Best of · Agent runtime

Best secrets managers and credential vaults for AI agents

The 10 highest-scoring of 13 secrets managers and credential vaults on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.

  • 13 ranked
  • 7 agent-ready
  • 9 hosted endpoints
  • Updated 8 October 2026

Top three

Picks by need

Worked out from the scores, prices and facts, so they change when the research does.

Highest score overall

Infisical A

A, 83.7/100 on the benchmark.

Also AWS Secrets Manager, BB, 77.7/100.

Schema & documentation

AWS Secrets Manager BB

96/100 on schema & documentation, against 87 for the overall leader.

Security & auth

1Password service accounts, SDKs and Environments MCP B

94/100 on security & auth, against 91 for the overall leader.

Maintenance & community

Keeper Secrets Manager B

92/100 on maintenance & community, against 90 for the overall leader.

Transparency & trust

1Password service accounts, SDKs and Environments MCP B

87/100 on transparency & trust, against 83 for the overall leader.

Lowest paid price per 1,000 calls

Google Cloud Secret Manager BB

$0.003 per 1,000 calls, the lowest of the 3 listings here with a paid price in this unit (free allowances aside).

Also Azure Key Vault, $0.003 per 1,000 calls.

The review panel's favourite

AWS Secrets Manager BB

3.9/5 from 8 panel reviews.

The shortlist

#ToolGradeBest forPriceWhere
1 Infisical
Infisical
A 83.7 Teams that want an open-source secrets manager they can self-host, and for coding agents run under Agent Vault so they call APIs without ever holding a token. Freemium hosted and local
2 AWS Secrets Manager
Amazon Web Services
BB 77.7 Agents running on AWS compute that should read credentials through a role with no key at all, and for RDS-family databases that need managed rotation. $0.40 / mo hosted
3 Google Cloud Secret Manager
Google Cloud
BB 76.5 Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants. $0.06 / mo hosted
4 Azure Key Vault
Microsoft Corporation
BB 74.7 Agents and runtimes already on Azure, where a managed identity reads a secret with no stored credential. $0.003 / 1k calls hosted
5 Akeyless (SecretlessAI and MCP server)
Akeyless
BB 73.6 Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract. Freemium hosted and local
6 Doppler
Doppler
BB 71.4 Teams that want a hosted store and a one-line doppler run wrapper for agents, with config-scoped read-only tokens. $21 / seat-mo hosted and local
7 Pulumi ESC
Pulumi Corporation
BB 71.1 Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup. $0.01 / 1k req hosted
8 1Password service accounts, SDKs and Environments MCP
1Password
B 69.7 Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value. $8.99 / seat-mo local
9 Keeper Secrets Manager
Keeper Security, Inc.
B 69.4 Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server. Paid local
10 Phase
Phi Security Inc.
B 68 Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI. $10 / seat-mo hosted

3 more are ranked in the full table.

How to choose

  1. Machine identity and scopingCheck how the runtime authenticates and whether each identity can read only its agent's keys, since a shared login exposes every key the agent could reach.
  2. Rotation during a live runCheck whether a rotated key reaches a running agent without a restart and how long the old value works, since a long overlap widens the risk from a leak.
  3. Audit events and read latencyCheck what each read logs and how much delay a read adds, since an agent that reads a key on every call pays that cost repeatedly.
  4. Self-hosting and data residencyCheck whether you can self-host or pick a region and what the vendor can read, since a key store is only as trusted as its host.

How the benchmark tests this category. An agent runtime reads a key at call time with a scoped machine identity, the key is rotated mid-run and access is then revoked. We check the scoping, how rotation lands, what the audit log records and how long each read takes.

Each one in detail

#1

Infisical

A 83.7/100

Open-source secrets manager with machine identities (Universal Auth, OIDC, AWS, GCP, Azure, Kubernetes, SPIFFE), dynamic secrets, rotation and audit logs, hosted in the US or EU or self-hosted.

Verdict Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.

Choose it for Teams that want an open-source secrets manager they can self-host, and for coding agents run under Agent Vault so they call APIs without ever holding a token.

