{
  "data": {
    "category": {
      "area": "agent-runtime",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host"
      ],
      "description": "Stores for API keys and other secrets that an agent or its runtime reads at call time, instead of keeping them in prompts, config files or environment dumps. Compared on access controls, rotation, audit, SDKs and self-hosting.",
      "indexed": [
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/advisorfinder-mcp.json",
          "kind": "mcp",
          "name": "advisorfinder.com MCP server",
          "slug": "advisorfinder-mcp",
          "url": "https://www.anchorterminal.com/tools/advisorfinder-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/focusgts-aep.json",
          "kind": "mcp",
          "name": "aep",
          "slug": "focusgts-aep",
          "url": "https://www.anchorterminal.com/tools/focusgts-aep"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/atlasyield-mcp.json",
          "kind": "mcp",
          "name": "AtlasYield",
          "slug": "atlasyield-mcp",
          "url": "https://www.anchorterminal.com/tools/atlasyield-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/correctover-mcp-server.json",
          "kind": "mcp",
          "name": "correctover.com MCP server",
          "slug": "correctover-mcp-server",
          "url": "https://www.anchorterminal.com/tools/correctover-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/designvault.json",
          "kind": "mcp",
          "name": "designvault",
          "slug": "designvault",
          "url": "https://www.anchorterminal.com/tools/designvault"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/draugr.json",
          "kind": "mcp",
          "name": "Draugr",
          "slug": "draugr",
          "url": "https://www.anchorterminal.com/tools/draugr"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/fentz-envcp.json",
          "kind": "mcp",
          "name": "envcp",
          "slug": "fentz-envcp",
          "url": "https://www.anchorterminal.com/tools/fentz-envcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/flarehq-security.json",
          "kind": "mcp",
          "name": "Flare",
          "slug": "flarehq-security",
          "url": "https://www.anchorterminal.com/tools/flarehq-security"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nautaai-holster-mcp.json",
          "kind": "mcp",
          "name": "Holster MCP",
          "slug": "nautaai-holster-mcp",
          "url": "https://www.anchorterminal.com/tools/nautaai-holster-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/royashbrook-hush.json",
          "kind": "mcp",
          "name": "hush",
          "slug": "royashbrook-hush",
          "url": "https://www.anchorterminal.com/tools/royashbrook-hush"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/identark-gateway.json",
          "kind": "mcp",
          "name": "IdentArk Gateway",
          "slug": "identark-gateway",
          "url": "https://www.anchorterminal.com/tools/identark-gateway"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/jikida-mcp.json",
          "kind": "mcp",
          "name": "jikida.io MCP server",
          "slug": "jikida-mcp",
          "url": "https://www.anchorterminal.com/tools/jikida-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/marchward-mcp-server.json",
          "kind": "mcp",
          "name": "marchward.ai MCP server",
          "slug": "marchward-mcp-server",
          "url": "https://www.anchorterminal.com/tools/marchward-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opzyai-mcp.json",
          "kind": "mcp",
          "name": "Opzyai Security Check",
          "slug": "opzyai-mcp",
          "url": "https://www.anchorterminal.com/tools/opzyai-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paysafe-agent-paysafe.json",
          "kind": "mcp",
          "name": "paysafe",
          "slug": "paysafe-agent-paysafe",
          "url": "https://www.anchorterminal.com/tools/paysafe-agent-paysafe"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/philidor-defi-vaults.json",
          "kind": "mcp",
          "name": "Philidor DeFi Vault Risk Analytics",
          "slug": "philidor-defi-vaults",
          "url": "https://www.anchorterminal.com/tools/philidor-defi-vaults"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/seal-mcp.json",
          "kind": "mcp",
          "name": "SEAL",
          "slug": "seal-mcp",
          "url": "https://www.anchorterminal.com/tools/seal-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/seekrit-mcp.json",
          "kind": "mcp",
          "name": "seekrit (local crypto plane)",
          "slug": "seekrit-mcp",
          "url": "https://www.anchorterminal.com/tools/seekrit-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ship-safe-scanner.json",
          "kind": "mcp",
          "name": "ShipSafe — Independent security verification",
          "slug": "ship-safe-scanner",
          "url": "https://www.anchorterminal.com/tools/ship-safe-scanner"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/getskarn-skarn.json",
          "kind": "mcp",
          "name": "Skarn",
          "slug": "getskarn-skarn",
          "url": "https://www.anchorterminal.com/tools/getskarn-skarn"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/speedvault-mcp.json",
