{
  "data": {
    "a": {
      "slug": "bitwarden-secrets-manager",
      "name": "Bitwarden Secrets Manager",
      "vendor": "Bitwarden",
      "vendorUrl": "https://bitwarden.com/products/secrets-manager/",
      "kind": "sdk",
      "category": "secrets",
      "summary": "End-to-end encrypted secrets store from the Bitwarden password manager company.",
      "url": "https://www.anchorterminal.com/tools/bitwarden-secrets-manager",
      "markdownUrl": "https://www.anchorterminal.com/tools/bitwarden-secrets-manager.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bitwarden-secrets-manager.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bitwarden-secrets-manager.json",
      "repo": "https://github.com/bitwarden/sdk-sm",
      "license": "Bitwarden's own SDK licence (SDK and bws), GPL-3.0 (Password Manager MCP server), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.bitwarden.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@bitwarden/sdk-napi"
        },
        {
          "registry": "pypi",
          "name": "bitwarden-sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "A machine account access token (`0.\u003cuuid\u003e.\u003cclient secret\u003e:\u003cencryption key\u003e`) goes in `BWS_ACCESS_TOKEN` or `--access-token`. The SDK exchanges the client secret at identity.bitwarden.com, then decrypts secrets locally with the key embedded in the token, so a plain curl can't read a value. Tokens are shown once, never stored server-side, and can expire on a date you set (default never).",
      "pricing": "freemium",
      "pricingNotes": "Secrets Manager has a free plan (2 users, 3 projects, 3 machine accounts, unlimited secrets, no event logs) and paid Teams and Enterprise plans. Teams $6 per user a month with 20 machine accounts included, Enterprise $12 per user a month with 50, and $1 a month per extra machine account on either. Secret storage, projects and users are unlimited on paid plans, and event logs come with Teams and Enterprise. A 14-day trial is on the pricing page; neither page says whether a card is needed. The product page lists self-hosting on Enterprise, while the plans help page still says coming soon (https://bitwarden.com/pricing/business/, https://bitwarden.com/help/secrets-manager-plans/).",
      "priceSummary": "$6 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 480,
        "npmWeekly": 24038,
        "pypiWeekly": 25331,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://bitwarden.com/help/secrets-manager-overview/",
      "capabilities": [
        "secrets.store",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "freemium",
        "source-available",
        "typescript",
        "python",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-05-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.1,
        "grade": "C",
        "agentReady": false,
        "rank": 297,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 52,
          "maintenance": 36,
          "payments": 25,
          "reliability": 71,
          "schema": 53,
          "security": 76,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "End-to-end encrypted, decrypted only on the client that holds the token. No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024.",
        "strengths": [
          "End-to-end encrypted, decrypted only on the client that holds the token",
          "Machine accounts at $1 a month each, 3 on the free plan, with Can read or Can read, write per project",
          "Per-machine-account event logs of secret access, retained indefinitely, on Teams and Enterprise",
          "SOC 2 Type II, ISO 27001 and a HackerOne bounty",
          "US or EU cloud, with self-hosting on Enterprise"
        ],
        "weaknesses": [
          "No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024",
          "33 open issues, mostly bugs, including a Python SDK segfault open since July 2025",
          "Revoked tokens keep working for up to an hour on already-authenticated machines",
          "No rotation, dynamic secrets, workload identity login or MCP server for Secrets Manager",
          "SDK and CLI under Bitwarden's own SDK licence, and no OpenAPI for the secrets API"
        ],
        "agentNotes": [
          "Create one machine account per agent with Can read on one project, and give its token an expiry date rather than the default of never",
          "Run the agent under `bws run -- \u003ccmd\u003e` so secrets arrive as environment variables and aren't written to disk or into the context",
          "Fetch with `bws secret list \u003cproject-id\u003e --output json` once per run; `bws secret get` needs the secret's UUID, not its name",
          "Set BWS_SERVER_URL for an EU organisation or a self-hosted server; the default is the US cloud",
          "Rotate the secret's value as well as revoking the token in an emergency, since a live session can read for up to an hour"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.1
          }
        ],
        "editorialScores": {
          "ergonomics": 52,
          "maintenance": 36,
          "payments": 25,
          "reliability": 71,
          "schema": 53,
          "security": 76,
          "transparency": 52
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "cargo install bws --locked   # or: curl https://bws.bitwarden.com/install | sh, npm install @bitwarden/sdk-napi, pip install bitwarden-sdk",
