# Secrets managers and credential vaults for agents > 9 secrets & credential vaults ranked by the Anchor benchmark. Leader Infisical (A). Stores for API keys and other secrets that an agent or its runtime reads at call time, instead of keeping them in prompts, config files or environment dumps. Compared on access controls, rotation, audit, SDKs and self-hosting. - Canonical: https://www.anchorterminal.com/categories/secrets - Markdown: https://www.anchorterminal.com/categories/secrets.md (~4,200 tokens) - Slim: https://www.anchorterminal.com/categories/secrets.min.md (~530 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/categories/secrets.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-05 Stores for API keys and other secrets that an agent or its runtime reads at call time, instead of keeping them in prompts, config files or environment dumps. Compared on access controls, rotation, audit, SDKs and self-hosting. - Tools ranked: 9 · agent-ready (BB or better): 5 · accept x402: 0 · hosted endpoints: 6 · desk reviews by the panel: 36 - JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability) - Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/ - Capabilities in this category: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, secrets.self-host - https://letme.dev/secrets.store picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md) ## Ranking | # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | 4 | Infisical | Infisical | HTTP API | Secrets | A | 81.9 | medium | no | OAuth or key | hosted + local | 3.8/5 (8) | https://www.anchorterminal.com/tools/infisical.md | | 15 | AWS Secrets Manager | Amazon Web Services | HTTP API | Secrets | A | 78.1 | medium | no | OAuth or key | hosted | 3.9/5 (8) | https://www.anchorterminal.com/tools/aws-secrets-manager.md | | 26 | Google Cloud Secret Manager | Google Cloud | HTTP API | Secrets | BB | 76.6 | medium | no | OAuth | hosted | 3.6/5 (8) | https://www.anchorterminal.com/tools/google-secret-manager.md | | 55 | Akeyless (SecretlessAI and MCP server) | Akeyless | Model platform | Secrets | BB | 73.7 | medium | no | OAuth or key | hosted + local | 3/5 (2) | https://www.anchorterminal.com/tools/akeyless.md | | 79 | Doppler | Doppler | HTTP API | Secrets | BB | 71.6 | medium | no | OAuth or key | hosted + local | 3/5 (2) | https://www.anchorterminal.com/tools/doppler.md | | 104 | 1Password service accounts, SDKs and Environments MCP | 1Password | Model platform | Secrets | B | 69.9 | medium | no | OAuth or key | local | 3.5/5 (2) | https://www.anchorterminal.com/tools/1password.md | | 136 | Azure MCP Server | Microsoft | MCP server | Infra | B | 67.8 | medium | no | OAuth or key | local | 2.5/5 (2) | https://www.anchorterminal.com/tools/azure-mcp.md | | 184 | HashiCorp Vault + Vault MCP Server | HashiCorp (IBM) | HTTP API | Secrets | B | 64.4 | medium | no | OAuth or key | local | 3/5 (2) | https://www.anchorterminal.com/tools/hashicorp-vault.md | | 297 | Bitwarden Secrets Manager | Bitwarden | SDK + MCP | Secrets | C | 57.1 | medium | no | API key | hosted | 2.5/5 (2) | https://www.anchorterminal.com/tools/bitwarden-secrets-manager.md | Scores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet. ## Summaries ### 4. Infisical, A (81.9) Open-source secrets manager with machine identities (Universal Auth, OIDC, AWS, GCP, Azure, Kubernetes, SPIFFE), dynamic secrets, rotation and audit logs, hosted in the US or EU or self-hosted. Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month. - Page: https://www.anchorterminal.com/tools/infisical · Markdown: https://www.anchorterminal.com/tools/infisical.md · JSON: https://www.anchorterminal.com/api/v1/tools/infisical.json - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, secrets.self-host, auth.agent-identity · endpoint: `https://app.infisical.com/api` ### 15. AWS Secrets Manager, A (78.1) Managed secrets store priced per secret and per API call, with IAM for access, KMS for encryption, CloudTrail for audit, cross-region replication and rotation either managed (RDS, Aurora, DocumentDB, Redshift) or by a Lambda function you own. IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads. - Page: https://www.anchorterminal.com/tools/aws-secrets-manager · Markdown: https://www.anchorterminal.com/tools/aws-secrets-manager.md · JSON: https://www.anchorterminal.com/api/v1/tools/aws-secrets-manager.json - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, infra.aws · endpoint: `https://secretsmanager.us-east-1.amazonaws.com` ### 26. Google Cloud Secret Manager, BB (76.6) Google Cloud's managed service for storing and accessing application secrets. Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle. - Page: https://www.anchorterminal.com/tools/google-secret-manager · Markdown: https://www.anchorterminal.com/tools/google-secret-manager.md · JSON: https://www.anchorterminal.com/api/v1/tools/google-secret-manager.json - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, infra.cloud · endpoint: `https://secretmanager.googleapis.com/v1` ### 55. Akeyless (SecretlessAI and MCP server), BB (73.7) SaaS secrets and machine-identity platform with a self-hosted Gateway that brokers access. Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract. - Page: https://www.anchorterminal.com/tools/akeyless · Markdown: https://www.anchorterminal.com/tools/akeyless.md · JSON: https://www.anchorterminal.com/api/v1/tools/akeyless.json - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, auth.agent-identity · endpoint: `https://api.akeyless.io` ### 79. Doppler, BB (71.6) Hosted secrets manager organised by project, environment and config. Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts. - Page: https://www.anchorterminal.com/tools/doppler · Markdown: https://www.anchorterminal.com/tools/doppler.md · JSON: https://www.anchorterminal.com/api/v1/tools/doppler.json - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit · endpoint: `https://api.doppler.com/v3` ### 104. 1Password service accounts, SDKs and Environments MCP, B (69.9) Password manager with a developer layer for agents. Service accounts scoped per vault to read, write or share, with an optional expiry and permissions that can't be changed after creation. Teams, Families and Individual get 1,000 service account reads an hour per token, and the 429 carries no Retry-After. - Page: https://www.anchorterminal.com/tools/1password · Markdown: https://www.anchorterminal.com/tools/1password.md · JSON: https://www.anchorterminal.com/api/v1/tools/1password.json - Capabilities: secrets.store, secrets.machine-identity, secrets.audit ### 136. Azure MCP Server, B (67.8) Microsoft's official local MCP server for Azure (`@azure/mcp`, also on NuGet as Azure.Mcp). Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config. npm `latest` installs a 3.0.0 beta, and betas rename and remove tools without a notice period. - Page: https://www.anchorterminal.com/tools/azure-mcp · Markdown: https://www.anchorterminal.com/tools/azure-mcp.md · JSON: https://www.anchorterminal.com/api/v1/tools/azure-mcp.json - Capabilities: infra.azure, infra.cloud ### 184. HashiCorp Vault + Vault MCP Server, B (64.4) Secrets management platform for storing credentials and controlling application access. Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased. - Page: https://www.anchorterminal.com/tools/hashicorp-vault · Markdown: https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON: https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, secrets.self-host, auth.agent-identity ### 297. Bitwarden Secrets Manager, C (57.1) End-to-end encrypted secrets store from the Bitwarden password manager company. End-to-end encrypted, decrypted only on the client that holds the token. No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024. - Page: https://www.anchorterminal.com/tools/bitwarden-secrets-manager · Markdown: https://www.anchorterminal.com/tools/bitwarden-secrets-manager.md · JSON: https://www.anchorterminal.com/api/v1/tools/bitwarden-secrets-manager.json - Capabilities: secrets.store, secrets.machine-identity, secrets.audit, secrets.self-host · endpoint: `https://api.bitwarden.com` ## How we test this category An agent runtime reads a key at call time with a scoped machine identity, the key is rotated mid-run and access is then revoked. We check the scoping, how rotation lands, what the audit log records and how long each read takes. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence. ## Indexed, not reviewed (30) Sorted into this category from public catalogues, with facts and our own checks but no score, grade or rank (https://www.anchorterminal.com/indexed/index.md). | Listing | Kind | What it does | Why it's here | | --- | --- | --- | --- | | [advisorfinder.com MCP server](https://www.anchorterminal.com/tools/advisorfinder-mcp.md) | MCP server | Search and vet SEC-registered financial advisors: profiles, disclosures, firm fees, credentials. | vendor's own | | [aep](https://www.anchorterminal.com/tools/focusgts-aep.md) | MCP server | Full-CRUD server for AEP, Journey Optimizer and CJA. 61 tools from one OAuth credential. | vendor's own | | [AtlasYield](https://www.anchorterminal.com/tools/atlasyield-mcp.md) | MCP server | DeFi vault judgment for agents: 16-factor Atlas Score, route survival, blowup alerts. Read-only. | vendor's own | | [correctover.com MCP server](https://www.anchorterminal.com/tools/correctover-mcp-server.md) | MCP server | MCP runtime security. 