          "kind": "mcp",
          "name": "speedvault.io MCP server",
          "slug": "speedvault-mcp",
          "url": "https://www.anchorterminal.com/tools/speedvault-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/human-tap.json",
          "kind": "mcp",
          "name": "TAP",
          "slug": "human-tap",
          "url": "https://www.anchorterminal.com/tools/human-tap"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/taskforge.json",
          "kind": "mcp",
          "name": "taskforge",
          "slug": "taskforge",
          "url": "https://www.anchorterminal.com/tools/taskforge"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/trestlescan-trestle.json",
          "kind": "mcp",
          "name": "Trestle",
          "slug": "trestlescan-trestle",
          "url": "https://www.anchorterminal.com/tools/trestlescan-trestle"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/trustysquire-trusty-squire.json",
          "kind": "mcp",
          "name": "Trusty Squire",
          "slug": "trustysquire-trusty-squire",
          "url": "https://www.anchorterminal.com/tools/trustysquire-trusty-squire"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/unmarking.json",
          "kind": "mcp",
          "name": "unmarking",
          "slug": "unmarking",
          "url": "https://www.anchorterminal.com/tools/unmarking"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/uplink.json",
          "kind": "mcp",
          "name": "Uplink",
          "slug": "uplink",
          "url": "https://www.anchorterminal.com/tools/uplink"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/seanwinslow-vault-knowledge.json",
          "kind": "mcp",
          "name": "vault-knowledge",
          "slug": "seanwinslow-vault-knowledge",
          "url": "https://www.anchorterminal.com/tools/seanwinslow-vault-knowledge"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/metamuse-wallet.json",
          "kind": "mcp",
          "name": "wallet",
          "slug": "metamuse-wallet",
          "url": "https://www.anchorterminal.com/tools/metamuse-wallet"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/yault-aesp.json",
          "kind": "mcp",
          "name": "Yault AESP",
          "slug": "yault-aesp",
          "url": "https://www.anchorterminal.com/tools/yault-aesp"
        }
      ],
      "indexedCount": 30,
      "json": "https://www.anchorterminal.com/categories/secrets.json",
      "name": "Secrets \u0026 credential vaults",
      "slug": "secrets",
      "test": "An agent runtime reads a key at call time with a scoped machine identity, the key is rotated mid-run and access is then revoked. We check the scoping, how rotation lands, what the audit log records and how long each read takes.",
      "title": "Secrets managers and credential vaults for agents",
      "toolCount": 13,
      "tools": [
        "infisical",
        "aws-secrets-manager",
        "google-secret-manager",
        "azure-key-vault",
        "akeyless",
        "doppler",
        "pulumi-esc",
        "1password",
        "keeper-secrets-manager",
        "phase",
        "azure-mcp",
        "hashicorp-vault",
        "bitwarden-secrets-manager"
      ],
      "url": "https://www.anchorterminal.com/categories/secrets"
    },
    "faq": [
      {
        "answer": "Infisical has the highest benchmark score of the 13 ranked secrets managers and credential vaults, 83.7 (A). AWS Secrets Manager is second with 77.7 (BB).",
        "question": "What are the highest-rated secrets managers and credential vaults for AI agents?"
      },
      {
        "answer": "7 of the 13 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.",
        "question": "How many secrets managers and credential vaults are agent-ready?"
      },
      {
        "answer": "None of the ranked listings here accepts x402 for its main call yet.",
        "question": "Which secrets managers and credential vaults accept x402 payments?"
      },
      {
        "answer": "By published paid prices, Google Cloud Secret Manager, at $0.003 per 1,000 calls, the lowest of the 3 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.",
        "question": "Which of these secrets managers and credential vaults is cheapest?"
      },
      {
        "answer": "By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.",
        "question": "How is this list ranked?"
      }
    ],
    "howToChoose": [
      {
        "label": "Machine identity and scoping",
        "detail": "Check how the runtime authenticates and whether each identity can read only its agent's keys, since a shared login exposes every key the agent could reach."
      },
      {
        "label": "Rotation during a live run",
        "detail": "Check whether a rotated key reaches a running agent without a restart and how long the old value works, since a long overlap widens the risk from a leak."
      },
      {
        "label": "Audit events and read latency",
        "detail": "Check what each read logs and how much delay a read adds, since an agent that reads a key on every call pays that cost repeatedly."
      },
      {
        "label": "Self-hosting and data residency",
        "detail": "Check whether you can self-host or pick a region and what the vendor can read, since a key store is only as trusted as its host."
