managed secret is $0.75 a month"
      },
      {
        "item": "Enterprise edition",
        "unit": "month",
        "usd": 2000,
        "note": "Includes 2,000 credits. A managed secret is $1.00 a month"
      }
    ],
    "provenance": {
      "legalEntity": "Pulumi Corporation",
      "domain": "pulumi.com",
      "domainRegistered": "2017-02-13",
      "endpointOnVendorDomain": true,
      "terms": "https://www.pulumi.com/terms-and-conditions/",
      "privacy": "https://www.pulumi.com/privacy/",
      "statusPage": "https://status.pulumi.com",
      "changelog": "https://www.pulumi.com/releases/changelog/",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Terms \u0026 Conditions govern use of the Pulumi Services and name Pulumi Corporation, 601 Union St., Suite 1415, Seattle, WA 98101, with Washington law and King County courts. We found no date on the page.",
        "The privacy statement covers customers who register to use the services and gives privacy@pulumi.com as contact. We found no date on the page.",
        "www.pulumi.com/.well-known/security.txt and www.pulumi.com/security.txt both return 404. The security page gives security@pulumi.com and a PGP key.",
        "status.pulumi.com is Atlassian Statuspage with an ESC component. Its incident feed goes back to October 2023.",
        "No data processing addendum or subprocessor list was found on www.pulumi.com. The addresses we tried returned 404 and the sitemap lists neither.",
        "RDAP for pulumi.com gives a registration date of 2017-02-13."
      ],
      "score": 82,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Pulumi Corporation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "pulumi.com, registered 2017-02-13 (9 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.pulumi.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.pulumi.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.pulumi.com/terms-and-conditions/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 4245,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "15.6 The Terms, and your relationship with Pulumi under the Terms, shall be governed by the laws of the State of Washington without regard to its conflict of laws provisions.",
              "says": "The law of the State of Washington"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…YOU EXPRESSLY UNDERSTAND AND AGREE THAT PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE.",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "4.3 If any charge owed by you is 30 days or more overdue, Pulumi may, without limiting its other rights and remedies, suspend your access to Pulumi Services until such amounts are paid in full, provided we have given you 10 or more days' prior notice that your account is overdue."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "If we change the Terms in any substantive way, we will give you at least seven (7) days’ notice before the changes take effect, during which period of time you may reject the changes by terminating your account.",
              "says": "Gives seven days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "1.3 You may not use the Pulumi Services if you are a person barred from receiving the Pulumi Services under the laws of the United States or other countries, including the country in which you are resident or from which you use the Pulumi Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "You acknowledge and agree that the form and nature of the Pulumi Services which Pulumi provides may change from time to time without prior notice to you, subject to the terms in Section 4.3.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "9.4 You agree that Pulumi, in its sole discretion and for any or no reason, may terminate your account or any part thereof."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Pulumi may use the customer's trade names, trademarks and logos in marketing materials and customer lists at its sole discretion.",
              "quote": "8.4 You agree that Pulumi, in its sole discretion, may use your trade names, trademarks, service marks, logos, domain names and other distinctive brand features in presentations, marketing materials, customer lists, financial reports and Web site listings"
            },
            {
              "date": "2026-10-08",
              "text": "The agreement renews automatically for periods equal to the initial term unless either party asks to end it at least 30 days before the term ends.",
              "quote": "shall be automatically renewed for additional periods of the same duration as the Initial Service Term (collectively, the “Term”), unless either party requests termination at least thirty (30) days prior to the end of the then-current term."
            },
            {
              "date": "2026-10-08",
              "text": "The liability clause says Pulumi is not liable to the customer for direct damages as well as indirect, incidental, special, consequential or exemplary ones.",
              "quote": "PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.pulumi.com/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 5514,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Please read this Privacy Statement carefully to learn how we collect, use, share and otherwise process information relating to individuals (\"Personal Data\"), and your rights and choices regarding our processing of your Personal Data."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We may retain your Personal Data for a period of time consistent with the original purpose of collection (see \"Purposes for which we process Personal Data and on what legal basis\" section above)."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may also collect information about you from other sources, including third parties from whom we have purchased Personal Data, and combine this information with Personal Data provided by you."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "…through which our customers may create their own websites and applications running on our platforms, sell or offer their own products and services, send electronic communications to other individuals, and collect and analyze Personal Data from individuals."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "…is necessary for our legitimate interests to advertise our websites or, where necessary, to the extent you have provided your prior separate consent (please also view \"Your rights relating to your Personal Data\" below to learn how you can control how your Personal Data is processed by Pulumi for marketing purposes);"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions or complaints regarding Pulumi's Privacy Statement or associated practices, please contact us at privacy@pulumi.com.",
              "says": "privacy@pulumi.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In this event, we will ensure that such recipient offers an adequate level of protection, for instance by entering into standard contractual clauses for the transfer of data as approved by the European Commission (Art.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "With third–party social networks, advertising networks and websites, which usually act as separate controllers, so that Pulumi can market and advertise on third party platforms and websites;"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The statement says it does not apply to the cloud products and services through which customers create and run their own websites and applications.",
              "quote": "This Privacy Statement does not apply to the extent we offer our customers various cloud products and services through which our customers may create their own websites and applications running on our platforms"
            },
            {
              "date": "2026-10-08",
              "text": "Pulumi collects business contact details and web behaviour data from third party data providers for targeted advertising and profiling.",
              "quote": "‘intent data’ which is web user behavior data, IP addresses, social handles, LinkedIn URL and custom profiles from third party data providers for the purposes of targeted advertising, delivering relevant email content, event promotion and profiling;"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/pulumi-esc.json",
    "live": {
      "slug": "pulumi-esc",
      "probe": {
        "target": "https://api.pulumi.com",
        "method": "get",
        "lastAt": "2026-10-08T19:08:56.424476066Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 155,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 159,
        "p95ms24h": 311,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 19
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.pulumi.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:06:55.619874847Z"
      },
      "pages": [
        {
          "url": "https://www.pulumi.com/releases/changelog/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:29:52.955269848Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ddd6467eba9b"
        },
        {
          "url": "https://www.pulumi.com/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:29:48.804855492Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ba84dc7bc768"
        },
        {
          "url": "https://www.pulumi.com/privacy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:29:51.056197289Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "96eac852b529"
        },
        {
          "url": "https://www.pulumi.com/terms-and-conditions/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:29:55.102680068Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "660bfdce2184"
        }
      ],
      "updatedAt": "2026-10-08T19:08:56.424476066Z"
    }
  }
}