        "http": "export BWS_ACCESS_TOKEN=\"$BWS_ACCESS_TOKEN\"\nbws secret list \"$BWS_PROJECT_ID\"   # values are end-to-end encrypted, so the CLI or SDK decrypts; plain curl can't"
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/bitwarden-secrets-manager"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Secrets Manager, Teams",
          "unit": "seat-month",
          "usd": 6,
          "note": "20 machine accounts included"
        },
        {
          "item": "Secrets Manager, Enterprise",
          "unit": "seat-month",
          "usd": 12,
          "note": "50 machine accounts included"
        },
        {
          "item": "Extra machine account",
          "unit": "account-month",
          "usd": 1
        }
      ],
      "provenance": {
        "legalEntity": "Bitwarden Inc. (terms name 8bit Solutions LLC, wholly owned by Bitwarden Inc.)",
        "domain": "bitwarden.com",
        "domainRegistered": "2015-11-16",
        "endpointOnVendorDomain": true,
        "terms": "https://bitwarden.com/terms/",
        "privacy": "https://bitwarden.com/privacy/",
        "statusPage": "https://status.bitwarden.com",
        "changelog": "https://github.com/bitwarden/sdk-sm/releases",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "Terms dated 1 June 2017 name 8bit Solutions LLC, a Delaware company wholly owned by Bitwarden Inc. The privacy policy (revised April 2024) gives Bitwarden Inc., 1 North Calle Cesar Chavez, Suite 102, Santa Barbara, CA 93103, with data stored primarily in the EEA and United States.",
          "bitwarden.com/.well-known/security.txt returned 404 on 30 September 2026; the SDK repository's SECURITY.md points to HackerOne.",
          "status.bitwarden.com runs on Hund.io. Since 3 July 2026 it shows five planned maintenance windows and one unscheduled incident, elevated US API error rates for 38 minutes on 29 September.",
          "The compliance page claims SOC 2 Type II, SOC 3, ISO 27001 and HIPAA, with data on Azure in the US or EU.",
          "The crate changelogs in sdk-sm stop at 1.0.0 (September 2024); later releases are only described on GitHub."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/bitwarden-secrets-manager.json",
      "live": {
        "slug": "bitwarden-secrets-manager",
        "probe": {
          "target": "https://api.bitwarden.com",
          "method": "get",
          "lastAt": "2026-10-05T01:43:34.211436947Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 130,
          "authRequired": false,
          "uptime24h": 99.26,
          "uptime30d": 97.39,
          "p50ms24h": 131,
          "p95ms24h": 317,
          "samples24h": 272,
          "samples30d": 920,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 102
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 239
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 265
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 270
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.bitwarden.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:50.88623142Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "bitwarden/sdk-sm",
            "version": "python-v2.1.0",
            "released": "2026-05-21",
            "seenAt": "2026-10-04T16:22:18.502566508Z"
          },
          {
            "registry": "npm",
            "name": "@bitwarden/sdk-napi",
            "version": "1.0.0",
            "seenAt": "2026-10-04T16:22:17.909661383Z"
          },
          {
            "registry": "pypi",
            "name": "bitwarden-sdk",
            "version": "2.1.0",
            "released": "2026-05-21",
            "seenAt": "2026-10-04T16:22:18.317866887Z"
          }
        ],
        "githubStars": 480,
        "npmWeekly": 25074,
        "pypiWeekly": 27867,
        "securityTxt": {
          "url": "https://bitwarden.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:46.220509573Z"
        },
        "domain": {
          "domain": "bitwarden.com",
          "registered": "2015-11-16",
          "source": "https://rdap.verisign.com/com/v1/domain/bitwarden.com",
          "checkedAt": "2026-10-04T13:03:43.146799125Z"
        },
        "pages": [
          {
            "url": "https://bitwarden.com/pricing/business/",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:30.968841046Z",
            "changedAt": "2026-10-03T15:29:42.809015327Z",
            "fingerprint": "8d0a67e9a051"
          },
          {
            "url": "https://bitwarden.com/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:32.998627256Z",
            "changedAt": "2026-10-04T15:41:32.998627256Z",
            "fingerprint": "612dca4ba267"
          },
          {
            "url": "https://bitwarden.com/terms/",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:35.010005656Z",
            "changedAt": "2026-10-03T15:29:46.855070037Z",
            "fingerprint": "662bff2efe7c"
          }
        ],
        "updatedAt": "2026-10-05T01:43:34.211436947Z"
      }
    },
    "b": {
      "slug": "infisical",
      "name": "Infisical",
      "vendor": "Infisical",
      "vendorUrl": "https://infisical.com",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Open-source secrets manager with machine identities (Universal Auth, OIDC, AWS, GCP, Azure, Kubernetes, SPIFFE), dynamic secrets, rotation and audit logs, hosted in the US or EU or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/infisical",