      }
    ],
    "picks": [
      {
        "also": {
          "name": "AWS Secrets Manager",
          "slug": "aws-secrets-manager",
          "why": "BB, 77.7/100"
        },
        "name": "Infisical",
        "need": "Highest score overall",
        "slug": "infisical",
        "why": "A, 83.7/100 on the benchmark"
      },
      {
        "name": "AWS Secrets Manager",
        "need": "Schema \u0026 documentation",
        "slug": "aws-secrets-manager",
        "why": "96/100 on schema \u0026 documentation, against 87 for the overall leader"
      },
      {
        "name": "1Password service accounts, SDKs and Environments MCP",
        "need": "Security \u0026 auth",
        "slug": "1password",
        "why": "94/100 on security \u0026 auth, against 91 for the overall leader"
      },
      {
        "name": "Keeper Secrets Manager",
        "need": "Maintenance \u0026 community",
        "slug": "keeper-secrets-manager",
        "why": "92/100 on maintenance \u0026 community, against 90 for the overall leader"
      },
      {
        "name": "1Password service accounts, SDKs and Environments MCP",
        "need": "Transparency \u0026 trust",
        "slug": "1password",
        "why": "87/100 on transparency \u0026 trust, against 83 for the overall leader"
      },
      {
        "also": {
          "name": "Azure Key Vault",
          "slug": "azure-key-vault",
          "why": "$0.003 per 1,000 calls"
        },
        "name": "Google Cloud Secret Manager",
        "need": "Lowest paid price per 1,000 calls",
        "slug": "google-secret-manager",
        "why": "$0.003 per 1,000 calls, the lowest of the 3 listings here with a paid price in this unit (free allowances aside)"
      },
      {
        "name": "AWS Secrets Manager",
        "need": "The review panel's favourite",
        "slug": "aws-secrets-manager",
        "why": "3.9/5 from 8 panel reviews"
      }
    ],
    "ranked": 13,
    "shortlist": [
      {
        "bestFor": "Teams that want an open-source secrets manager they can self-host, and for coding agents run under Agent Vault so they call APIs without ever holding a token.",
        "grade": "A",
        "name": "Infisical",
        "position": 1,
        "price": "Freemium",
        "score": 83.7,
        "slug": "infisical",
        "strengths": [
          "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them",
          "Thirteen machine identity auth methods with short-lived, revocable access tokens",
          "MIT core that self-hosts with no API rate limits, plus US and EU cloud regions"
        ],
        "url": "https://www.anchorterminal.com/tools/infisical",
        "verdict": "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.",
        "weaknesses": [
          "Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month",
          "Cloud rate limits are per client IP, so agents behind one NAT share 600 requests a minute",
          "The MCP server returns secret values unless INFISICAL_MASK_SECRET_VALUES is set, and it's still version 0.0.x"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "Agents running on AWS compute that should read credentials through a role with no key at all, and for RDS-family databases that need managed rotation.",
        "grade": "BB",
        "name": "AWS Secrets Manager",
        "position": 2,
        "price": "$0.40 / mo",
        "score": 77.7,
        "slug": "aws-secrets-manager",
        "strengths": [
          "IAM roles on EC2, ECS, Lambda and EKS mean no long-lived credential in the agent",
          "Published quotas, 10,000 reads a second per region, and a 99.99% SLA",
          "Idempotent writes on ClientRequestToken and immutable versions"
        ],
        "url": "https://www.anchorterminal.com/tools/aws-secrets-manager",
        "verdict": "IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.",
        "weaknesses": [
          "Every API call is billed, so per-request reads add up and the docs push you to cache",
          "Rotation outside the RDS family means writing and running a Lambda function",
          "Off-AWS agents need AWS credentials of their own, often a static access key"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.",
        "grade": "BB",
        "name": "Google Cloud Secret Manager",
        "position": 3,
        "price": "$0.06 / mo",
        "score": 76.5,
        "slug": "google-secret-manager",
        "strengths": [
          "Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused",
          "$0.06 a version a month and $0.03 per 10,000 accesses, with 6 versions and 10,000 accesses a month free",
          "IAM conditions and per-secret roles, with version_destroy_ttl to delay destruction"
        ],
        "url": "https://www.anchorterminal.com/tools/google-secret-manager",
        "verdict": "Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.",
        "weaknesses": [
          "Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle",
          "Secret reads are Data Access audit logs, which you have to enable",
          "Global secrets accept only 2 version writes a second, and AddSecretVersion has no request ID for safe retries"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents and runtimes already on Azure, where a managed identity reads a secret with no stored credential.",
        "grade": "BB",
        "name": "Azure Key Vault",
        "position": 4,
        "price": "$0.003 / 1k calls",
        "score": 74.7,
        "slug": "azure-key-vault",
        "strengths": [
