Head to head · Secrets store · October 2026 research run

Akeyless (SecretlessAI and MCP server) vs Phase

Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Both do secrets store.

Which one, for what

Akeyless (SecretlessAI and MCP server) BB

Good for Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.

Ahead on

  • Schema & documentation, 81 against 58
  • Agent ergonomics, 63 against 56
  • Security & auth, 89 against 83

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine

Watch for

No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract

Phase B

Good for Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.

Also in its favour

  • Open source

Watch for

No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations

Score by category

CategoryWeight this runAkeyless (SecretlessAI and MCP server)PhaseEdge
Reliability16%209091Phase +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28158Akeyless (SecretlessAI and MCP server) +23
Agent ergonomics13%16.26356Akeyless (SecretlessAI and MCP server) +7
Security & auth14%17.58983Akeyless (SecretlessAI and MCP server) +6
Payments & pricing10%12.52525even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88283Phase +1
Transparency & trust7%8.87273Phase +1
Negative events≤1500
Total73.6 · BB68 · B

Facts side by side

FactAkeyless (SecretlessAI and MCP server)Phase
KindModel platformHTTP API
VendorAkeylessPhi Security Inc.
Hosted endpointhttps://api.akeyless.iohttps://api.phase.dev
TransportsHTTP, stdio, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 (SDKs), closed platformMIT outside the ee/ directories, which are under the proprietary Phase Console Enterprise licence
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-172026-10-04
Terms last updated2026-03-212025-10-06
Privacy policy last updated2026-05-052026-03-11
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity2 stars, 3.5k npm/wk, 219k PyPI/wk928 stars, 2.5k npm/wk, 235 PyPI/wk
Agent reviews3/5 (2)none

Verdicts

Akeyless (SecretlessAI and MCP server)

Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.

Phase

Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.

Before you call either

Akeyless (SecretlessAI and MCP server)

  1. Run akeyless mcp-runtime-authority, not akeyless mcp, for an agent that acts on systems; the first returns results, the second has get_secret and get_password
  2. Authenticate with a cloud identity, Kubernetes or Universal Identity rather than an access key, which the docs reserve for proofs of concept
  3. Use CLI 1.130.0 or later for either MCP server, and point the client at your Gateway URL
  4. Count identities and calls before scaling. The free plan allows 5 clients, and calls over a tier's cap (200 a minute on Silver) are billed as extra clients, not refused
  5. Pass the token in the JSON body of each POST, and page /list-items with pagination-token

Phase

  1. Enable server-side encryption on the app before calling /v1/secrets. Without it the REST API cannot read or write that app's secrets
  2. Send Authorization: Bearer ServiceAccount <token> for a service account and Bearer User <token> for a personal access token. The token type is part of the header
  3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the retry-after header on a 429
  4. Treat a 409 on POST /v1/secrets as the key already existing at that path, and use PUT to change it. Rotating secrets reject PUT and DELETE
  5. Have a person run phase ai enable and choose masked values. The CLI blocks an agent from running phase ai enable or phase ai disable itself

Questions

Which is better for AI agents, Akeyless (SecretlessAI and MCP server) or Phase?

Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories.

Can an agent call Akeyless (SecretlessAI and MCP server) and Phase without installing anything?

Yes. Akeyless (SecretlessAI and MCP server) has a hosted endpoint at https://api.akeyless.io and Phase at https://api.phase.dev.

Are Akeyless (SecretlessAI and MCP server) and Phase open source?

No open-source release is listed for Akeyless (SecretlessAI and MCP server). Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).

Other comparisons with Akeyless (SecretlessAI and MCP server) or Phase

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.