      "markdownUrl": "https://www.anchorterminal.com/tools/infisical.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/infisical.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/infisical.json",
      "repo": "https://github.com/Infisical/infisical",
      "license": "MIT (core), proprietary under ee/",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://app.infisical.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "@infisical/sdk"
        },
        {
          "registry": "pypi",
          "name": "infisicalsdk"
        },
        {
          "registry": "npm",
          "name": "@infisical/cli"
        },
        {
          "registry": "npm",
          "name": "@infisical/mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "Machine identities log in with Universal Auth (client ID and secret posted to /api/v1/auth/universal-auth/login), Token Auth, OIDC, JWT, or native AWS, Azure, GCP, Kubernetes, OCI, AliCloud, LDAP, TLS certificate or SPIFFE auth, and get a short-lived access token (`st.…`, default TTL 7,200 s) sent as a Bearer header. Revoke it at /api/v1/auth/token/revoke. Agent Vault sessions use a separate session token that only works against the proxy. The docs MCP server at infisical.com/docs/mcp needs no auth.",
      "pricing": "freemium",
      "pricingNotes": "Free, Pro, Advanced and Enterprise plans on Infisical Cloud. Free is $0 with 5 identities, 3 environments, no audit logs, no rotation and no dynamic secrets, and needs no card. Pro is $20 per identity a month billed yearly ($23 monthly) with 30-day audit logs and rotation. Advanced is $40 per identity a month billed yearly ($46 monthly) with 90-day audit logs, dynamic secrets and higher rate limits. Pro and Advanced trials need no card. Enterprise is custom. Agent Proxy is on Free and Pro for static secrets. Cloud rate limits are per client IP, 600 requests a minute overall, then Free 200 reads, 90 writes and 120 secret operations a minute, Pro 350, 200 and 300. Self-hosting the MIT core is free with no rate limits; the code under ee/ needs an Enterprise licence (https://infisical.com/pricing, https://infisical.com/docs/api-reference/overview/rate-limits).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 10,
      "popularity": {
        "githubStars": 28405,
        "npmWeekly": 305133,
        "pypiWeekly": 391329,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://infisical.com/docs",
      "llmsTxt": "https://infisical.com/docs/llms.txt",
      "openapi": "https://app.infisical.com/api/docs/json",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "auth.agent-identity"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 81.9,
        "grade": "A",
        "agentReady": true,
        "rank": 4,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 91,
          "maintenance": 90,
          "payments": 30,
          "reliability": 90,
          "schema": 87,
          "security": 91,
          "transparency": 85
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.",
        "strengths": [
          "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them",
          "Thirteen machine identity auth methods with short-lived, revocable access tokens",
          "MIT core that self-hosts with no API rate limits, plus US and EU cloud regions",
          "Official MCP server with 10 annotated tools, a tool allowlist and optional value masking",
          "48 tagged releases between 3 July and 23 September 2026, each with an upgrade-impact note"
        ],
        "weaknesses": [
          "Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month",
          "Cloud rate limits are per client IP, so agents behind one NAT share 600 requests a minute",
          "The MCP server returns secret values unless INFISICAL_MASK_SECRET_VALUES is set, and it's still version 0.0.x",
          "Agent Vault session tokens travel to the proxy unencrypted, and the feature sits under the proprietary ee/ licence",
          "No SLA found, and every listed subprocessor is in the United States despite the EU region"
        ],
        "agentNotes": [
          "Run a coding agent under `infisical agent-vault run` with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length",
          "Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value",
          "Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit",
          "Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets",
          "On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.8,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 81.9
          }
        ],
        "editorialScores": {
          "ergonomics": 91,
          "maintenance": 90,
          "payments": 30,
          "reliability": 90,
          "schema": 87,
          "security": 91,
          "transparency": 77
        },
        "provenanceScore": 92
      },
      "connect": {
        "install": "npm install @infisical/sdk   # or: pip install infisicalsdk, brew install infisical/get-cli/infisical",
        "http": "curl -G https://app.infisical.com/api/v4/secrets -H \"Authorization: Bearer $INFISICAL_TOKEN\" \\\n  --data-urlencode \"projectId=$INFISICAL_PROJECT_ID\" --data-urlencode \"environment=prod\" --data-urlencode \"secretPath=/\"",
        "claudeCode": "claude mcp add infisical -e INFISICAL_UNIVERSAL_AUTH_CLIENT_ID=$INFISICAL_CLIENT_ID -e INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET=$INFISICAL_CLIENT_SECRET -e INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret -- npx -y @infisical/mcp",