          "No API keys. Every call carries a Microsoft Entra ID bearer token, and managed identities remove stored credentials for workloads on Azure",
          "Azure roles can be assigned on a vault or one secret, with Key Vault Secrets User limited to reading secret contents",
          "Deleted secrets stay recoverable for 7 to 90 days, and purging needs a separate permission"
        ],
        "url": "https://www.anchorterminal.com/tools/azure-key-vault",
        "verdict": "Access runs on Microsoft Entra ID tokens and Azure roles that can be scoped to one secret, with soft delete, a 99.99 per cent SLA and a public OpenAPI contract. Secret rotation needs an Event Grid trigger and a function the owner writes, audit logging is off until enabled, and an Azure subscription needs a person and a payment card.",
        "weaknesses": [
          "No managed rotation for secrets. Key Vault raises a near-expiry event 30 days ahead and the owner's Azure Function does the rotation",
          "Audit logging is off until a diagnostic setting sends AuditEvent logs to a storage account, event hub or Azure Monitor",
          "Set Secret has no idempotency key, so a retried write adds another version"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.",
        "grade": "BB",
        "name": "Akeyless (SecretlessAI and MCP server)",
        "position": 5,
        "price": "Freemium",
        "score": 73.6,
        "slug": "akeyless",
        "strengths": [
          "Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials",
          "Runtime Authority intent rules with a kill switch, generally available since 9 September 2026",
          "SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS and FIPS 140-3 validation listed in the trust centre, plus a bug bounty"
        ],
        "url": "https://www.anchorterminal.com/tools/akeyless",
        "verdict": "Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.",
        "weaknesses": [
          "No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract",
          "Errors come back as a single `error` string with no code, and no Retry-After or backoff guidance turned up",
          "The free plan has no OIDC, SAML or LDAP auth and keeps audit logs for 3 days"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "Teams that want a hosted store and a one-line `doppler run` wrapper for agents, with config-scoped read-only tokens.",
        "grade": "BB",
        "name": "Doppler",
        "position": 6,
        "price": "$21 / seat-mo",
        "score": 71.4,
        "slug": "doppler",
        "strengths": [
          "Service tokens bound to one config, read-only by default, with --max-age expiry",
          "OIDC service account identities on Team, so shared runners don't hold a static token",
          "OpenAPI 3.1 and an llms.txt with about 500 Markdown links"
        ],
        "url": "https://www.anchorterminal.com/tools/doppler",
        "verdict": "Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.",
        "weaknesses": [
          "Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts",
          "The MCP server is experimental, has no tool annotations or value masking, and exposes up to 89 tools by default",
          "35 open CLI issues, most of the newest without a reply"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.",
        "grade": "BB",
        "name": "Pulumi ESC",
        "position": 7,
        "price": "$0.01 / 1k req",
        "score": 71.1,
        "slug": "pulumi-esc",
        "strengths": [
          "The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it",
          "Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page",
          "OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default"
        ],
        "url": "https://www.anchorterminal.com/tools/pulumi-esc",
        "verdict": "An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.",
        "weaknesses": [
          "Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise",
          "No API rate limit with numbers was found in the reviewed documentation",
          "No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value.",
        "grade": "B",
        "name": "1Password service accounts, SDKs and Environments MCP",
        "position": 8,
        "price": "$8.99 / seat-mo",
        "score": 69.7,
        "slug": "1password",
        "strengths": [
          "Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation",
          "Environments MCP server with 8 tools that never returns a secret value and asks for approval per Environment",
          "Official Go, JavaScript and Python SDKs, MIT, with workload identity through the Credential Broker in JavaScript 0.5.0 (public preview)"
        ],
        "url": "https://www.anchorterminal.com/tools/1password",
        "verdict": "Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After.",
        "weaknesses": [
          "Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After",
          "SDKs are version 0 with three months of patches per release, and 5 of the 8 newest Python SDK issues have no reply",
          "No SLA found, and the audit log and Events API need Business"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.",
        "grade": "B",
        "name": "Keeper Secrets Manager",
        "position": 9,
        "price": "Paid",
        "score": 69.4,
        "slug": "keeper-secrets-manager",
        "strengths": [
          "Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone",
