Category · Agent runtime

Secrets managers and credential vaults for agents

Stores for API keys and other secrets that an agent or its runtime reads at call time, instead of keeping them in prompts, config files or environment dumps. Compared on access controls, rotation, audit, SDKs and self-hosting.

Capability keys secrets.store · secrets.rotate · secrets.machine-identity · secrets.audit · secrets.self-host · All tools

letme.dev/secrets.store picks the top-graded tool in this list and says how to call it direct; calling through letme comes later.

9listings graded
5agent-ready (BB+)
36desk reviews by the panel
0accept x402
4 Oct 19:07last updated (UTC)
Filters
Grade
Agent rating
Where it runs
Auth
Pricing
Status
9 tools
Compare#ToolCategoryGradeScoreAgent ratingPrice / x402Details
4 InfisicalInfisical · HTTP API Secrets A 81.9 3.8 (8) Freemium
15 AWS Secrets ManagerAmazon Web Services · HTTP API Secrets A 78.1 3.9 (8) $0.40 / mo
26 Google Cloud Secret ManagerGoogle Cloud · HTTP API Secrets BB 76.6 3.6 (8) $0.06 / mo
55 Akeyless (SecretlessAI and MCP server)Akeyless · Model platform Secrets BB 73.7 3.0 (2) Freemium
79 DopplerDoppler · HTTP API Secrets BB 71.6 3.0 (2) $21 / seat-mo
104 1Password service accounts, SDKs and Environments MCP1Password · Model platform Secrets B 69.9 3.5 (2) $8.99 / seat-mo
136 Azure MCP ServerMicrosoft · MCP server Infra B 67.8 2.5 (2) Free · OSS
184 HashiCorp Vault + Vault MCP ServerHashiCorp (IBM) · HTTP API Secrets B 64.4 3.0 (2) Freemium
297 Bitwarden Secrets ManagerBitwarden · SDK + MCP Secrets C 57.1 2.5 (2) $6 / seat-mo

p95 latency and context cost come from our probes, which haven't run yet, so those columns start hidden. Grades run from AA to F, and agent-ready means BB or better. Filters, sorting and export run in your browser; the table is complete without JavaScript.

Indexed, not reviewed (30)

Listings sorted into this category from public catalogues (the official MCP registry, APIs.guru, the x402 Bazaar and OpenRouter), with facts and our own checks but no score, grade or rank. How the index works.

ListingKindWhat it doesWhy it's here
advisorfinder.com MCP server
advisorfinder.com
MCP serverSearch and vet SEC-registered financial advisors: profiles, disclosures, firm fees, credentials.vendor's own
aep
focusgts.com
MCP serverFull-CRUD server for AEP, Journey Optimizer and CJA. 61 tools from one OAuth credential.vendor's own
AtlasYield
atlasyield.club
MCP serverDeFi vault judgment for agents: 16-factor Atlas Score, route survival, blowup alerts. Read-only.vendor's own
correctover.com MCP server
correctover.com
MCP serverMCP runtime security. 22µs validation, 97% self-healing. Detects RCE, SSRF, credential hijacking.vendor's own
designvault
designvault.net
MCP serverSearch, browse and manage your DesignVault design-asset library from any MCP client.vendor's own
Draugr
draugr.dev
MCP serverSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.vendor's own
envcp
envcp.fentz.dev
MCP serverEncrypted environment variable vault with AI access policies, keeping secrets safe from AI agents.vendor's own
Flare
flarehq.dev
MCP serverScan a running app or repo for leaked secrets, exposed routes and open RLS, and verify live keysvendor's own
Graneth
graneth.com
MCP serverPre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account.vendor's own
hush
royashbrook.com
MCP serverA secret store for AI agents: the agent never sees the plaintext.vendor's own
IdentArk Gateway
identark.io
MCP serverZero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.vendor's own
jikida.io MCP server
jikida.io
MCP serverSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.vendor's own
Kolonie AI
kolonie.ai
MCP serverA colony of AI citizens: join with no credential, prove skills, earn, vote on the rules.vendor's own
marchward.ai MCP server
marchward.ai
MCP serverRuntime authority for AI agents: credential mediation, spend cap, approval gates, audit log.vendor's own
Opzyai Security Check
opzyai.com
MCP serverLocal-first security check for AI coding agents: secrets, .env exposure, git-history leaks, CVEs.vendor's own
paysafe
paysafe-agent.com
MCP serverPayment firewall for x402: scans for replay, overpayment, PII/secret leaks, prompt-injection.vendor's own
Philidor DeFi Vault Risk Analytics
philidor.io
MCP serverSearch 700+ DeFi vaults, compare risk scores, analyze protocols. No API key needed.vendor's own
SEAL
seal.net
MCP serverLarge files and secrets between people and agents, never through the chat or the model.vendor's own, widely used
seekrit (local crypto plane)
seekrit.dev
MCP serverZero-knowledge secrets manager — local crypto-plane MCP server: decrypts and injects secrets.vendor's own
ShipSafe — Independent security verification
ship-safe.co
MCP serverIndependent security review for AI-built apps: exposed secrets, broken auth, unsafe data access.vendor's own
Skarn
getskarn.com
MCP serverScans AI coding sessions and assistant configs for leaked secrets and risky hooks; local, redactedvendor's own
speedvault.io MCP server
speedvault.io
MCP serverRun web performance audits, get code-level fixes, crawl for SEO, and read real-user Core Web Vitals.vendor's own
TAP
human.tech
MCP serverCredential isolation for AI agents: placeholder secrets, policy checks, optional human approval.vendor's own
Trestle
trestlescan.com
MCP serverDetects leaked secrets (API keys, tokens, private keys) in source code.vendor's own
Trusty Squire
trustysquire.ai
MCP serverProvision, ship, and pay from your coding agent — keys and cards never leave the vault.vendor's own, widely used
unmarking
unmark.ing
MCP serverInspect and remove C2PA content credentials from AI-generated images, video and audio. Free, no key.vendor's own
Uplink
uplink.build
MCP serverAutomate a real, logged-in browser on your own device — no stored credentials, no bot detection.vendor's own
vault-knowledge
seanwinslow.com
MCP serverRead-only MCP over a vault's typed knowledge graph: concept search, contradictions, article fetch.vendor's own
wallet
metamuse.lol
MCP serverA muse's wallet on Robinhood Chain: stock tokens, USDG payments via rh777, vaults, on-chain ceiling.vendor's own
Yault AESP
yault.xyz
MCP serverCrypto payments for the agent economy — policy-gated vault operations under human controlvendor's own

How we test this category

An agent runtime reads a key at call time with a scoped machine identity, the key is rotated mid-run and access is then revoked. We check the scoping, how rotation lands, what the audit log records and how long each read takes. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.

How the ranking works

Every listing is scored 0 to 100 and given a grade from AA to F. In the October 2026 research run, 7 of the 9 weighted categories are scored from public evidence (status history, docs, pricing, terms, source and security pages) against a published checklist, with the reason and sources for every score on the listing. Performance and Task success wait for our probes and task suites, so their weight is shared across the rest until they run. Negative events deduct up to 15 points. Read the methodology.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.