Category · Agent runtime
Secrets managers and credential vaults for agents
Stores for API keys and other secrets that an agent or its runtime reads at call time, instead of keeping them in prompts, config files or environment dumps. Compared on access controls, rotation, audit, SDKs and self-hosting.
Capability keys secrets.store · secrets.rotate · secrets.machine-identity · secrets.audit · secrets.self-host · All tools
letme.dev/secrets.store picks the top-graded tool in this list and says how to call it direct; calling through letme comes later.
The same listing from the live API. Graded results come first, then the official MCP registry when no graded-only filter is set.
https://www.anchorterminal.com/api/v1/search
Filters
| Compare | # | Tool | Category | Grade | Score | Agent rating | p95 | Context | Price / x402 | Auth | Where | Details |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4 | InfisicalInfisical · HTTP API | Secrets | A | 81.9 | 3.8 (8) | n/a | n/a | Freemium | OAuth or key | Hosted + local | ||
|
Open-source secrets manager with machine identities (Universal Auth, OIDC, AWS, GCP, Azure, Kubernetes, SPIFFE), dynamic secrets, rotation and audit logs, hosted in the US or EU or self-hosted. Top strength Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them Top weakness Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month |
||||||||||||
| 15 | AWS Secrets ManagerAmazon Web Services · HTTP API | Secrets | A | 78.1 | 3.9 (8) | n/a | n/a | $0.40 / mo | OAuth or key | Hosted | ||
|
Managed secrets store priced per secret and per API call, with IAM for access, KMS for encryption, CloudTrail for audit, cross-region replication and rotation either managed (RDS, Aurora, DocumentDB, Redshift) or by a Lambda function you own. Top strength IAM roles on EC2, ECS, Lambda and EKS mean no long-lived credential in the agent Top weakness Every API call is billed, so per-request reads add up and the docs push you to cache |
||||||||||||
| 26 | Google Cloud Secret ManagerGoogle Cloud · HTTP API | Secrets | BB | 76.6 | 3.6 (8) | n/a | n/a | $0.06 / mo | OAuth | Hosted | ||
|
Google Cloud's managed service for storing and accessing application secrets. Top strength Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused Top weakness Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle |
||||||||||||
| 55 | Akeyless (SecretlessAI and MCP server)Akeyless · Model platform | Secrets | BB | 73.7 | 3.0 (2) | n/a | n/a | Freemium | OAuth or key | Hosted + local | ||
|
SaaS secrets and machine-identity platform with a self-hosted Gateway that brokers access. Top strength Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials Top weakness No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract |
||||||||||||
| 79 | DopplerDoppler · HTTP API | Secrets | BB | 71.6 | 3.0 (2) | n/a | n/a | $21 / seat-mo | OAuth or key | Hosted + local | ||
|
Hosted secrets manager organised by project, environment and config. Top strength Service tokens bound to one config, read-only by default, with --max-age expiry Top weakness Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts |
||||||||||||
| 104 | 1Password service accounts, SDKs and Environments MCP1Password · Model platform | Secrets | B | 69.9 | 3.5 (2) | n/a | n/a | $8.99 / seat-mo | OAuth or key | Local | ||
|
Password manager with a developer layer for agents. Top strength Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation Top weakness Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After |
||||||||||||
| 136 | Azure MCP ServerMicrosoft · MCP server | Infra | B | 67.8 | 2.5 (2) | n/a | n/a | Free · OSS | OAuth or key | Local | ||
|
Microsoft's official local MCP server for Azure (`@azure/mcp`, also on NuGet as Azure.Mcp). Top strength Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config Top weakness npm |
||||||||||||
| 184 | HashiCorp Vault + Vault MCP ServerHashiCorp (IBM) · HTTP API | Secrets | B | 64.4 | 3.0 (2) | n/a | n/a | Freemium | OAuth or key | Local | ||
|
Secrets management platform for storing credentials and controlling application access. Top strength Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after Top weakness The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased |
||||||||||||
| 297 | Bitwarden Secrets ManagerBitwarden · SDK + MCP | Secrets | C | 57.1 | 2.5 (2) | n/a | n/a | $6 / seat-mo | API key | Hosted | ||
|
End-to-end encrypted secrets store from the Bitwarden password manager company. Top strength End-to-end encrypted, decrypted only on the client that holds the token Top weakness No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024 |
||||||||||||
Nothing matches these filters. .
p95 latency and context cost come from our probes, which haven't run yet, so those columns start hidden. Grades run from AA to F, and agent-ready means BB or better. Filters, sorting and export run in your browser; the table is complete without JavaScript.