          "Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page",
          "An application sees only the shared folders and records assigned to it, read-only unless shared as editable"
        ],
        "url": "https://www.anchorterminal.com/tools/keeper-secrets-manager",
        "verdict": "Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.",
        "weaknesses": [
          "Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote",
          "No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with `{\"error\":\"throttled\"}`",
          "No OpenAPI or documented raw HTTP use for `/api/rest/sm/v1`. The SDKs are the only supported route"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.",
        "grade": "B",
        "name": "Phase",
        "position": 10,
        "price": "$10 / seat-mo",
        "score": 68,
        "slug": "phase",
        "strengths": [
          "Service account tokens take an expiry and can be created and deleted through `/v1/service-accounts/:id/tokens`, and service accounts are free on every plan",
          "The CLI's AI mode redacts `secret` and `sealed` values and blocks `printenv`, `env` and `phase shell` when it detects an agent",
          "Every reveal and every REST fetch of a secret is recorded as a `READ` event with actor and IP address"
        ],
        "url": "https://www.anchorterminal.com/tools/phase",
        "verdict": "Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.",
        "weaknesses": [
          "No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations",
          "No pagination, field selection or idempotency keys were found in the API reference, and errors are a single free-text `error` string",
          "The Free plan keeps audit logs for 24 hours. Rotation, custom roles and network access policies need Pro, and dynamic secrets need Enterprise"
        ],
        "where": "hosted",
        "x402": "no"
      }
    ],
    "updated": "2026-10-08"
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/best/secrets/",
    "json": "https://www.anchorterminal.com/best/secrets/index.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/best/secrets/index.md",
    "slim": "https://www.anchorterminal.com/best/secrets/index.min.md"
  },
  "markdown": "The 10 highest-scoring of 13 secrets managers and credential vaults on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.\n\n- Ranked: 13 · agent-ready (BB or better): 7 · accept x402: 0 · hosted endpoints: 9\n- Full ranked table: https://www.anchorterminal.com/categories/secrets.md\n- Head-to-head comparisons: https://www.anchorterminal.com/compare/secrets/index.md (71)\n- Methodology: https://www.anchorterminal.com/benchmark/index.md\n\n## The shortlist\n\n| # | Tool | Grade | Score | Best for | Price | Where |\n| --- | --- | --- | --- | --- | --- | --- |\n| 1 | [Infisical](https://www.anchorterminal.com/tools/infisical.md) | A | 83.7 | Teams that want an open-source secrets manager they can self-host, and for coding agents run under Agent Vault so they call APIs without ever holding a token. | Freemium | hosted and local |\n| 2 | [AWS Secrets Manager](https://www.anchorterminal.com/tools/aws-secrets-manager.md) | BB | 77.7 | Agents running on AWS compute that should read credentials through a role with no key at all, and for RDS-family databases that need managed rotation. | $0.40 / mo | hosted |\n| 3 | [Google Cloud Secret Manager](https://www.anchorterminal.com/tools/google-secret-manager.md) | BB | 76.5 | Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants. | $0.06 / mo | hosted |\n| 4 | [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) | BB | 74.7 | Agents and runtimes already on Azure, where a managed identity reads a secret with no stored credential. | $0.003 / 1k calls | hosted |\n| 5 | [Akeyless (SecretlessAI and MCP server)](https://www.anchorterminal.com/tools/akeyless.md) | BB | 73.6 | Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract. | Freemium | hosted and local |\n| 6 | [Doppler](https://www.anchorterminal.com/tools/doppler.md) | BB | 71.4 | Teams that want a hosted store and a one-line \\`doppler run\\` wrapper for agents, with config-scoped read-only tokens. | $21 / seat-mo | hosted and local |\n| 7 | [Pulumi ESC](https://www.anchorterminal.com/tools/pulumi-esc.md) | BB | 71.1 | Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup. | $0.01 / 1k req | hosted |\n| 8 | [1Password service accounts, SDKs and Environments MCP](https://www.anchorterminal.com/tools/1password.md) | B | 69.7 | Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value. | $8.99 / seat-mo | local |\n| 9 | [Keeper Secrets Manager](https://www.anchorterminal.com/tools/keeper-secrets-manager.md) | B | 69.4 | Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server. | Paid | local |\n| 10 | [Phase](https://www.anchorterminal.com/tools/phase.md) | B | 68 | Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI. | $10 / seat-mo | hosted |\n\n## Picks by need\n\n- Highest score overall: [Infisical](https://www.anchorterminal.com/tools/infisical.md), A, 83.7/100 on the benchmark. Also [AWS Secrets Manager](https://www.anchorterminal.com/tools/aws-secrets-manager.md), BB, 77.7/100.\n- Schema \u0026 documentation: [AWS Secrets Manager](https://www.anchorterminal.com/tools/aws-secrets-manager.md), 96/100 on schema \u0026 documentation, against 87 for the overall leader.\n- Security \u0026 auth: [1Password service accounts, SDKs and Environments MCP](https://www.anchorterminal.com/tools/1password.md), 94/100 on security \u0026 auth, against 91 for the overall leader.