{
  "data": {
    "a": {
      "slug": "akeyless",
      "name": "Akeyless (SecretlessAI and MCP server)",
      "vendor": "Akeyless",
      "vendorUrl": "https://www.akeyless.io",
      "kind": "platform",
      "category": "secrets",
      "summary": "SaaS secrets and machine-identity platform with a self-hosted Gateway that brokers access.",
      "url": "https://www.anchorterminal.com/tools/akeyless",
      "markdownUrl": "https://www.anchorterminal.com/tools/akeyless.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/akeyless.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/akeyless.json",
      "repo": "https://github.com/akeylesslabs/akeyless-python",
      "license": "Apache-2.0 (SDKs), closed platform",
      "transports": [
        "http",
        "stdio",
        "streamable-http"
      ],
      "remoteUrl": "https://api.akeyless.io",
      "packages": [
        {
          "registry": "pypi",
          "name": "akeyless"
        },
        {
          "registry": "npm",
          "name": "akeyless"
        }
      ],
      "auth": "mixed",
      "authNotes": "POST /auth with an access-id and a credential from an access key, AWS IAM, Azure AD, GCP, Kubernetes, OIDC, SAML, LDAP, JWT, certificate, OCI, Kerberos or Universal Identity, returning a token passed in the body of later calls. The docs say API key auth is for proofs of concept, not production, and the access key is shown once. The MCP servers reuse the CLI profile or explicit auth flags and inherit its RBAC.",
      "pricing": "freemium",
      "pricingNotes": "Free and Enterprise plans. The free plan has 5 clients, 500 static secrets, 5 dynamic secrets, 5 rotated secrets, 3 targets, 1 OIDC app, 1 SSH and 1 PKI certificate issuer, 5 managed certificates, 1,000 encryption and KMS transactions a day, 5 KMS keys, 5 password manager users with 5 static and 50 shared passwords, 1 Gateway cluster and 3 days of audit log retention, without SAML, OIDC or LDAP auth, zero-knowledge mode, HSM integration or event forwarding. Enterprise is quoted, with clients and transactions counted at the end of each month and overage billed at the end of the 12-month contract. No dollar figures are published (https://www.akeyless.io/pricing/).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 2,
        "npmWeekly": 3523,
        "pypiWeekly": 219234,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.akeyless.io",
      "llmsTxt": "https://docs.akeyless.io/llms.txt",
      "openapi": "https://github.com/akeylesslabs/akeyless-go/blob/v5/api/openapi.yaml",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "auth.agent-identity"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "freemium",
        "free-tier",
        "mcp",
        "local",
        "python",
        "typescript",
        "go",
        "enterprise"
      ],
      "lastRelease": "2026-09-17",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 73.6,
        "grade": "BB",
        "agentReady": true,
        "rank": 74,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 82,
          "payments": 25,
          "reliability": 90,
          "schema": 81,
          "security": 89,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.",
        "bestFor": "Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.",
        "strengths": [
          "Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials",
          "Runtime Authority intent rules with a kill switch, generally available since 9 September 2026",
          "SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS and FIPS 140-3 validation listed in the trust centre, plus a bug bounty",
          "A 99.99% availability SLA on every support tier, with transaction caps published per tier",
          "OpenAPI 3.0 document for 657 paths in the Go SDK repository, and an llms.txt with about 800 Markdown links"
        ],
        "weaknesses": [
          "No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract",
          "Errors come back as a single `error` string with no code, and no Retry-After or backoff guidance turned up",
          "The free plan has no OIDC, SAML or LDAP auth and keeps audit logs for 3 days",
          "akeyless mcp can return secret values to the model, and neither MCP server has a published tool list, version or registry entry",
          "No security.txt, and the closed CLI and Gateway are the only way to run the MCP servers"
        ],
        "agentNotes": [
          "Run akeyless mcp-runtime-authority, not akeyless mcp, for an agent that acts on systems; the first returns results, the second has get_secret and get_password",
          "Authenticate with a cloud identity, Kubernetes or Universal Identity rather than an access key, which the docs reserve for proofs of concept",
          "Use CLI 1.130.0 or later for either MCP server, and point the client at your Gateway URL",
          "Count identities and calls before scaling. The free plan allows 5 clients, and calls over a tier's cap (200 a minute on Silver) are billed as extra clients, not refused",
          "Pass the token in the JSON body of each POST, and page `/list-items` with `pagination-token`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 73.6
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 82,
          "payments": 25,
          "reliability": 90,
          "schema": 81,
          "security": 89,
          "transparency": 71
