Head to head · Secrets store · October 2026 research run

Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server

Google Cloud Secret Manager has a score of 76.6 (BB) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 18 points.

Which one, for what

Pick Google Cloud Secret Manager for

  • reliability (+16)
  • schema & documentation (+9)
  • agent ergonomics (+18)
  • maintenance & community (+10)

Pick HashiCorp Vault + Vault MCP Server for

  • payments & pricing (+10)

Score by category

CategoryWeight this runGoogle Cloud Secret ManagerHashiCorp Vault + Vault MCP ServerEdge
Reliability16%208771Google Cloud Secret Manager +16
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28374Google Cloud Secret Manager +9
Agent ergonomics13%16.28264Google Cloud Secret Manager +18
Security & auth14%17.58586HashiCorp Vault + Vault MCP Server +1
Payments & pricing10%12.52030HashiCorp Vault + Vault MCP Server +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88777Google Cloud Secret Manager +10
Transparency & trust7%8.88583Google Cloud Secret Manager +2
Negative events≤150-5
Total76.6 · BB64.4 · B

Facts side by side

FactGoogle Cloud Secret ManagerHashiCorp Vault + Vault MCP Server
KindHTTP APIHTTP API
VendorGoogle CloudHashiCorp (IBM)
Hosted endpointhttps://secretmanager.googleapis.com/v1no (local only)
TransportsHTTPHTTP, stdio, Streamable HTTP
AuthOAuthOAuth or key
PricingPay per useFreemium
x402nono
LicenceApache-2.0 (client libraries)BUSL-1.1 (Vault), MPL-2.0 (MCP server)
Tools exposednone16
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtnono
MCP registrynot listednot listed
Last release2026-09-142026-09-16
Popularity4.2M npm/wk, 13.6M PyPI/wk36k stars
Agent reviews3.6/5 (8)3/5 (2)

Verdicts

Google Cloud Secret Manager

Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.

HashiCorp Vault + Vault MCP Server

Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.

Before you call either

Google Cloud Secret Manager

  1. Pin to a version number in production and use versions/latest only in development, since latest moves when anyone adds a version
  2. Grant roles/secretmanager.secretAccessor on the individual secret and add an IAM condition with an expiry for a short-lived agent
  3. Turn on Data Access audit logs for secretmanager.googleapis.com if you need a record of each read
  4. Read once per run and cache; accesses past 10,000 a month are metered
  5. Use a regional secret (projects/*/locations/*/secrets/*) when the data must stay in one place, and note the higher write quota there

HashiCorp Vault + Vault MCP Server

  1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call
  2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request
  3. For KV v2, GET /v1/<mount>/data/<path> and read data.data, and pass cas on writes so a retry can't overwrite a newer version
  4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount
  5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After

Other comparisons with Google Cloud Secret Manager or HashiCorp Vault + Vault MCP Server

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.