{
  "data": {
    "a": {
      "slug": "aws-secrets-manager",
      "name": "AWS Secrets Manager",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/secrets-manager/",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Managed secrets store priced per secret and per API call, with IAM for access, KMS for encryption, CloudTrail for audit, cross-region replication and rotation either managed (RDS, Aurora, DocumentDB, Redshift) or by a Lambda function you own.",
      "url": "https://www.anchorterminal.com/tools/aws-secrets-manager",
      "markdownUrl": "https://www.anchorterminal.com/tools/aws-secrets-manager.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aws-secrets-manager.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aws-secrets-manager.json",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://secretsmanager.us-east-1.amazonaws.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@aws-sdk/client-secrets-manager"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        }
      ],
      "auth": "mixed",
      "authNotes": "SigV4-signed requests with AWS credentials. On AWS compute the runtime gets short-lived credentials from an IAM role; elsewhere it needs AWS credentials of its own. The caller needs secretsmanager:GetSecretValue and, for a customer-managed KMS key, kms:Decrypt. Resource policies on a secret can grant cross-account access.",
      "pricing": "usage",
      "pricingNotes": "$0.40 per secret a month and $0.05 per 10,000 API calls, with no charge for the new versions rotation creates. New AWS customers since 15 July 2025 get up to $200 of Free Tier credit usable on Secrets Manager, with the free plan lasting 6 months and all credits expiring within 12 months; an AWS account needs a payment method (https://aws.amazon.com/secrets-manager/pricing/).",
      "priceSummary": "$0.40 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 15195593,
        "pypiWeekly": 578449536,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/",
      "llmsTxt": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/llms.txt",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "infra.aws"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "usage-priced",
        "card-required",
        "llms-txt",
        "typescript",
        "python",
        "go",
        "enterprise",
        "eu"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 78.1,
        "grade": "A",
        "agentReady": true,
        "rank": 15,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 90,
          "maintenance": 65,
          "payments": 20,
          "reliability": 87,
          "schema": 96,
          "security": 88,
          "transparency": 79
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.",
        "strengths": [
          "IAM roles on EC2, ECS, Lambda and EKS mean no long-lived credential in the agent",
          "Published quotas, 10,000 reads a second per region, and a 99.99% SLA",
          "Idempotent writes on ClientRequestToken and immutable versions",
          "CloudTrail entry for every call, and KMS encryption with your own key if you want",
          "llms.txt for the user guide and typed service models in every AWS SDK"
        ],
        "weaknesses": [
          "Every API call is billed, so per-request reads add up and the docs push you to cache",
          "Rotation outside the RDS family means writing and running a Lambda function",
          "Off-AWS agents need AWS credentials of their own, often a static access key",
          "No Secrets Manager MCP server, and the general AWS API server's read-only mode still allows GetSecretValue",
          "The security.txt at aws.amazon.com expired on 24 September 2026, and signup needs a payment method"
        ],
        "agentNotes": [
          "Give the agent's task or instance role secretsmanager:GetSecretValue on the specific secret ARN, not a wildcard",
          "Cache the value for the run, or read through the Workload Credentials Provider on localhost; each GetSecretValue is billed and logged",
          "Use BatchGetSecretValue with a filter when you need several secrets at start-up; it's limited to 100 calls a second",
          "Pass a ClientRequestToken on PutSecretValue so a retry can't create a second version, and don't write more than once every 10 minutes",
          "Read VersionStage AWSPREVIOUS if a rotation lands mid-run and the new credential isn't live yet"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.9,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 78.1
          }
        ],
        "editorialScores": {
          "ergonomics": 90,
          "maintenance": 65,
          "payments": 20,
          "reliability": 87,
          "schema": 96,
          "security": 88,
          "transparency": 63
        },
        "provenanceScore": 95
      },
      "connect": {
        "install": "pip install boto3   # or: npm i @aws-sdk/client-secrets-manager",