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "pip install akeyless   # or: npm i akeyless",
        "http": "TOKEN=$(curl -s -X POST https://api.akeyless.io/auth -H \"Content-Type: application/json\" \\\n  -d \"{\\\"access-id\\\":\\\"$AKEYLESS_ACCESS_ID\\\",\\\"access-key\\\":\\\"$AKEYLESS_ACCESS_KEY\\\"}\" | jq -r .token)\ncurl -s -X POST https://api.akeyless.io/get-secret-value -H \"Content-Type: application/json\" \\\n  -d \"{\\\"names\\\":[\\\"/prod/db-password\\\"],\\\"token\\\":\\\"$TOKEN\\\"}\"",
        "claudeCode": "claude mcp add akeyless -- akeyless mcp-runtime-authority",
        "config": {
          "mcpServers": {
            "akeyless": {
              "args": [
                "mcp-runtime-authority"
              ],
              "command": "akeyless"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/akeyless"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Akeyless Security Ltd.",
        "domain": "akeyless.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.akeyless.io/terms-of-service/",
        "privacy": "https://www.akeyless.io/privacy-policy/",
        "statusPage": "https://status.akeyless.io",
        "changelog": "https://changelog.akeyless.io/cli",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "Website terms (21 March 2026) and privacy policy (5 May 2026) name Akeyless Security Ltd., Ze'ev Jabotinsky St. 7, Ramat Gan, Israel, with a US subsidiary Akeyless Security USA, Inc. The terms cover the website only; the service runs under a separate licence or master services agreement.",
          "www.akeyless.io/.well-known/security.txt returned 404 when checked on 30 September 2026.",
          "The .io RDAP servers answered 429 and a robots.txt failure, so the registration date is blank.",
          "The status page history shows one incident since 3 July 2026, 21 minutes of degraded dynamic secret performance in us-east-2 on 23 September, and a scheduled maintenance window on 19 July.",
          "The CLI changelog at changelog.akeyless.io dates each release, 1.152.0 on 16 September 2026 being the newest."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/akeyless.json",
      "live": {
        "slug": "akeyless",
        "probe": {
          "target": "https://api.akeyless.io",
          "method": "get",
          "lastAt": "2026-10-09T01:12:39.016519607Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 44,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 50,
          "p95ms24h": 103,
          "samples24h": 267,
          "samples30d": 1997,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 13,
              "ok": 13
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.akeyless.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T01:07:18.402609731Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "akeyless",
            "version": "5.0.39",
            "seenAt": "2026-10-08T15:57:22.638958691Z"
          },
          {
            "registry": "pypi",
            "name": "akeyless",
            "version": "5.0.39",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T15:57:19.679296437Z"
          }
        ],
        "githubStars": 2,
        "npmWeekly": 3587,
        "pypiWeekly": 192330,
        "securityTxt": {
          "url": "https://akeyless.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:50.161949588Z"
        },
        "llmsTxt": {
          "url": "https://docs.akeyless.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T13:59:59.863503602Z"
        },
        "domain": {
          "domain": "akeyless.io",
          "checkedAt": "2026-10-04T13:09:25.717264008Z"
        },
        "pages": [
          {
            "url": "https://changelog.akeyless.io/cli",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:16:06.245599167Z",
            "changedAt": "2026-10-07T18:03:10.44050169Z",
            "fingerprint": "f0221e37b77a"
          },
          {
            "url": "https://www.akeyless.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:04.908061169Z",
            "changedAt": "2026-10-03T15:36:56.900207187Z",
            "fingerprint": "23bd00d937d2"
          },
          {
            "url": "https://www.akeyless.io/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:07.401360347Z",
            "changedAt": "2026-10-03T15:36:59.079097768Z",
            "fingerprint": "ae198dd0fa22"
          },
          {
            "url": "https://www.akeyless.io/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:10.020038635Z",
            "changedAt": "2026-10-03T15:37:02.238780939Z",
            "fingerprint": "32e16cb5a55b"
          }
        ],
        "updatedAt": "2026-10-09T01:12:39.016519607Z"
      }
    },
    "answer": "Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories.",
    "b": {
      "slug": "phase",
      "name": "Phase",
      "vendor": "Phi Security Inc.",
      "vendorUrl": "https://phase.dev",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Phase is an open-source secrets manager from Phi Security Inc. with end-to-end encryption, service accounts, secret rotation and audit logs. Agents reach it through a REST API, a CLI and SDKs, on Phase Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/phase",
      "markdownUrl": "https://www.anchorterminal.com/tools/phase.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/phase.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/phase.json",
      "repo": "https://github.com/phasehq/console",
