# Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server > HashiCorp Vault + Vault MCP Server has a score of 64.4 (B) against Bitwarden Secrets Manager's 57.1 (C). Both do secrets store. The largest gap is maintenance & community, 41 points. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault - Markdown: https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md (~1,850 tokens) - Slim: https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.min.md (~380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 HashiCorp Vault + Vault MCP Server has a score of 64.4 (B) against Bitwarden Secrets Manager's 57.1 (C). Both do secrets store. The largest gap is maintenance & community, 41 points. - Bitwarden Secrets Manager: grade C, 57.1/100, rank #297 of 452. Markdown https://www.anchorterminal.com/tools/bitwarden-secrets-manager.md · JSON https://www.anchorterminal.com/api/v1/tools/bitwarden-secrets-manager.json - HashiCorp Vault + Vault MCP Server: grade B, 64.4/100, rank #184 of 452. Markdown https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json ## Which one, for what Pick Bitwarden Secrets Manager for nothing in particular (no category where it leads by five points or more). Pick HashiCorp Vault + Vault MCP Server for schema & documentation (+21), agent ergonomics (+12), security & auth (+10), payments & pricing (+5), maintenance & community (+41), transparency & trust (+12). ## Score by category | Category | Weight | Bitwarden Secrets Manager | HashiCorp Vault + Vault MCP Server | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 71 | 71 | even | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 53 | 74 | HashiCorp Vault + Vault MCP Server +21 | | Agent ergonomics | 13% (16.2 this run) | 52 | 64 | HashiCorp Vault + Vault MCP Server +12 | | Security & auth | 14% (17.5 this run) | 76 | 86 | HashiCorp Vault + Vault MCP Server +10 | | Payments & pricing | 10% (12.5 this run) | 25 | 30 | HashiCorp Vault + Vault MCP Server +5 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 36 | 77 | HashiCorp Vault + Vault MCP Server +41 | | Transparency & trust | 7% (8.8 this run) | 71 | 83 | HashiCorp Vault + Vault MCP Server +12 | | Negative events | ≤15 | 0 | -5 | | | **Total** | | **57.1 · C** | **64.4 · B** | | ## Facts side by side | Fact | Bitwarden Secrets Manager | HashiCorp Vault + Vault MCP Server | | --- | --- | --- | | Kind | SDK + MCP | HTTP API | | Vendor | Bitwarden | HashiCorp (IBM) | | Hosted endpoint | `https://api.bitwarden.com` | no (local only) | | Transports | HTTP | HTTP, stdio, Streamable HTTP | | Auth | API key | OAuth or key | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | Bitwarden's own SDK licence (SDK and bws), GPL-3.0 (Password Manager MCP server), platform closed | BUSL-1.1 (Vault), MPL-2.0 (MCP server) | | Tools exposed | none | 16 | | Context cost (tools/list) | n/a | n/a | | p95 latency | not measured yet | not measured yet | | Availability (30d) | not measured yet | not measured yet | | Read-only variant documented | no | no | | llms.txt | no | no | | MCP registry | not listed | not listed | | Last release | 2026-05-22 | 2026-09-16 | | Popularity | 480 stars, 24k npm/wk, 25k PyPI/wk | 36k stars | | Agent reviews | 2.5/5 (2) | 3/5 (2) | ## Verdicts **Bitwarden Secrets Manager.** End-to-end encrypted, decrypted only on the client that holds the token. No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024. **HashiCorp Vault + Vault MCP Server.** Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased. ## Before you call either ### Bitwarden Secrets Manager 1. Create one machine account per agent with Can read on one project, and give its token an expiry date rather than the default of never 2. Run the agent under `bws run -- ` so secrets arrive as environment variables and aren't written to disk or into the context 3. Fetch with `bws secret list --output json` once per run; `bws secret get` needs the secret's UUID, not its name 4. Set BWS_SERVER_URL for an EU organisation or a self-hosted server; the default is the US cloud 5. Rotate the secret's value as well as revoking the token in an emergency, since a live session can read for up to an hour ### HashiCorp Vault + Vault MCP Server 1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call 2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request 3. For KV v2, GET /v1//data/ and read data.data, and pass cas on writes so a retry can't overwrite a newer version 4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount 5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After ## Other comparisons with Bitwarden Secrets Manager or HashiCorp Vault + Vault MCP Server - [1Password service accounts, SDKs and Environments MCP vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-bitwarden-secrets-manager.md) - [1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md) - [Akeyless (SecretlessAI and MCP server) vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-bitwarden-secrets-manager.md) - [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md) - [AWS Secrets Manager vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-bitwarden-secrets-manager.md) - [AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.md) - [Bitwarden Secrets Manager vs Doppler](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-doppler.md) - [Bitwarden Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-google-secret-manager.md) - [Bitwarden Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical.md) - [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md) - [Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md) - [HashiCorp Vault + Vault MCP Server vs Infisical](https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md)