\n- Maintenance \u0026 community: [Keeper Secrets Manager](https://www.anchorterminal.com/tools/keeper-secrets-manager.md), 92/100 on maintenance \u0026 community, against 90 for the overall leader.\n- Transparency \u0026 trust: [1Password service accounts, SDKs and Environments MCP](https://www.anchorterminal.com/tools/1password.md), 87/100 on transparency \u0026 trust, against 83 for the overall leader.\n- Lowest paid price per 1,000 calls: [Google Cloud Secret Manager](https://www.anchorterminal.com/tools/google-secret-manager.md), $0.003 per 1,000 calls, the lowest of the 3 listings here with a paid price in this unit (free allowances aside). Also [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md), $0.003 per 1,000 calls.\n- The review panel's favourite: [AWS Secrets Manager](https://www.anchorterminal.com/tools/aws-secrets-manager.md), 3.9/5 from 8 panel reviews.\n\n## How to choose\n\n- Machine identity and scoping: Check how the runtime authenticates and whether each identity can read only its agent's keys, since a shared login exposes every key the agent could reach.\n- Rotation during a live run: Check whether a rotated key reaches a running agent without a restart and how long the old value works, since a long overlap widens the risk from a leak.\n- Audit events and read latency: Check what each read logs and how much delay a read adds, since an agent that reads a key on every call pays that cost repeatedly.\n- Self-hosting and data residency: Check whether you can self-host or pick a region and what the vendor can read, since a key store is only as trusted as its host.\n\n- How the benchmark tests this category: An agent runtime reads a key at call time with a scoped machine identity, the key is rotated mid-run and access is then revoked. We check the scoping, how rotation lands, what the audit log records and how long each read takes.\n\n## Each one in detail\n\n### 1. Infisical, A 83.7/100\n\nOpen-source secrets manager with machine identities (Universal Auth, OIDC, AWS, GCP, Azure, Kubernetes, SPIFFE), dynamic secrets, rotation and audit logs, hosted in the US or EU or self-hosted.\n\n- Verdict: Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.\n- Choose it for: Teams that want an open-source secrets manager they can self-host, and for coding agents run under Agent Vault so they call APIs without ever holding a token.\n- Strength: Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them\n- Strength: Thirteen machine identity auth methods with short-lived, revocable access tokens\n- Strength: MIT core that self-hosts with no API rate limits, plus US and EU cloud regions\n- Weakness: Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month\n- Weakness: Cloud rate limits are per client IP, so agents behind one NAT share 600 requests a minute\n- Weakness: The MCP server returns secret values unless INFISICAL_MASK_SECRET_VALUES is set, and it's still version 0.0.x\n- Price: Freemium · Auth: OAuth or key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/infisical.md\n\n### 2. AWS Secrets Manager, BB 77.7/100\n\nManaged secrets store priced per secret and per API call, with IAM for access, KMS for encryption, CloudTrail for audit, cross-region replication and rotation either managed (RDS, Aurora, DocumentDB, Redshift) or by a Lambda function you own.\n\n- Verdict: IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.\n- Choose it for: Agents running on AWS compute that should read credentials through a role with no key at all, and for RDS-family databases that need managed rotation.\n- Strength: IAM roles on EC2, ECS, Lambda and EKS mean no long-lived credential in the agent\n- Strength: Published quotas, 10,000 reads a second per region, and a 99.99% SLA\n- Strength: Idempotent writes on ClientRequestToken and immutable versions\n- Weakness: Every API call is billed, so per-request reads add up and the docs push you to cache\n- Weakness: Rotation outside the RDS family means writing and running a Lambda function\n- Weakness: Off-AWS agents need AWS credentials of their own, often a static access key\n- Price: $0.40 / mo · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/aws-secrets-manager.md\n- Against #1: https://www.anchorterminal.com/compare/aws-secrets-manager-vs-infisical.md\n\n### 3. Google Cloud Secret Manager, BB 76.5/100\n\nGoogle Cloud's managed service for storing and accessing application secrets.\n\n- Verdict: Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.\n- Choose it for: Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.\n- Strength: Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused\n- Strength: $0.06 a version a month and $0.03 per 10,000 accesses, with 6 versions and 10,000 accesses a month free\n- Strength: IAM conditions and per-secret roles, with version_destroy_ttl to delay destruction\n- Weakness: Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle\n- Weakness: Secret reads are Data Access audit logs, which you have to enable\n- Weakness: Global secrets accept only 2 version writes a second, and AddSecretVersion has no request ID for safe retries\n- Price: $0.06 / mo · Auth: OAuth · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/google-secret-manager.md\n- Against #1: https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md\n\n### 4. Azure Key Vault, BB 74.7/100\n\nMicrosoft Azure's managed store for secrets, encryption keys and TLS certificates. Applications read secrets over a REST API or the Azure SDKs and CLI, signing in with Microsoft Entra ID and authorised by Azure role assignments.