      "license": "MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.phase.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@phase.dev/phase-node"
        },
        {
          "registry": "pypi",
          "name": "phase-dev"
        },
        {
          "registry": "go",
          "name": "github.com/phasehq/golang-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs in to the console with Google, GitHub or GitLab, creates a service account and a token with an optional expiry, and the agent sends it as `Authorization: Bearer ServiceAccount \u003ctoken\u003e`. Personal access tokens use `Bearer User \u003ctoken\u003e` and inherit the user's role. Tokens can also be created and deleted over the API for service accounts with server-side key management. Workloads on AWS or Azure can log in with an external identity and receive a token with a TTL. Access follows the account's role and its apps and environments, not the individual token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 5 users or service accounts, 3 apps, 3 environments, 24-hour audit logs and 120 API requests a minute. Pro is $10 a user a month ($120 billed yearly) with a 14-day trial, unlimited apps, rotation, custom roles, network access policies, 90-day audit logs and 240 requests a minute. Enterprise is $25 a user a month ($300 yearly) with dynamic secrets, OIDC SSO, SCIM, log forwarding and a 99.99 per cent uptime SLA listed. Only human users are charged, and service accounts are free. The pricing page does not say whether a card is taken. Self-hosting the MIT core is free, and the Pro and Enterprise tiers need a licence (https://phase.dev/pricing/).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the API reference or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 928,
        "npmWeekly": 2485,
        "pypiWeekly": 235,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.phase.dev",
      "llmsTxt": "https://docs.phase.dev/llms.txt",
      "capabilities": [
        "secrets.store",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "secrets.rotate"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "cli",
        "llms-txt",
        "go",
        "typescript",
        "python",
        "eu",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-04",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 194,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 56,
          "maintenance": 83,
          "payments": 25,
          "reliability": 91,
          "schema": 58,
          "security": 83,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.",
        "bestFor": "Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.",
        "strengths": [
          "Service account tokens take an expiry and can be created and deleted through `/v1/service-accounts/:id/tokens`, and service accounts are free on every plan",
          "The CLI's AI mode redacts `secret` and `sealed` values and blocks `printenv`, `env` and `phase shell` when it detects an agent",
          "Every reveal and every REST fetch of a secret is recorded as a `READ` event with actor and IP address",
          "MIT outside the `ee/` directories, self-hosted with Docker Compose or Kubernetes, with no outbound usage telemetry per the docs",
          "Eleven console versions between 24 July and 8 October 2026, and no incident on the status page since 30 June 2026"
        ],
        "weaknesses": [
          "No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations",
          "No pagination, field selection or idempotency keys were found in the API reference, and errors are a single free-text `error` string",
          "The Free plan keeps audit logs for 24 hours. Rotation, custom roles and network access policies need Pro, and dynamic secrets need Enterprise",
          "The REST API works only on apps with server-side encryption enabled, which gives up end-to-end encryption for that app",
          "The pricing page lists a Phase Agents Relay credential proxy on every plan, but no documentation or CLI command for it was found"
        ],
        "agentNotes": [
          "Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets",
          "Send `Authorization: Bearer ServiceAccount \u003ctoken\u003e` for a service account and `Bearer User \u003ctoken\u003e` for a personal access token. The token type is part of the header",
          "Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429",
          "Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE`",
          "Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 56,
          "maintenance": 83,
          "payments": 25,
          "reliability": 91,
          "schema": 58,
          "security": 83,
          "transparency": 58
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "curl -fsSL https://pkg.phase.dev/install.sh | sh   # or: brew tap phasehq/cli \u0026\u0026 brew install phase",
        "http": "curl -G https://api.phase.dev/v1/secrets/ -H \"Authorization: Bearer ServiceAccount $PHASE_TOKEN\" \\\n  -d app_id=$PHASE_APP_ID -d env=development",
        "claudeCode": "phase ai enable"
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/phase"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 10,
          "note": "$120 a user billed yearly. Service accounts free"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "$300 a user billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Phi Security Inc.",
        "domain": "phase.dev",
