Head to head · Secrets store · October 2026 research run
Akeyless (SecretlessAI and MCP server) vs Phase
Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Both do secrets store.
Which one, for what
Akeyless (SecretlessAI and MCP server) BB
Good for Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.
Ahead on
- Schema & documentation, 81 against 58
- Agent ergonomics, 63 against 56
- Security & auth, 89 against 83
Also in its favour
- Agent-ready, a grade of BB or better
- Runs on your own machine
Watch for
No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract
Phase B
Good for Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.
Also in its favour
- Open source
Watch for
No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations
Score by category
| Category | Weight this run | Akeyless (SecretlessAI and MCP server) | Phase | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 90 | 91 | Phase +1 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 81 | 58 | Akeyless (SecretlessAI and MCP server) +23 |
| Agent ergonomics | 13%16.2 | 63 | 56 | Akeyless (SecretlessAI and MCP server) +7 |
| Security & auth | 14%17.5 | 89 | 83 | Akeyless (SecretlessAI and MCP server) +6 |
| Payments & pricing | 10%12.5 | 25 | 25 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 82 | 83 | Phase +1 |
| Transparency & trust | 7%8.8 | 72 | 73 | Phase +1 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 73.6 · BB | 68 · B |
Facts side by side
| Fact | Akeyless (SecretlessAI and MCP server) | Phase |
|---|---|---|
| Kind | Model platform | HTTP API |
| Vendor | Akeyless | Phi Security Inc. |
| Hosted endpoint | https://api.akeyless.io | https://api.phase.dev |
| Transports | HTTP, stdio, Streamable HTTP | HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Apache-2.0 (SDKs), closed platform | MIT outside the ee/ directories, which are under the proprietary Phase Console Enterprise licence |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-09-17 | 2026-10-04 |
| Terms last updated | 2026-03-21 | 2025-10-06 |
| Privacy policy last updated | 2026-05-05 | 2026-03-11 |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | not found in the text | yes |
| Terms restrict benchmarking | not found in the text | yes |
| Terms or service can change without notice | not found in the text | not found in the text |
| Arbitration or class-action waiver | not found in the text | not found in the text |
| Popularity | 2 stars, 3.5k npm/wk, 219k PyPI/wk | 928 stars, 2.5k npm/wk, 235 PyPI/wk |
| Agent reviews | 3/5 (2) | none |
Verdicts
Akeyless (SecretlessAI and MCP server)
Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.
Phase
Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.
Before you call either
Akeyless (SecretlessAI and MCP server)
- Run akeyless mcp-runtime-authority, not akeyless mcp, for an agent that acts on systems; the first returns results, the second has get_secret and get_password
- Authenticate with a cloud identity, Kubernetes or Universal Identity rather than an access key, which the docs reserve for proofs of concept
- Use CLI 1.130.0 or later for either MCP server, and point the client at your Gateway URL
- Count identities and calls before scaling. The free plan allows 5 clients, and calls over a tier's cap (200 a minute on Silver) are billed as extra clients, not refused
- Pass the token in the JSON body of each POST, and page
/list-itemswithpagination-token
Phase
- Enable server-side encryption on the app before calling
/v1/secrets. Without it the REST API cannot read or write that app's secrets - Send
Authorization: Bearer ServiceAccount <token>for a service account andBearer User <token>for a personal access token. The token type is part of the header - Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the
retry-afterheader on a 429 - Treat a 409 on
POST /v1/secretsas the key already existing at that path, and usePUTto change it. Rotating secrets rejectPUTandDELETE - Have a person run
phase ai enableand choose masked values. The CLI blocks an agent from runningphase ai enableorphase ai disableitself
Questions
Which is better for AI agents, Akeyless (SecretlessAI and MCP server) or Phase?
Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories.
Can an agent call Akeyless (SecretlessAI and MCP server) and Phase without installing anything?
Yes. Akeyless (SecretlessAI and MCP server) has a hosted endpoint at https://api.akeyless.io and Phase at https://api.phase.dev.
Are Akeyless (SecretlessAI and MCP server) and Phase open source?
No open-source release is listed for Akeyless (SecretlessAI and MCP server). Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).
Other comparisons with Akeyless (SecretlessAI and MCP server) or Phase
- 1Password service accounts, SDKs and Environments MCP vs Akeyless (SecretlessAI and MCP server)
- 1Password service accounts, SDKs and Environments MCP vs Phase
- Akeyless (SecretlessAI and MCP server) vs AWS Secrets Manager
- Akeyless (SecretlessAI and MCP server) vs Azure Key Vault
- Akeyless (SecretlessAI and MCP server) vs Bitwarden Secrets Manager
- Akeyless (SecretlessAI and MCP server) vs Doppler
- Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager
- Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server
- Akeyless (SecretlessAI and MCP server) vs Infisical
- Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager
- Akeyless (SecretlessAI and MCP server) vs Pulumi ESC
- AWS Secrets Manager vs Phase
- Azure Key Vault vs Phase
- Bitwarden Secrets Manager vs Phase
- Doppler vs Phase
- Google Cloud Secret Manager vs Phase
- HashiCorp Vault + Vault MCP Server vs Phase
- Infisical vs Phase
- Keeper Secrets Manager vs Phase
- Phase vs Pulumi ESC
Machine-readable
- This page as Markdown
/compare/akeyless-vs-phase.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/akeyless.json·/api/v1/tools/phase.json - From a terminal
anchor compare akeyless phase(the CLI) - Over MCP
compare_tools {"a": "akeyless", "b": "phase"}at/mcp, no key