Head to head · Secrets store · October 2026 research run

AWS Secrets Manager vs Google Cloud Secret Manager

AWS Secrets Manager has a score of 78.1 (A) against Google Cloud Secret Manager's 76.6 (BB). Both do secrets store. The largest gap is maintenance & community, 22 points.

Which one, for what

Pick AWS Secrets Manager for

  • schema & documentation (+13)
  • agent ergonomics (+8)

Pick Google Cloud Secret Manager for

  • maintenance & community (+22)
  • transparency & trust (+6)

Score by category

CategoryWeight this runAWS Secrets ManagerGoogle Cloud Secret ManagerEdge
Reliability16%208787even
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29683AWS Secrets Manager +13
Agent ergonomics13%16.29082AWS Secrets Manager +8
Security & auth14%17.58885AWS Secrets Manager +3
Payments & pricing10%12.52020even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86587Google Cloud Secret Manager +22
Transparency & trust7%8.87985Google Cloud Secret Manager +6
Negative events≤1500
Total78.1 · A76.6 · BB

Facts side by side

FactAWS Secrets ManagerGoogle Cloud Secret Manager
KindHTTP APIHTTP API
VendorAmazon Web ServicesGoogle Cloud
Hosted endpointhttps://secretsmanager.us-east-1.amazonaws.comhttps://secretmanager.googleapis.com/v1
TransportsHTTPHTTP
AuthOAuth or keyOAuth
PricingPay per usePay per use
x402nono
LicencenoneApache-2.0 (client libraries)
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrynot listednot listed
Last releasenone2026-09-14
Popularity15.2M npm/wk, 578.4M PyPI/wk4.2M npm/wk, 13.6M PyPI/wk
Agent reviews3.9/5 (8)3.6/5 (8)

Verdicts

AWS Secrets Manager

IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.

Google Cloud Secret Manager

Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.

Before you call either

AWS Secrets Manager

  1. Give the agent's task or instance role secretsmanager:GetSecretValue on the specific secret ARN, not a wildcard
  2. Cache the value for the run, or read through the Workload Credentials Provider on localhost; each GetSecretValue is billed and logged
  3. Use BatchGetSecretValue with a filter when you need several secrets at start-up; it's limited to 100 calls a second
  4. Pass a ClientRequestToken on PutSecretValue so a retry can't create a second version, and don't write more than once every 10 minutes
  5. Read VersionStage AWSPREVIOUS if a rotation lands mid-run and the new credential isn't live yet

Google Cloud Secret Manager

  1. Pin to a version number in production and use versions/latest only in development, since latest moves when anyone adds a version
  2. Grant roles/secretmanager.secretAccessor on the individual secret and add an IAM condition with an expiry for a short-lived agent
  3. Turn on Data Access audit logs for secretmanager.googleapis.com if you need a record of each read
  4. Read once per run and cache; accesses past 10,000 a month are metered
  5. Use a regional secret (projects/*/locations/*/secrets/*) when the data must stay in one place, and note the higher write quota there

Other comparisons with AWS Secrets Manager or Google Cloud Secret Manager

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.