\n\n- Verdict: Access runs on Microsoft Entra ID tokens and Azure roles that can be scoped to one secret, with soft delete, a 99.99 per cent SLA and a public OpenAPI contract. Secret rotation needs an Event Grid trigger and a function the owner writes, audit logging is off until enabled, and an Azure subscription needs a person and a payment card.\n- Choose it for: Agents and runtimes already on Azure, where a managed identity reads a secret with no stored credential.\n- Strength: No API keys. Every call carries a Microsoft Entra ID bearer token, and managed identities remove stored credentials for workloads on Azure\n- Strength: Azure roles can be assigned on a vault or one secret, with Key Vault Secrets User limited to reading secret contents\n- Strength: Deleted secrets stay recoverable for 7 to 90 days, and purging needs a separate permission\n- Weakness: No managed rotation for secrets. Key Vault raises a near-expiry event 30 days ahead and the owner's Azure Function does the rotation\n- Weakness: Audit logging is off until a diagnostic setting sends AuditEvent logs to a storage account, event hub or Azure Monitor\n- Weakness: Set Secret has no idempotency key, so a retried write adds another version\n- Price: $0.003 / 1k calls · Auth: OAuth · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/azure-key-vault.md\n- Against #1: https://www.anchorterminal.com/compare/azure-key-vault-vs-infisical.md\n\n### 5. Akeyless (SecretlessAI and MCP server), BB 73.6/100\n\nSaaS secrets and machine-identity platform with a self-hosted Gateway that brokers access.\n\n- Verdict: Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.\n- Choose it for: Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.\n- Strength: Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials\n- Strength: Runtime Authority intent rules with a kill switch, generally available since 9 September 2026\n- Strength: SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS and FIPS 140-3 validation listed in the trust centre, plus a bug bounty\n- Weakness: No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract\n- Weakness: Errors come back as a single `error` string with no code, and no Retry-After or backoff guidance turned up\n- Weakness: The free plan has no OIDC, SAML or LDAP auth and keeps audit logs for 3 days\n- Price: Freemium · Auth: OAuth or key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/akeyless.md\n- Against #1: https://www.anchorterminal.com/compare/akeyless-vs-infisical.md\n\n### 6. Doppler, BB 71.4/100\n\nHosted secrets manager organised by project, environment and config.\n\n- Verdict: Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.\n- Choose it for: Teams that want a hosted store and a one-line `doppler run` wrapper for agents, with config-scoped read-only tokens.\n- Strength: Service tokens bound to one config, read-only by default, with --max-age expiry\n- Strength: OIDC service account identities on Team, so shared runners don't hold a static token\n- Strength: OpenAPI 3.1 and an llms.txt with about 500 Markdown links\n- Weakness: Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts\n- Weakness: The MCP server is experimental, has no tool annotations or value masking, and exposes up to 89 tools by default\n- Weakness: 35 open CLI issues, most of the newest without a reply\n- Price: $21 / seat-mo · Auth: OAuth or key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/doppler.md\n- Against #1: https://www.anchorterminal.com/compare/doppler-vs-infisical.md\n\n### 7. Pulumi ESC, BB 71.1/100\n\nPulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs.\n\n- Verdict: An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.\n- Choose it for: Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.\n- Strength: The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it\n- Strength: Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page\n- Strength: OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default\n- Weakness: Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise\n- Weakness: No API rate limit with numbers was found in the reviewed documentation\n- Weakness: No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date\n- Price: $0.01 / 1k req · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/pulumi-esc.md\n- Against #1: https://www.anchorterminal.com/compare/infisical-vs-pulumi-esc.md\n\n### 8. 1Password service accounts, SDKs and Environments MCP, B 69.7/100\n\nPassword manager with a developer layer for agents.\n\n- Verdict: Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After.\n- Choose it for: Teams whose people already use 1Password and want agents reading from the same vaults with read-only, vault-scoped tokens, and for developers who want an MCP server that never leaks a value.\n- Strength: Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation\n- Strength: Environments MCP server with 8 tools that never returns a secret value and asks for approval per Environment\n- Strength: Official Go, JavaScript and Python SDKs, MIT, with workload identity through the Credential Broker in JavaScript 0.5.0 (public preview)\n- Weakness: Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After\n- Weakness: SDKs are version 0 with three months of patches per release, and 5 of the 8 newest Python SDK issues have no reply\n- Weakness: No SLA found, and the audit log and Events API need Business\n- Price: $8.99 / seat-mo · Auth: OAuth or key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/1password.md\n- Against #1: https://www.anchorterminal.com/compare/1password-vs-infisical.md\n\n### 9. Keeper Secrets Manager, B 69.4/100\n\nKeeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the `ksm` CLI or a local MCP server, decrypting on the client.