Strengths

  • Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them
  • Thirteen machine identity auth methods with short-lived, revocable access tokens
  • MIT core that self-hosts with no API rate limits, plus US and EU cloud regions

Weaknesses

  • Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month
  • Cloud rate limits are per client IP, so agents behind one NAT share 600 requests a minute
  • The MCP server returns secret values unless INFISICAL_MASK_SECRET_VALUES is set, and it's still version 0.0.x

Price FreemiumAuth OAuth or keyx402 nohosted and local

Full assessment

#2

AWS Secrets Manager

BB 77.7/100

Managed secrets store priced per secret and per API call, with IAM for access, KMS for encryption, CloudTrail for audit, cross-region replication and rotation either managed (RDS, Aurora, DocumentDB, Redshift) or by a Lambda function you own.

Verdict IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.

Choose it for Agents running on AWS compute that should read credentials through a role with no key at all, and for RDS-family databases that need managed rotation.

Strengths

  • IAM roles on EC2, ECS, Lambda and EKS mean no long-lived credential in the agent
  • Published quotas, 10,000 reads a second per region, and a 99.99% SLA
  • Idempotent writes on ClientRequestToken and immutable versions

Weaknesses

  • Every API call is billed, so per-request reads add up and the docs push you to cache
  • Rotation outside the RDS family means writing and running a Lambda function
  • Off-AWS agents need AWS credentials of their own, often a static access key

Price $0.40 / moAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Infisical

#3

Google Cloud Secret Manager

BB 76.5/100

Google Cloud's managed service for storing and accessing application secrets.

Verdict Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.

Choose it for Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.

Strengths

  • Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused
  • $0.06 a version a month and $0.03 per 10,000 accesses, with 6 versions and 10,000 accesses a month free
  • IAM conditions and per-secret roles, with version_destroy_ttl to delay destruction

Weaknesses

  • Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle
  • Secret reads are Data Access audit logs, which you have to enable
  • Global secrets accept only 2 version writes a second, and AddSecretVersion has no request ID for safe retries

Price $0.06 / moAuth OAuthx402 nohosted

Full assessment · Against #1, Infisical

#4

Azure Key Vault

BB 74.7/100

Microsoft Azure's managed store for secrets, encryption keys and TLS certificates. Applications read secrets over a REST API or the Azure SDKs and CLI, signing in with Microsoft Entra ID and authorised by Azure role assignments.

Verdict Access runs on Microsoft Entra ID tokens and Azure roles that can be scoped to one secret, with soft delete, a 99.99 per cent SLA and a public OpenAPI contract. Secret rotation needs an Event Grid trigger and a function the owner writes, audit logging is off until enabled, and an Azure subscription needs a person and a payment card.

Choose it for Agents and runtimes already on Azure, where a managed identity reads a secret with no stored credential.

Strengths

  • No API keys. Every call carries a Microsoft Entra ID bearer token, and managed identities remove stored credentials for workloads on Azure
  • Azure roles can be assigned on a vault or one secret, with Key Vault Secrets User limited to reading secret contents
  • Deleted secrets stay recoverable for 7 to 90 days, and purging needs a separate permission

Weaknesses

  • No managed rotation for secrets. Key Vault raises a near-expiry event 30 days ahead and the owner's Azure Function does the rotation
  • Audit logging is off until a diagnostic setting sends AuditEvent logs to a storage account, event hub or Azure Monitor
  • Set Secret has no idempotency key, so a retried write adds another version

Price $0.003 / 1k callsAuth OAuthx402 nohosted

Full assessment · Against #1, Infisical

#5

Akeyless (SecretlessAI and MCP server)

BB 73.6/100

SaaS secrets and machine-identity platform with a self-hosted Gateway that brokers access.

Verdict Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.

Choose it for Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.

Strengths

  • Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials
  • Runtime Authority intent rules with a kill switch, generally available since 9 September 2026
  • SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS and FIPS 140-3 validation listed in the trust centre, plus a bug bounty

Weaknesses

  • No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract
  • Errors come back as a single error string with no code, and no Retry-After or backoff guidance turned up
  • The free plan has no OIDC, SAML or LDAP auth and keeps audit logs for 3 days

Price FreemiumAuth OAuth or keyx402 nohosted and local

Full assessment · Against #1, Infisical

#6

Doppler

BB 71.4/100

Hosted secrets manager organised by project, environment and config.