        "config": {
          "mcpServers": {
            "infisical": {
              "args": [
                "-y",
                "@infisical/mcp"
              ],
              "command": "npx",
              "env": {
                "INFISICAL_ENABLED_TOOLS": "list-projects,list-secrets,get-secret",
                "INFISICAL_UNIVERSAL_AUTH_CLIENT_ID": "${INFISICAL_CLIENT_ID}",
                "INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET": "${INFISICAL_CLIENT_SECRET}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/infisical"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Infisical, Inc.",
        "domain": "infisical.com",
        "domainRegistered": "2022-07-06",
        "endpointOnVendorDomain": true,
        "terms": "https://infisical.com/terms",
        "privacy": "https://infisical.com/privacy",
        "statusPage": "https://status.infisical.com",
        "changelog": "https://github.com/Infisical/infisical/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The privacy policy (last updated 15 September 2025) names Infisical, Inc. without a postal address and links a subprocessor list dated 9 September 2026 with 17 entries, all in the United States.",
          "security.txt expires 2027-08-01 and points to a Bugcrowd disclosure programme; a paid bounty is private and invitation-only.",
          "The docs changelog stops at July 2025; releases since then are tagged on GitHub with generated notes and an upgrade-impact file per release in the repository.",
          "status.infisical.com runs on incident.io and showed only a planned maintenance on 23 July 2026 between July and October 2026."
        ],
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/infisical.json",
      "live": {
        "slug": "infisical",
        "probe": {
          "target": "https://app.infisical.com/api",
          "method": "get",
          "lastAt": "2026-10-05T01:43:39.193812911Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 265,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 253,
          "p95ms24h": 306,
          "samples24h": 272,
          "samples30d": 920,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.infisical.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T01:46:35.013668094Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "Infisical/infisical",
            "version": "v0.165.16",
            "released": "2026-09-23",
            "seenAt": "2026-10-04T16:30:07.020121532Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/cli",
            "version": "0.43.138",
            "seenAt": "2026-10-04T16:30:03.879471957Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/mcp",
            "version": "0.0.24",
            "seenAt": "2026-10-04T16:30:05.024522005Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/sdk",
            "version": "5.0.2",
            "seenAt": "2026-10-04T16:30:02.799307929Z"
          },
          {
            "registry": "pypi",
            "name": "infisicalsdk",
            "version": "1.0.17",
            "released": "2026-08-17",
            "seenAt": "2026-10-04T16:30:03.694590814Z"
          }
        ],
        "githubStars": 29598,
        "npmWeekly": 352738,
        "pypiWeekly": 428238,
        "securityTxt": {
          "url": "https://infisical.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-08-01T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:56.427929639Z"
        },
        "llmsTxt": {
          "url": "https://infisical.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.483742063Z"
        },
        "domain": {
          "domain": "infisical.com",
          "registered": "2022-07-06",
          "source": "https://rdap.verisign.com/com/v1/domain/infisical.com",
          "checkedAt": "2026-10-04T13:05:56.955224704Z"
        },
        "pages": [
          {
            "url": "https://infisical.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:06.403675987Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b27bc7fd3df5"
          },
          {
            "url": "https://infisical.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:08.688215502Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f0c109cb65cf"
          },
          {
            "url": "https://infisical.com/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:45:10.606822528Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "01d76f6adafb"
          }
        ],
        "updatedAt": "2026-10-05T01:46:35.013668094Z"
      }
    },
    "summary": "Infisical has a score of 81.9 (A) against Bitwarden Secrets Manager's 57.1 (C). Both do secrets store. The largest gap is maintenance \u0026 community, 54 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical",
    "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical.md",
    "slim": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical.min.md"
  },