        "domainRegistered": "2023-02-03",
        "endpointOnVendorDomain": true,
        "terms": "https://phase.dev/legal/terms/",
        "privacy": "https://phase.dev/legal/privacy/",
        "statusPage": "https://phase.statuspage.io",
        "changelog": "https://phase.dev/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 6 October 2025) name Phi Security Inc. and cover the website, the Phase Console and the self-hosted version. The site footer gives 8 The Green, Ste A, Dover, DE 19901, United States.",
          "The privacy policy (last updated 11 March 2026) covers phase.dev and the services, gives no retention period in days and refers to the trust centre for the subprocessor list.",
          "security.txt at phase.dev expires on 10 December 2030, lists three contact addresses and points to `SECURITY.md` in the console repository.",
          "trust.phase.dev is drawn by script and gave our reader no text, so the subprocessor list and any DPA were not read.",
          "RDAP for phase.dev gives a registration date of 2023-02-03.",
          "The status page is an Atlassian Statuspage at phase.statuspage.io with components for the console, the API, Cloudflare and AWS eu-central-1."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/phase.json",
      "live": {
        "slug": "phase",
        "probe": {
          "target": "https://api.phase.dev",
          "method": "get",
          "lastAt": "2026-10-09T01:12:54.002999851Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 124,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 117,
          "p95ms24h": 175,
          "samples24h": 63,
          "samples30d": 63,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 13,
              "ok": 13
            }
          ]
        },
        "vendorStatus": {
          "page": "https://phase.statuspage.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T01:07:47.27786387Z"
        },
        "updatedAt": "2026-10-09T01:12:54.002999851Z"
      }
    },
    "facts": [
      {
        "a": "Model platform",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Akeyless",
        "b": "Phi Security Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://api.akeyless.io",
        "b": "https://api.phase.dev",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (SDKs), closed platform",
        "b": "MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-17",
        "b": "2026-10-04",
        "name": "Last release"
      },
      {
        "a": "2026-03-21",
        "b": "2025-10-06",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-05",
        "b": "2026-03-11",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "2 stars, 3.5k npm/wk, 219k PyPI/wk",
        "b": "928 stars, 2.5k npm/wk, 235 PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories.",
        "question": "Which is better for AI agents, Akeyless (SecretlessAI and MCP server) or Phase?"
      },
      {
        "answer": "Yes. Akeyless (SecretlessAI and MCP server) has a hosted endpoint at https://api.akeyless.io and Phase at https://api.phase.dev.",
        "question": "Can an agent call Akeyless (SecretlessAI and MCP server) and Phase without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Akeyless (SecretlessAI and MCP server). Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).",
        "question": "Are Akeyless (SecretlessAI and MCP server) and Phase open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 81 against 58",
          "Agent ergonomics, 63 against 56",
          "Security \u0026 auth, 89 against 83"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Runs on your own machine"
        ],
        "goodFor": "Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.",
        "slug": "akeyless",
        "watchFor": "No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract"
      },
      {
        "aheadOn": null,
        "also": [
          "Open source"
        ],
        "goodFor": "Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.",
        "slug": "phase",
        "watchFor": "No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations"
      }
    ],
    "job": {
      "capability": "secrets.store",
      "name": "Secrets store"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-akeyless.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs Akeyless (SecretlessAI and MCP server)",
        "url": "https://www.anchorterminal.com/compare/1password-vs-akeyless"
      },
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-phase.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs Phase",
        "url": "https://www.anchorterminal.com/compare/1password-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-aws-secrets-manager.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs AWS Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-aws-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-azure-key-vault.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Azure Key Vault",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-azure-key-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-bitwarden-secrets-manager.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Bitwarden Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-bitwarden-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-doppler.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Doppler",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-doppler"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-infisical.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Infisical",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-infisical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-pulumi-esc.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-pulumi-esc"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.json",