Verdict Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.

Choose it for Teams that want a hosted store and a one-line doppler run wrapper for agents, with config-scoped read-only tokens.

Strengths

  • Service tokens bound to one config, read-only by default, with --max-age expiry
  • OIDC service account identities on Team, so shared runners don't hold a static token
  • OpenAPI 3.1 and an llms.txt with about 500 Markdown links

Weaknesses

  • Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts
  • The MCP server is experimental, has no tool annotations or value masking, and exposes up to 89 tools by default
  • 35 open CLI issues, most of the newest without a reply

Price $21 / seat-moAuth OAuth or keyx402 nohosted and local

Full assessment · Against #1, Infisical

#7

Pulumi ESC

BB 71.1/100

Pulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs.

Verdict An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.

Choose it for Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.

Strengths

  • The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it
  • Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page
  • OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default

Weaknesses

  • Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise
  • No API rate limit with numbers was found in the reviewed documentation
  • No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date

Price $0.01 / 1k reqAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Infisical

#8

1Password service accounts, SDKs and Environments MCP

B 69.7/100

Password manager with a developer layer for agents.

Verdict Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After.

Choose it for Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value.

Strengths

  • Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation
  • Environments MCP server with 8 tools that never returns a secret value and asks for approval per Environment
  • Official Go, JavaScript and Python SDKs, MIT, with workload identity through the Credential Broker in JavaScript 0.5.0 (public preview)

Weaknesses

  • Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After
  • SDKs are version 0 with three months of patches per release, and 5 of the 8 newest Python SDK issues have no reply
  • No SLA found, and the audit log and Events API need Business

Price $8.99 / seat-moAuth OAuth or keyx402 nolocal

Full assessment · Against #1, Infisical

#9

Keeper Secrets Manager

B 69.4/100

Keeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the ksm CLI or a local MCP server, decrypting on the client.

Verdict Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.

Choose it for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.

Strengths

  • Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone
  • Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page
  • An application sees only the shared folders and records assigned to it, read-only unless shared as editable

Weaknesses

  • Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote
  • No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with {"error":"throttled"}
  • No OpenAPI or documented raw HTTP use for /api/rest/sm/v1. The SDKs are the only supported route

Price PaidAuth API keyx402 nolocal

Full assessment · Against #1, Infisical

#10

Phase

B 68/100

Phase is an open-source secrets manager from Phi Security Inc. with end-to-end encryption, service accounts, secret rotation and audit logs. Agents reach it through a REST API, a CLI and SDKs, on Phase Cloud or self-hosted.

Verdict Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.

Choose it for Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.

Strengths

  • Service account tokens take an expiry and can be created and deleted through /v1/service-accounts/:id/tokens, and service accounts are free on every plan
  • The CLI's AI mode redacts secret and sealed values and blocks printenv, env and phase shell when it detects an agent
  • Every reveal and every REST fetch of a secret is recorded as a READ event with actor and IP address

Weaknesses

  • No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations
  • No pagination, field selection or idempotency keys were found in the API reference, and errors are a single free-text error string
  • The Free plan keeps audit logs for 24 hours. Rotation, custom roles and network access policies need Pro, and dynamic secrets need Enterprise

Price $10 / seat-moAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Infisical

Head to head

All 71 comparisons in this category

Questions

What are the highest-rated secrets managers and credential vaults for AI agents?

Infisical has the highest benchmark score of the 13 ranked secrets managers and credential vaults, 83.7 (A). AWS Secrets Manager is second with 77.7 (BB).

How many secrets managers and credential vaults are agent-ready?

7 of the 13 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.

Which secrets managers and credential vaults accept x402 payments?

None of the ranked listings here accepts x402 for its main call yet.

Which of these secrets managers and credential vaults is cheapest?

By published paid prices, Google Cloud Secret Manager, at $0.003 per 1,000 calls, the lowest of the 3 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.

How is this list ranked?

By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.

How this list is made

The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.

Full ranked table · 71 head-to-head comparisons · Best tools in every category

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.