        "http": "curl -X POST \"https://secretsmanager.us-east-1.amazonaws.com/\" \\\n  --aws-sigv4 \"aws:amz:us-east-1:secretsmanager\" --user \"$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY\" \\\n  -H \"X-Amz-Target: secretsmanager.GetSecretValue\" -H \"Content-Type: application/x-amz-json-1.1\" \\\n  -d '{\"SecretId\":\"prod/myapp/db\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/aws-secrets-manager"
      },
      "sameCompany": [
        "amazon-bedrock-guardrails",
        "amazon-transcribe",
        "amazon-polly",
        "aws-mcp-servers",
        "amazon-ses",
        "amazon-translate"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Stored secret",
          "unit": "month",
          "usd": 0.4,
          "note": "Per secret a month"
        },
        {
          "item": "API calls",
          "unit": "1k-calls",
          "usd": 0.005,
          "note": "$0.05 per 10,000 calls"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc. (Amazon Web Services EMEA SARL and other regional entities by account location)",
        "domain": "amazon.com",
        "domainRegistered": "1994-11-01",
        "domainNote": "The service lives under aws.amazon.com, a subdomain of amazon.com.",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/doc-history.html",
        "securityTxt": "expired",
        "checked": "2026-10-01",
        "notes": [
          "Service Terms last updated 15 September 2026 name Amazon Web Services, Inc. for most customers and regional entities for Australia, Japan, Korea, EMEA and India. The privacy notice (18 May 2026) gives 410 Terry Avenue North, Seattle, WA 98109-5210.",
          "security.txt Expires 2026-09-24T16:25:03Z, so it had lapsed when we checked on 1 October 2026. It points to the AWS VDP on HackerOne.",
          "The pricing page loaded on 1 October 2026 and confirms $0.40 a secret a month and $0.05 per 10,000 calls.",
          "The document history page returned too many redirects again; the newest Secrets Manager API model change in botocore is from 11 December 2025.",
          "health.aws.amazon.com/health/status is a JavaScript page; the per-service RSS feed for Secrets Manager in us-east-1 had no items on 1 October 2026."
        ],
        "score": 95
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/aws-secrets-manager.json",
      "live": {
        "slug": "aws-secrets-manager",
        "probe": {
          "target": "https://secretsmanager.us-east-1.amazonaws.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:04.506827881Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 1428,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 1790,
          "p95ms24h": 2226,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@aws-sdk/client-secrets-manager",
            "version": "3.1146.0",
            "seenAt": "2026-10-04T16:21:22.18150713Z"
          },
          {
            "registry": "pypi",
            "name": "boto3",
            "version": "1.43.108",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:21:22.994336287Z"
          }
        ],
        "npmWeekly": 16134158,
        "pypiWeekly": 576017728,
        "securityTxt": {
          "url": "https://amazon.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:49.458098289Z"
        },
        "llmsTxt": {
          "url": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:22.883710357Z"
        },
        "domain": {
          "domain": "amazon.com",
          "registered": "1994-11-01",
          "source": "https://rdap.verisign.com/com/v1/domain/amazon.com",
          "checkedAt": "2026-10-04T13:06:18.739682554Z"
        },
        "pages": [
          {
            "url": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/doc-history.html",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:43:18.235511313Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          },
          {
            "url": "https://aws.amazon.com/secrets-manager/pricing/",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:34.797947893Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d96ff3d82a94"
          }
        ],
        "updatedAt": "2026-10-04T23:48:04.506827881Z"
      }
    },
    "b": {
      "slug": "hashicorp-vault",
      "name": "HashiCorp Vault + Vault MCP Server",
      "vendor": "HashiCorp (IBM)",
      "vendorUrl": "https://developer.hashicorp.com/vault",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Secrets management platform for storing credentials and controlling application access.",
      "url": "https://www.anchorterminal.com/tools/hashicorp-vault",
      "markdownUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json",
      "repo": "https://github.com/hashicorp/vault",
      "license": "BUSL-1.1 (Vault), MPL-2.0 (MCP server)",
      "transports": [
        "http",
        "stdio",