        "title": "AWS Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.json",
        "title": "Azure Key Vault vs Phase",
        "url": "https://www.anchorterminal.com/compare/azure-key-vault-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.json",
        "title": "Bitwarden Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/doppler-vs-phase.json",
        "title": "Doppler vs Phase",
        "url": "https://www.anchorterminal.com/compare/doppler-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.json",
        "title": "Google Cloud Secret Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.json",
        "title": "HashiCorp Vault + Vault MCP Server vs Phase",
        "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/infisical-vs-phase.json",
        "title": "Infisical vs Phase",
        "url": "https://www.anchorterminal.com/compare/infisical-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.json",
        "title": "Keeper Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.json",
        "title": "Phase vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/phase-vs-pulumi-esc"
      }
    ],
    "scores": [
      {
        "akeyless": 90,
        "by": 1,
        "edge": "phase",
        "key": "reliability",
        "name": "Reliability",
        "phase": 91,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "akeyless": 81,
        "by": 23,
        "edge": "akeyless",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "phase": 58,
        "weight": 13
      },
      {
        "akeyless": 63,
        "by": 7,
        "edge": "akeyless",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "phase": 56,
        "weight": 13
      },
      {
        "akeyless": 89,
        "by": 6,
        "edge": "akeyless",
        "key": "security",
        "name": "Security \u0026 auth",
        "phase": 83,
        "weight": 14
      },
      {
        "akeyless": 25,
        "by": 0,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "phase": 25,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "akeyless": 82,
        "by": 1,
        "edge": "phase",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "phase": 83,
        "weight": 7
      },
      {
        "akeyless": 72,
        "by": 1,
        "edge": "phase",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "phase": 73,
        "weight": 7
      }
    ],
    "summary": "Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Both do secrets store.",
    "verdicts": {
      "akeyless": "Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.",
      "phase": "Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/akeyless-vs-phase",
    "json": "https://www.anchorterminal.com/compare/akeyless-vs-phase.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/akeyless-vs-phase.md",
    "slim": "https://www.anchorterminal.com/compare/akeyless-vs-phase.min.md"
  },
  "markdown": "Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Both do secrets store.\n\n- Akeyless (SecretlessAI and MCP server): grade BB, 73.6/100, rank #74 of 722. Markdown https://www.anchorterminal.com/tools/akeyless.md · JSON https://www.anchorterminal.com/api/v1/tools/akeyless.json\n- Phase: grade B, 68/100, rank #194 of 722. Markdown https://www.anchorterminal.com/tools/phase.md · JSON https://www.anchorterminal.com/api/v1/tools/phase.json\n\n## Which one, for what\n\n### Akeyless (SecretlessAI and MCP server) (BB)\n\nGood for: Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.\n\nAhead on:\n- Schema \u0026 documentation, 81 against 58\n- Agent ergonomics, 63 against 56\n- Security \u0026 auth, 89 against 83\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Runs on your own machine\n\nWatch for: No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract\n\n### Phase (B)\n\nGood for: Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.\n\nAlso in its favour:\n- Open source\n\nWatch for: No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations\n\n\n## Score by category\n\n| Category | Weight | Akeyless (SecretlessAI and MCP server) | Phase | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 90 | 91 | Phase +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 58 | Akeyless (SecretlessAI and MCP server) +23 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 56 | Akeyless (SecretlessAI and MCP server) +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 89 | 83 | Akeyless (SecretlessAI and MCP server) +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 25 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 82 | 83 | Phase +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 73 | Phase +1 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **73.6 · BB** | **68 · B** | |\n\n## Facts side by side\n\n| Fact | Akeyless (SecretlessAI and MCP server) | Phase |\n| --- | --- | --- |\n| Kind | Model platform | HTTP API |\n| Vendor | Akeyless | Phi Security Inc. |\n| Hosted endpoint | `https://api.akeyless.io` | `https://api.phase.dev` |\n| Transports | HTTP, stdio, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (SDKs), closed platform | MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-17 | 2026-10-04 |\n| Terms last updated | 2026-03-21 | 2025-10-06 |\n| Privacy policy last updated | 2026-05-05 | 2026-03-11 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 2 stars, 3.5k npm/wk, 219k PyPI/wk | 928 stars, 2.5k npm/wk, 235 PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Akeyless (SecretlessAI and MCP server).** Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.\n\n**Phase.** Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.\n\n## Before you call either\n\n### Akeyless (SecretlessAI and MCP server)\n\n1. Run akeyless mcp-runtime-authority, not akeyless mcp, for an agent that acts on systems; the first returns results, the second has get_secret and get_password\n2. Authenticate with a cloud identity, Kubernetes or Universal Identity rather than an access key, which the docs reserve for proofs of concept\n3. Use CLI 1.130.0 or later for either MCP server, and point the client at your Gateway URL\n4. Count identities and calls before scaling. The free plan allows 5 clients, and calls over a tier's cap (200 a minute on Silver) are billed as extra clients, not refused\n5. Pass the token in the JSON body of each POST, and page `/list-items` with `pagination-token`\n\n### Phase\n\n1. Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets\n2. Send `Authorization: Bearer ServiceAccount \u003ctoken\u003e` for a service account and `Bearer User \u003ctoken\u003e` for a personal access token. The token type is part of the header\n3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429\n4. Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE`\n5. Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself\n\n## Questions\n\n### Which is better for AI agents, Akeyless (SecretlessAI and MCP server) or Phase?\n\nAkeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories.\n\n### Can an agent call Akeyless (SecretlessAI and MCP server) and Phase without installing anything?\n\nYes. Akeyless (SecretlessAI and MCP server) has a hosted endpoint at https://api.akeyless.io and Phase at https://api.phase.dev.\n\n### Are Akeyless (SecretlessAI and MCP server) and Phase open source?\n\nNo open-source release is listed for Akeyless (SecretlessAI and MCP server). Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/akeyless-vs-phase.json, and with the fewest tokens: https://www.anchorterminal.com/compare/akeyless-vs-phase.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"akeyless\", \"b\": \"phase\"}`. From a terminal: `anchor compare akeyless phase`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/akeyless.json and https://www.anchorterminal.com/api/v1/tools/phase.json\n\n## Other comparisons with Akeyless (SecretlessAI and MCP server) or Phase\n\n- [1Password service accounts, SDKs and Environments MCP vs Akeyless (SecretlessAI and MCP server)](https://www.anchorterminal.com/compare/1password-vs-akeyless.md)\n- [1Password service accounts, SDKs and Environments MCP vs Phase](https://www.anchorterminal.com/compare/1password-vs-phase.md)\n- [Akeyless (SecretlessAI and MCP server) vs AWS Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-aws-secrets-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Azure Key Vault](https://www.anchorterminal.com/compare/akeyless-vs-azure-key-vault.md)\n- [Akeyless (SecretlessAI and MCP server) vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-bitwarden-secrets-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Doppler](https://www.anchorterminal.com/compare/akeyless-vs-doppler.md)\n- [Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md)\n- [Akeyless (SecretlessAI and MCP server) vs Infisical](https://www.anchorterminal.com/compare/akeyless-vs-infisical.md)\n- [Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Pulumi ESC](https://www.anchorterminal.com/compare/akeyless-vs-pulumi-esc.md)\n- [AWS Secrets Manager vs Phase](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.md)\n- [Azure Key Vault vs Phase](https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.md)\n- [Bitwarden Secrets Manager vs Phase](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.md)\n- [Doppler vs Phase](https://www.anchorterminal.com/compare/doppler-vs-phase.md)\n- [Google Cloud Secret Manager vs Phase](https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.md)\n- [HashiCorp Vault + Vault MCP Server vs Phase](https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.md)\n- [Infisical vs Phase](https://www.anchorterminal.com/compare/infisical-vs-phase.md)\n- [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md)\n- [Phase vs Pulumi ESC](https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Akeyless (SecretlessAI and MCP server) vs Phase",
        "url": ""
      }
    ],
    "description": "Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Both do secrets store. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Akeyless (SecretlessAI and MCP server) BB 73.6",
      "Phase B 68",
      "scores"
    ],
    "h1": "Akeyless (SecretlessAI and MCP server) vs Phase",
    "image": "https://www.anchorterminal.com/assets/og/compare-akeyless-vs-phase.png",
    "path": "/compare/akeyless-vs-phase",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Akeyless (SecretlessAI and MCP server) vs Phase for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/akeyless-vs-phase"
  },
  "tokens": {
    "markdown": 2550,
    "slim": 680
  },
  "version": 1
}
