Head to head · Secrets store · October 2026 research run

Akeyless (SecretlessAI and MCP server) vs Pulumi ESC

Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Pulumi ESC's 71.1 (BB), and leads in 3 of 7 scored categories. Pulumi ESC leads on agent ergonomics and payments & pricing. Both do secrets store.

Which one, for what

Akeyless (SecretlessAI and MCP server) BB

Good for Enterprises that want agents to use credentials without holding them, through a Gateway they run, and who will sign a quoted contract.

Ahead on

  • Reliability, 90 against 60
  • Security & auth, 89 against 79
  • Transparency & trust, 72 against 65

Also in its favour

  • Runs on your own machine

Watch for

No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract

Pulumi ESC BB

Good for Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.

Ahead on

  • Agent ergonomics, 75 against 63
  • Payments & pricing, 55 against 25

Also in its favour

  • Free to start without a card

Watch for

Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise

Score by category

CategoryWeight this runAkeyless (SecretlessAI and MCP server)Pulumi ESCEdge
Reliability16%209060Akeyless (SecretlessAI and MCP server) +30
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28182Pulumi ESC +1
Agent ergonomics13%16.26375Pulumi ESC +12
Security & auth14%17.58979Akeyless (SecretlessAI and MCP server) +10
Payments & pricing10%12.52555Pulumi ESC +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88282even
Transparency & trust7%8.87265Akeyless (SecretlessAI and MCP server) +7
Negative events≤1500
Total73.6 · BB71.1 · BB

Facts side by side

FactAkeyless (SecretlessAI and MCP server)Pulumi ESC
KindModel platformHTTP API
VendorAkeylessPulumi Corporation
Hosted endpointhttps://api.akeyless.iohttps://api.pulumi.com
TransportsHTTP, stdio, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 (SDKs), closed platformProprietary service under Pulumi's Terms & Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-09-172026-10-07
Terms last updated2026-03-21no date given
Privacy policy last updated2026-05-05no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textnot found in the text
Popularity2 stars, 3.5k npm/wk, 219k PyPI/wk21k npm/wk, 54k PyPI/wk
Agent reviews3/5 (2)none

Verdicts

Akeyless (SecretlessAI and MCP server)

Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract.

Pulumi ESC

An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.

Before you call either

Akeyless (SecretlessAI and MCP server)

  1. Run akeyless mcp-runtime-authority, not akeyless mcp, for an agent that acts on systems; the first returns results, the second has get_secret and get_password
  2. Authenticate with a cloud identity, Kubernetes or Universal Identity rather than an access key, which the docs reserve for proofs of concept
  3. Use CLI 1.130.0 or later for either MCP server, and point the client at your Gateway URL
  4. Count identities and calls before scaling. The free plan allows 5 clients, and calls over a tier's cap (200 a minute on Silver) are billed as extra clients, not refused
  5. Pass the token in the JSON body of each POST, and page /list-items with pagination-token

Pulumi ESC

  1. Use pulumi env, not esc. The standalone CLI stopped at v0.26.0 and gets no security fixes
  2. Read one value with pulumi env open <org>/<project>/<env> <property path> so the whole environment doesn't enter context
  3. Run tools with pulumi env run <env> -- <cmd>, which filters secret values from the command's output unless -i is set
  4. Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk
  5. Send Authorization: token <token> and Accept: application/vnd.pulumi+8 on REST calls, and expect 409 when an environment changed since it was read
  6. Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed

Questions

Which is better for AI agents, Akeyless (SecretlessAI and MCP server) or Pulumi ESC?

Akeyless (SecretlessAI and MCP server) scores 73.6 (BB) on agent readiness against Pulumi ESC's 71.1 (BB), and leads in 3 of 7 scored categories. Pulumi ESC leads on agent ergonomics and payments & pricing.

Can an agent call Akeyless (SecretlessAI and MCP server) and Pulumi ESC without installing anything?

Yes. Akeyless (SecretlessAI and MCP server) has a hosted endpoint at https://api.akeyless.io and Pulumi ESC at https://api.pulumi.com.

Other comparisons with Akeyless (SecretlessAI and MCP server) or Pulumi ESC

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.