22µs validation, 97% self-healing. Detects RCE, SSRF, credential hijacking. | vendor's own | | [designvault](https://www.anchorterminal.com/tools/designvault.md) | MCP server | Search, browse and manage your DesignVault design-asset library from any MCP client. | vendor's own | | [Draugr](https://www.anchorterminal.com/tools/draugr.md) | MCP server | Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk. | vendor's own | | [envcp](https://www.anchorterminal.com/tools/fentz-envcp.md) | MCP server | Encrypted environment variable vault with AI access policies, keeping secrets safe from AI agents. | vendor's own | | [Flare](https://www.anchorterminal.com/tools/flarehq-security.md) | MCP server | Scan a running app or repo for leaked secrets, exposed routes and open RLS, and verify live keys | vendor's own | | [Graneth](https://www.anchorterminal.com/tools/graneth-mcp-server.md) | MCP server | Pre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account. | vendor's own | | [hush](https://www.anchorterminal.com/tools/royashbrook-hush.md) | MCP server | A secret store for AI agents: the agent never sees the plaintext. | vendor's own | | [IdentArk Gateway](https://www.anchorterminal.com/tools/identark-gateway.md) | MCP server | Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval. | vendor's own | | [jikida.io MCP server](https://www.anchorterminal.com/tools/jikida-mcp.md) | MCP server | Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets. | vendor's own | | [Kolonie AI](https://www.anchorterminal.com/tools/kolonie.md) | MCP server | A colony of AI citizens: join with no credential, prove skills, earn, vote on the rules. | vendor's own | | [marchward.ai MCP server](https://www.anchorterminal.com/tools/marchward-mcp-server.md) | MCP server | Runtime authority for AI agents: credential mediation, spend cap, approval gates, audit log. | vendor's own | | [Opzyai Security Check](https://www.anchorterminal.com/tools/opzyai-mcp.md) | MCP server | Local-first security check for AI coding agents: secrets, .env exposure, git-history leaks, CVEs. | vendor's own | | [paysafe](https://www.anchorterminal.com/tools/paysafe-agent-paysafe.md) | MCP server | Payment firewall for x402: scans for replay, overpayment, PII/secret leaks, prompt-injection. | vendor's own | | [Philidor DeFi Vault Risk Analytics](https://www.anchorterminal.com/tools/philidor-defi-vaults.md) | MCP server | Search 700+ DeFi vaults, compare risk scores, analyze protocols. No API key needed. | vendor's own | | [SEAL](https://www.anchorterminal.com/tools/seal-mcp.md) | MCP server | Large files and secrets between people and agents, never through the chat or the model. | vendor's own, widely used | | [seekrit (local crypto plane)](https://www.anchorterminal.com/tools/seekrit-mcp.md) | MCP server | Zero-knowledge secrets manager — local crypto-plane MCP server: decrypts and injects secrets. | vendor's own | | [ShipSafe — Independent security verification](https://www.anchorterminal.com/tools/ship-safe-scanner.md) | MCP server | Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access. | vendor's own | | [Skarn](https://www.anchorterminal.com/tools/getskarn-skarn.md) | MCP server | Scans AI coding sessions and assistant configs for leaked secrets and risky hooks; local, redacted | vendor's own | | [speedvault.io MCP server](https://www.anchorterminal.com/tools/speedvault-mcp.md) | MCP server | Run web performance audits, get code-level fixes, crawl for SEO, and read real-user Core Web Vitals. | vendor's own | | [TAP](https://www.anchorterminal.com/tools/human-tap.md) | MCP server | Credential isolation for AI agents: placeholder secrets, policy checks, optional human approval. | vendor's own | | [Trestle](https://www.anchorterminal.com/tools/trestlescan-trestle.md) | MCP server | Detects leaked secrets (API keys, tokens, private keys) in source code. | vendor's own | | [Trusty Squire](https://www.anchorterminal.com/tools/trustysquire-trusty-squire.md) | MCP server | Provision, ship, and pay from your coding agent — keys and cards never leave the vault. | vendor's own, widely used | | [unmarking](https://www.anchorterminal.com/tools/unmarking.md) | MCP server | Inspect and remove C2PA content credentials from AI-generated images, video and audio. Free, no key. | vendor's own | | [Uplink](https://www.anchorterminal.com/tools/uplink.md) | MCP server | Automate a real, logged-in browser on your own device — no stored credentials, no bot detection. | vendor's own | | [vault-knowledge](https://www.anchorterminal.com/tools/seanwinslow-vault-knowledge.md) | MCP server | Read-only MCP over a vault's typed knowledge graph: concept search, contradictions, article fetch. | vendor's own | | [wallet](https://www.anchorterminal.com/tools/metamuse-wallet.md) | MCP server | A muse's wallet on Robinhood Chain: stock tokens, USDG payments via rh777, vaults, on-chain ceiling. | vendor's own | | [Yault AESP](https://www.anchorterminal.com/tools/yault-aesp.md) | MCP server | Crypto payments for the agent economy — policy-gated vault operations under human control | vendor's own |