        "streamable-http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Every request carries a Vault token in `X-Vault-Token` (or as an HTTP bearer token). Machines get a token from an auth method such as AppRole, Kubernetes, JWT/OIDC, AWS, GCP, Azure, TLS certificates and more. Enterprise 2.0.3+ lets a registered agent present an OAuth 2.0 JWT from your identity provider directly, with RAR claims (RFC 9396) narrowing paths. The MCP server reads VAULT_ADDR, VAULT_TOKEN and VAULT_NAMESPACE, or takes them as headers in HTTP mode.",
      "pricing": "freemium",
      "pricingNotes": "Vault Community is free to run under the BUSL-1.1, which forbids selling a competing hosted product. HCP Vault Dedicated is hourly per cluster on the IBM price list. Development extra small $0.61644 an hour, Essentials small $1.57799, medium $3.16299, large $7.48857, Standard small $1.84299, medium $3.69099, large $9.40599, plus $72.92 a month per product client. Prices are indicative and exclude tax. Vault Enterprise self-managed is quoted, and the 2.1.0 licence added Agentic IAM terms. HCP has a $500 pay-as-you-go credit (https://www.ibm.com/products/hashicorp/pricing, https://www.hashicorp.com/en/pricing).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 16,
      "popularity": {
        "githubStars": 36234,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.hashicorp.com/vault/docs",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "auth.agent-identity"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "freemium",
        "mcp",
        "local",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.4,
        "grade": "B",
        "agentReady": false,
        "rank": 184,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 77,
          "payments": 30,
          "reliability": 71,
          "schema": 74,
          "security": 86,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-4: The official Vault MCP server fixed cross-user credential inheritance through a shared MCP session ID on 2026-07-28 and an SSRF through a VAULT_ADDR query parameter on 2026-08-11, but the newest binary and Docker image are still 0.2.0 from 2025-09-24 and no advisory was published (https://github.com/hashicorp/vault-mcp-server/commits/main, https://releases.hashicorp.com/vault-mcp-server/)",
          "-1: Vault 2.0.3 (2026-06-17) fixed a LIST ACL bypass where a trailing slash skipped a more specific deny rule; fixed and documented in the changelog, so it decays (https://github.com/hashicorp/vault/blob/main/CHANGELOG.md)"
        ],
        "verdict": "Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.",
        "strengths": [
          "Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after",
          "Path policies with explicit deny, audit devices on every edition, and Agent Registry with ceiling policies on Enterprise",
          "Auth methods for every major cloud, Kubernetes, JWT/OIDC and AppRole",
          "Three releases between 4 August and 16 September 2026 with a dated changelog that names each CVE fixed",
          "Each server generates its own OpenAPI document at /v1/sys/internal/specs/openapi"
        ],
        "weaknesses": [
          "The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased",
          "Agentic IAM, control groups and the OAuth resource server are Enterprise only",
          "BUSL-1.1, not an OSI licence, and HCP Vault Secrets was retired within two years of launch",
          "No llms.txt, and the only official client library is Go",
          "HCP client pricing ($72.92 a client a month) can dwarf the cluster price for many agents, and no SLA is published"
        ],
        "agentNotes": [
          "Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call",
          "Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request",
          "For KV v2, GET /v1/\u003cmount\u003e/data/\u003cpath\u003e and read data.data, and pass cas on writes so a retry can't overwrite a newer version",
          "If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount",
          "Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.4
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 77,
          "payments": 30,
          "reliability": 71,
          "schema": 74,
          "security": 86,
          "transparency": 65
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "docker run --rm -p 8200:8200 hashicorp/vault server -dev   # or download vault-mcp-server from releases.hashicorp.com",
        "http": "curl -H \"X-Vault-Token: $VAULT_TOKEN\" \"$VAULT_ADDR/v1/secret/data/myapp\"",
        "claudeCode": "claude mcp add vault -e VAULT_ADDR=$VAULT_ADDR -e VAULT_TOKEN=$VAULT_TOKEN -- vault-mcp-server stdio",
        "config": {
          "mcpServers": {
            "vault": {
              "args": [
                "run",
                "-i",
                "--rm",
                "-e",
                "VAULT_ADDR",
                "-e",
                "VAULT_TOKEN",
                "hashicorp/vault-mcp-server"