\n\n- Verdict: Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.\n- Choose it for: Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.\n- Strength: Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone\n- Strength: Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page\n- Strength: An application sees only the shared folders and records assigned to it, read-only unless shared as editable\n- Weakness: Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote\n- Weakness: No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with `{\"error\":\"throttled\"}`\n- Weakness: No OpenAPI or documented raw HTTP use for `/api/rest/sm/v1`. The SDKs are the only supported route\n- Price: Paid · Auth: API key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/keeper-secrets-manager.md\n- Against #1: https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager.md\n\n### 10. Phase, B 68/100\n\nPhase is an open-source secrets manager from Phi Security Inc. with end-to-end encryption, service accounts, secret rotation and audit logs. Agents reach it through a REST API, a CLI and SDKs, on Phase Cloud or self-hosted.\n\n- Verdict: Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.\n- Choose it for: Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.\n- Strength: Service account tokens take an expiry and can be created and deleted through `/v1/service-accounts/:id/tokens`, and service accounts are free on every plan\n- Strength: The CLI's AI mode redacts `secret` and `sealed` values and blocks `printenv`, `env` and `phase shell` when it detects an agent\n- Strength: Every reveal and every REST fetch of a secret is recorded as a `READ` event with actor and IP address\n- Weakness: No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations\n- Weakness: No pagination, field selection or idempotency keys were found in the API reference, and errors are a single free-text `error` string\n- Weakness: The Free plan keeps audit logs for 24 hours. Rotation, custom roles and network access policies need Pro, and dynamic secrets need Enterprise\n- Price: $10 / seat-mo · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/phase.md\n- Against #1: https://www.anchorterminal.com/compare/infisical-vs-phase.md\n\n3 more are ranked in the full table: https://www.anchorterminal.com/categories/secrets.md\n\n## Head to head\n\n- [AWS Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-infisical.md)\n- [Google Cloud Secret Manager vs Infisical](https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md)\n- [Azure Key Vault vs Infisical](https://www.anchorterminal.com/compare/azure-key-vault-vs-infisical.md)\n- [Akeyless (SecretlessAI and MCP server) vs Infisical](https://www.anchorterminal.com/compare/akeyless-vs-infisical.md)\n- [AWS Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-google-secret-manager.md)\n- [AWS Secrets Manager vs Azure Key Vault](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-azure-key-vault.md)\n- [Akeyless (SecretlessAI and MCP server) vs AWS Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-aws-secrets-manager.md)\n- [Azure Key Vault vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/azure-key-vault-vs-google-secret-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Azure Key Vault](https://www.anchorterminal.com/compare/akeyless-vs-azure-key-vault.md)\n\n## Questions\n\n### What are the highest-rated secrets managers and credential vaults for AI agents?\n\nInfisical has the highest benchmark score of the 13 ranked secrets managers and credential vaults, 83.7 (A). AWS Secrets Manager is second with 77.7 (BB).\n\n### How many secrets managers and credential vaults are agent-ready?\n\n7 of the 13 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.\n\n### Which secrets managers and credential vaults accept x402 payments?\n\nNone of the ranked listings here accepts x402 for its main call yet.\n\n### Which of these secrets managers and credential vaults is cheapest?\n\nBy published paid prices, Google Cloud Secret Manager, at $0.003 per 1,000 calls, the lowest of the 3 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.\n\n### How is this list ranked?\n\nBy the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.\n\n## How this list is made\n\nThe order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Best of",
        "url": "https://www.anchorterminal.com/best/"
      },
      {
        "name": "Secrets \u0026 credential vaults",
        "url": ""
      }
    ],
    "description": "Infisical (A), AWS Secrets Manager (BB) and Google Cloud Secret Manager (BB) lead the 13 ranked secrets managers and credential vaults. Picks by need, strengths, weaknesses and prices from the Anchor benchmark.",
    "facts": [
      "Infisical A",
      "AWS Secrets Manager BB",
      "Google Cloud Secret Manager BB"
    ],
    "h1": "Best secrets managers and credential vaults for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/best-secrets.png",
    "path": "/best/secrets/",
    "published": "",
    "section": "tools",
    "title": "Best secrets managers and credential vaults for AI agents in 2026",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/best/secrets/"
  },
  "tokens": {
    "markdown": 6200,
    "slim": 1580
  },
  "version": 1
}