  "markdown": "Infisical has a score of 81.9 (A) against Bitwarden Secrets Manager's 57.1 (C). Both do secrets store. The largest gap is maintenance \u0026 community, 54 points.\n\n- Bitwarden Secrets Manager: grade C, 57.1/100, rank #297 of 452. Markdown https://www.anchorterminal.com/tools/bitwarden-secrets-manager.md · JSON https://www.anchorterminal.com/api/v1/tools/bitwarden-secrets-manager.json\n- Infisical: grade A, 81.9/100, rank #4 of 452. Markdown https://www.anchorterminal.com/tools/infisical.md · JSON https://www.anchorterminal.com/api/v1/tools/infisical.json\n\n## Which one, for what\n\nPick Bitwarden Secrets Manager for nothing in particular (no category where it leads by five points or more).\n\nPick Infisical for reliability (+19), schema \u0026 documentation (+34), agent ergonomics (+39), security \u0026 auth (+15), payments \u0026 pricing (+5), maintenance \u0026 community (+54), transparency \u0026 trust (+14).\n\n## Score by category\n\n| Category | Weight | Bitwarden Secrets Manager | Infisical | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 90 | Infisical +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 53 | 87 | Infisical +34 |\n| Agent ergonomics | 13% (16.2 this run) | 52 | 91 | Infisical +39 |\n| Security \u0026 auth | 14% (17.5 this run) | 76 | 91 | Infisical +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 30 | Infisical +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 36 | 90 | Infisical +54 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 85 | Infisical +14 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **57.1 · C** | **81.9 · A** | |\n\n## Facts side by side\n\n| Fact | Bitwarden Secrets Manager | Infisical |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Bitwarden | Infisical |\n| Hosted endpoint | `https://api.bitwarden.com` | `https://app.infisical.com/api` |\n| Transports | HTTP | HTTP, Streamable HTTP, stdio |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Bitwarden's own SDK licence (SDK and bws), GPL-3.0 (Password Manager MCP server), platform closed | MIT (core), proprietary under ee/ |\n| Tools exposed | none | 10 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-05-22 | 2026-09-23 |\n| Popularity | 480 stars, 24k npm/wk, 25k PyPI/wk | 28k stars, 305k npm/wk, 391k PyPI/wk |\n| Agent reviews | 2.5/5 (2) | 3.8/5 (8) |\n\n## Verdicts\n\n**Bitwarden Secrets Manager.** End-to-end encrypted, decrypted only on the client that holds the token. No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024.\n\n**Infisical.** Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.\n\n## Before you call either\n\n### Bitwarden Secrets Manager\n\n1. Create one machine account per agent with Can read on one project, and give its token an expiry date rather than the default of never\n2. Run the agent under `bws run -- \u003ccmd\u003e` so secrets arrive as environment variables and aren't written to disk or into the context\n3. Fetch with `bws secret list \u003cproject-id\u003e --output json` once per run; `bws secret get` needs the secret's UUID, not its name\n4. Set BWS_SERVER_URL for an EU organisation or a self-hosted server; the default is the US cloud\n5. Rotate the secret's value as well as revoking the token in an emergency, since a live session can read for up to an hour\n\n### Infisical\n\n1. Run a coding agent under `infisical agent-vault run` with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length\n2. Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value\n3. Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit\n4. Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets\n5. On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land\n\n## Other comparisons with Bitwarden Secrets Manager or Infisical\n\n- [1Password service accounts, SDKs and Environments MCP vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-bitwarden-secrets-manager.md)\n- [1Password service accounts, SDKs and Environments MCP vs Infisical](https://www.anchorterminal.com/compare/1password-vs-infisical.md)\n- [Akeyless (SecretlessAI and MCP server) vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-bitwarden-secrets-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Infisical](https://www.anchorterminal.com/compare/akeyless-vs-infisical.md)\n- [AWS Secrets Manager vs Bitwarden Secrets Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-bitwarden-secrets-manager.md)\n- [AWS Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-infisical.md)\n- [Bitwarden Secrets Manager vs Doppler](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-doppler.md)\n- [Bitwarden Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-google-secret-manager.md)\n- [Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md)\n- [Doppler vs Infisical](https://www.anchorterminal.com/compare/doppler-vs-infisical.md)\n- [Google Cloud Secret Manager vs Infisical](https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md)\n- [HashiCorp Vault + Vault MCP Server vs Infisical](https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Bitwarden Secrets Manager vs Infisical",
        "url": ""
      }
    ],
    "description": "Infisical has a score of 81.9 (A) against Bitwarden Secrets Manager's 57.1 (C). Both do secrets store. The largest gap is maintenance \u0026 community, 54 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Bitwarden Secrets Manager C 57.1",
      "Infisical A 81.9",
      "scores"
    ],
    "h1": "Bitwarden Secrets Manager vs Infisical",
    "image": "https://www.anchorterminal.com/assets/og/compare-bitwarden-secrets-manager-vs-infisical.png",
    "path": "/compare/bitwarden-secrets-manager-vs-infisical",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Bitwarden Secrets Manager vs Infisical for AI agents, C 57.1 vs A 81.9",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical"
  },
  "tokens": {
    "markdown": 1750,
    "slim": 380
  },
  "version": 1
}