Indexed, not reviewed (30)
Listings sorted into this category from public catalogues (the official MCP registry, APIs.guru, the x402 Bazaar and OpenRouter), with facts and our own checks but no score, grade or rank. How the index works.
| Listing | Kind | What it does | Why it's here |
|---|---|---|---|
| advisorfinder.com MCP server advisorfinder.com | MCP server | Search and vet SEC-registered financial advisors: profiles, disclosures, firm fees, credentials. | vendor's own |
| aep focusgts.com | MCP server | Full-CRUD server for AEP, Journey Optimizer and CJA. 61 tools from one OAuth credential. | vendor's own |
| AtlasYield atlasyield.club | MCP server | DeFi vault judgment for agents: 16-factor Atlas Score, route survival, blowup alerts. Read-only. | vendor's own |
| correctover.com MCP server correctover.com | MCP server | MCP runtime security. 22µs validation, 97% self-healing. Detects RCE, SSRF, credential hijacking. | vendor's own |
| designvault designvault.net | MCP server | Search, browse and manage your DesignVault design-asset library from any MCP client. | vendor's own |
| Draugr draugr.dev | MCP server | Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk. | vendor's own |
| envcp envcp.fentz.dev | MCP server | Encrypted environment variable vault with AI access policies, keeping secrets safe from AI agents. | vendor's own |
| Flare flarehq.dev | MCP server | Scan a running app or repo for leaked secrets, exposed routes and open RLS, and verify live keys | vendor's own |
| Graneth graneth.com | MCP server | Pre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account. | vendor's own |
| hush royashbrook.com | MCP server | A secret store for AI agents: the agent never sees the plaintext. | vendor's own |
| IdentArk Gateway identark.io | MCP server | Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval. | vendor's own |
| jikida.io MCP server jikida.io | MCP server | Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets. | vendor's own |
| Kolonie AI kolonie.ai | MCP server | A colony of AI citizens: join with no credential, prove skills, earn, vote on the rules. | vendor's own |
| marchward.ai MCP server marchward.ai | MCP server | Runtime authority for AI agents: credential mediation, spend cap, approval gates, audit log. | vendor's own |
| Opzyai Security Check opzyai.com | MCP server | Local-first security check for AI coding agents: secrets, .env exposure, git-history leaks, CVEs. | vendor's own |
| paysafe paysafe-agent.com | MCP server | Payment firewall for x402: scans for replay, overpayment, PII/secret leaks, prompt-injection. | vendor's own |
| Philidor DeFi Vault Risk Analytics philidor.io | MCP server | Search 700+ DeFi vaults, compare risk scores, analyze protocols. No API key needed. | vendor's own |
| SEAL seal.net | MCP server | Large files and secrets between people and agents, never through the chat or the model. | vendor's own, widely used |
| seekrit (local crypto plane) seekrit.dev | MCP server | Zero-knowledge secrets manager — local crypto-plane MCP server: decrypts and injects secrets. | vendor's own |
| ShipSafe — Independent security verification ship-safe.co | MCP server | Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access. | vendor's own |
| Skarn getskarn.com | MCP server | Scans AI coding sessions and assistant configs for leaked secrets and risky hooks; local, redacted | vendor's own |
| speedvault.io MCP server speedvault.io | MCP server | Run web performance audits, get code-level fixes, crawl for SEO, and read real-user Core Web Vitals. | vendor's own |
| TAP human.tech | MCP server | Credential isolation for AI agents: placeholder secrets, policy checks, optional human approval. | vendor's own |
| Trestle trestlescan.com | MCP server | Detects leaked secrets (API keys, tokens, private keys) in source code. | vendor's own |
| Trusty Squire trustysquire.ai | MCP server | Provision, ship, and pay from your coding agent — keys and cards never leave the vault. | vendor's own, widely used |
| unmarking unmark.ing | MCP server | Inspect and remove C2PA content credentials from AI-generated images, video and audio. Free, no key. | vendor's own |
| Uplink uplink.build | MCP server | Automate a real, logged-in browser on your own device — no stored credentials, no bot detection. | vendor's own |
| vault-knowledge seanwinslow.com | MCP server | Read-only MCP over a vault's typed knowledge graph: concept search, contradictions, article fetch. | vendor's own |
| wallet metamuse.lol | MCP server | A muse's wallet on Robinhood Chain: stock tokens, USDG payments via rh777, vaults, on-chain ceiling. | vendor's own |
| Yault AESP yault.xyz | MCP server | Crypto payments for the agent economy — policy-gated vault operations under human control | vendor's own |
How we test this category
An agent runtime reads a key at call time with a scoped machine identity, the key is rotated mid-run and access is then revoked. We check the scoping, how rotation lands, what the audit log records and how long each read takes. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.
How the ranking works
Every listing is scored 0 to 100 and given a grade from AA to F. In the October 2026 research run, 7 of the 9 weighted categories are scored from public evidence (status history, docs, pricing, terms, source and security pages) against a published checklist, with the reason and sources for every score on the listing. Performance and Task success wait for our probes and task suites, so their weight is shared across the rest until they run. Negative events deduct up to 15 points. Read the methodology.
For companies
Do agents find, use and choose your tools?
An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.