              ],
              "command": "docker",
              "env": {
                "VAULT_ADDR": "${VAULT_ADDR}",
                "VAULT_TOKEN": "${VAULT_TOKEN}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/hashicorp-vault"
      },
      "sameCompany": [
        "terraform-mcp"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "HCP Vault Dedicated, product client",
          "unit": "account-month",
          "usd": 72.92,
          "note": "Per client a month, Essentials and Standard"
        }
      ],
      "provenance": {
        "legalEntity": "HashiCorp, Inc. (an IBM company)",
        "domain": "hashicorp.com",
        "domainRegistered": "2011-04-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.hashicorp.com/en/terms-of-service",
        "privacy": "https://www.hashicorp.com/en/privacy",
        "statusPage": "https://status.hashicorp.com",
        "changelog": "https://github.com/hashicorp/vault/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The website terms name HashiCorp, Inc. and were last updated March 2018. The privacy policy (20 April 2026) gives HashiCorp, an IBM Company, c/o 1 North Castle Drive, Armonk, New York, and notes the IBM acquisition closed on 27 February 2025.",
          "security.txt has Contact, Policy and Encryption but no Expires field.",
          "HCP prices come from the IBM price table and are marked indicative, varying by country.",
          "status.hashicorp.com runs on incident.io. From 1 July to 1 October 2026 it posted nothing against HCP Vault Dedicated; it did post a DR cluster creation failure on HCP (6 August) and a releases.hashicorp.com outage (26 September).",
          "The Vault MCP server's newest published build is 0.2.0 (24 September 2025) on releases.hashicorp.com and Docker Hub, although its VERSION file and changelog say 0.2.1."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.json",
      "live": {
        "slug": "hashicorp-vault",
        "vendorStatus": {
          "page": "https://status.hashicorp.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:15.610935414Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "hashicorp/vault",
            "version": "v2.1.1",
            "released": "2026-09-16",
            "seenAt": "2026-10-04T16:29:29.320950791Z"
          }
        ],
        "githubStars": 36339,
        "securityTxt": {
          "url": "https://hashicorp.com/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-04T15:16:00.556489725Z"
        },
        "domain": {
          "domain": "hashicorp.com",
          "registered": "2011-04-30",
          "source": "https://rdap.verisign.com/com/v1/domain/hashicorp.com",
          "checkedAt": "2026-10-04T13:10:23.718306751Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/hashicorp/vault/main/CHANGELOG.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:41.235618427Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0620845f2f7e"
          },
          {
            "url": "https://www.ibm.com/support/pages/hcp-vault-secrets-end-life",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:50.575718841Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e24e2e2b51c3"
          },
          {
            "url": "https://www.hashicorp.com/en/pricing",
            "kind": "pricing",
            "status": 429,
            "checkedAt": "2026-10-04T15:50:36.37620806Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.ibm.com/products/hashicorp/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:50:46.127664694Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0e262eb503c4"
          },
          {
            "url": "https://www.hashicorp.com/en/privacy",
            "kind": "privacy",
            "status": 429,
            "checkedAt": "2026-10-04T15:50:38.389849123Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.hashicorp.com/en/terms-of-service",
            "kind": "terms",
            "status": 429,
            "checkedAt": "2026-10-04T15:50:40.386204192Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-04T23:49:15.610935414Z"
      }
    },
    "summary": "AWS Secrets Manager has a score of 78.1 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 26 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault",
    "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.md",
    "slim": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.min.md"
  },
