Head to head · Secrets store · October 2026 research run
AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server
AWS Secrets Manager has a score of 78.1 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 26 points.
Which one, for what
Pick AWS Secrets Manager for
- reliability (+16)
- schema & documentation (+22)
- agent ergonomics (+26)
Pick HashiCorp Vault + Vault MCP Server for
- payments & pricing (+10)
- maintenance & community (+12)
Score by category
| Category | Weight this run | AWS Secrets Manager | HashiCorp Vault + Vault MCP Server | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 87 | 71 | AWS Secrets Manager +16 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 96 | 74 | AWS Secrets Manager +22 |
| Agent ergonomics | 13%16.2 | 90 | 64 | AWS Secrets Manager +26 |
| Security & auth | 14%17.5 | 88 | 86 | AWS Secrets Manager +2 |
| Payments & pricing | 10%12.5 | 20 | 30 | HashiCorp Vault + Vault MCP Server +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 65 | 77 | HashiCorp Vault + Vault MCP Server +12 |
| Transparency & trust | 7%8.8 | 79 | 83 | HashiCorp Vault + Vault MCP Server +4 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 78.1 · A | 64.4 · B |
Facts side by side
| Fact | AWS Secrets Manager | HashiCorp Vault + Vault MCP Server |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Amazon Web Services | HashiCorp (IBM) |
| Hosted endpoint | https://secretsmanager.us-east-1.amazonaws.com | no (local only) |
| Transports | HTTP | HTTP, stdio, Streamable HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Pay per use | Freemium |
| x402 | no | no |
| Licence | none | BUSL-1.1 (Vault), MPL-2.0 (MCP server) |
| Tools exposed | none | 16 |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| MCP registry | not listed | not listed |
| Last release | none | 2026-09-16 |
| Popularity | 15.2M npm/wk, 578.4M PyPI/wk | 36k stars |
| Agent reviews | 3.9/5 (8) | 3/5 (2) |
Verdicts
AWS Secrets Manager
IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.
HashiCorp Vault + Vault MCP Server
Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.
Before you call either
AWS Secrets Manager
- Give the agent's task or instance role secretsmanager:GetSecretValue on the specific secret ARN, not a wildcard
- Cache the value for the run, or read through the Workload Credentials Provider on localhost; each GetSecretValue is billed and logged
- Use BatchGetSecretValue with a filter when you need several secrets at start-up; it's limited to 100 calls a second
- Pass a ClientRequestToken on PutSecretValue so a retry can't create a second version, and don't write more than once every 10 minutes
- Read VersionStage AWSPREVIOUS if a rotation lands mid-run and the new credential isn't live yet
HashiCorp Vault + Vault MCP Server
- Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call
- Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request
- For KV v2, GET /v1/<mount>/data/<path> and read data.data, and pass cas on writes so a retry can't overwrite a newer version
- If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount
- Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After
Other comparisons with AWS Secrets Manager or HashiCorp Vault + Vault MCP Server
- 1Password service accounts, SDKs and Environments MCP vs AWS Secrets Manager
- 1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server
- Akeyless (SecretlessAI and MCP server) vs AWS Secrets Manager
- Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server
- AWS Secrets Manager vs Bitwarden Secrets Manager
- AWS Secrets Manager vs Doppler
- AWS Secrets Manager vs Google Cloud Secret Manager
- AWS Secrets Manager vs Infisical
- Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server
- Doppler vs HashiCorp Vault + Vault MCP Server
- Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server
- HashiCorp Vault + Vault MCP Server vs Infisical