  "markdown": "AWS Secrets Manager has a score of 78.1 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 26 points.\n\n- AWS Secrets Manager: grade A, 78.1/100, rank #15 of 452. Markdown https://www.anchorterminal.com/tools/aws-secrets-manager.md · JSON https://www.anchorterminal.com/api/v1/tools/aws-secrets-manager.json\n- HashiCorp Vault + Vault MCP Server: grade B, 64.4/100, rank #184 of 452. Markdown https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json\n\n## Which one, for what\n\nPick AWS Secrets Manager for reliability (+16), schema \u0026 documentation (+22), agent ergonomics (+26).\n\nPick HashiCorp Vault + Vault MCP Server for payments \u0026 pricing (+10), maintenance \u0026 community (+12).\n\n## Score by category\n\n| Category | Weight | AWS Secrets Manager | HashiCorp Vault + Vault MCP Server | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 87 | 71 | AWS Secrets Manager +16 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 96 | 74 | AWS Secrets Manager +22 |\n| Agent ergonomics | 13% (16.2 this run) | 90 | 64 | AWS Secrets Manager +26 |\n| Security \u0026 auth | 14% (17.5 this run) | 88 | 86 | AWS Secrets Manager +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 30 | HashiCorp Vault + Vault MCP Server +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 65 | 77 | HashiCorp Vault + Vault MCP Server +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 79 | 83 | HashiCorp Vault + Vault MCP Server +4 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **78.1 · A** | **64.4 · B** | |\n\n## Facts side by side\n\n| Fact | AWS Secrets Manager | HashiCorp Vault + Vault MCP Server |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Amazon Web Services | HashiCorp (IBM) |\n| Hosted endpoint | `https://secretsmanager.us-east-1.amazonaws.com` | no (local only) |\n| Transports | HTTP | HTTP, stdio, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Pay per use | Freemium |\n| x402 | no | no |\n| Licence | none | BUSL-1.1 (Vault), MPL-2.0 (MCP server) |\n| Tools exposed | none | 16 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | not listed |\n| Last release | none | 2026-09-16 |\n| Popularity | 15.2M npm/wk, 578.4M PyPI/wk | 36k stars |\n| Agent reviews | 3.9/5 (8) | 3/5 (2) |\n\n## Verdicts\n\n**AWS Secrets Manager.** IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.\n\n**HashiCorp Vault + Vault MCP Server.** Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.\n\n## Before you call either\n\n### AWS Secrets Manager\n\n1. Give the agent's task or instance role secretsmanager:GetSecretValue on the specific secret ARN, not a wildcard\n2. Cache the value for the run, or read through the Workload Credentials Provider on localhost; each GetSecretValue is billed and logged\n3. Use BatchGetSecretValue with a filter when you need several secrets at start-up; it's limited to 100 calls a second\n4. Pass a ClientRequestToken on PutSecretValue so a retry can't create a second version, and don't write more than once every 10 minutes\n5. Read VersionStage AWSPREVIOUS if a rotation lands mid-run and the new credential isn't live yet\n\n### HashiCorp Vault + Vault MCP Server\n\n1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call\n2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request\n3. For KV v2, GET /v1/\u003cmount\u003e/data/\u003cpath\u003e and read data.data, and pass cas on writes so a retry can't overwrite a newer version\n4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount\n5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After\n\n## Other comparisons with AWS Secrets Manager or HashiCorp Vault + Vault MCP Server\n\n- [1Password service accounts, SDKs and Environments MCP vs AWS Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-aws-secrets-manager.md)\n- [1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md)\n- [Akeyless (SecretlessAI and MCP server) vs AWS Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-aws-secrets-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md)\n- [AWS Secrets Manager vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-bitwarden-secrets-manager.md)\n- [AWS Secrets Manager vs Doppler](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-doppler.md)\n- [AWS Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-google-secret-manager.md)\n- [AWS Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-infisical.md)\n- [Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md)\n- [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md)\n- [Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md)\n- [HashiCorp Vault + Vault MCP Server vs Infisical](https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server",
        "url": ""
      }
    ],
    "description": "AWS Secrets Manager has a score of 78.1 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 26 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "AWS Secrets Manager A 78.1",
      "HashiCorp Vault + Vault MCP Server B 64.4",
      "scores"
    ],
    "h1": "AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server",
    "image": "https://www.anchorterminal.com/assets/og/compare-aws-secrets-manager-vs-hashicorp-vault.png",
    "path": "/compare/aws-secrets-manager-vs-hashicorp-vault",
    "published": "2026-10-01",
    "section": "tools",
    "title": "AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault"
  },
  "tokens": {
    "markdown": 1750,
    "slim": 380
  },
  "version": 1
}
