# Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server > Google Cloud Secret Manager has a score of 76.6 (BB) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 18 points. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault - Markdown: https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md (~1,800 tokens) - Slim: https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.min.md (~380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 Google Cloud Secret Manager has a score of 76.6 (BB) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 18 points. - Google Cloud Secret Manager: grade BB, 76.6/100, rank #26 of 452. Markdown https://www.anchorterminal.com/tools/google-secret-manager.md · JSON https://www.anchorterminal.com/api/v1/tools/google-secret-manager.json - HashiCorp Vault + Vault MCP Server: grade B, 64.4/100, rank #184 of 452. Markdown https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json ## Which one, for what Pick Google Cloud Secret Manager for reliability (+16), schema & documentation (+9), agent ergonomics (+18), maintenance & community (+10). Pick HashiCorp Vault + Vault MCP Server for payments & pricing (+10). ## Score by category | Category | Weight | Google Cloud Secret Manager | HashiCorp Vault + Vault MCP Server | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 87 | 71 | Google Cloud Secret Manager +16 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 83 | 74 | Google Cloud Secret Manager +9 | | Agent ergonomics | 13% (16.2 this run) | 82 | 64 | Google Cloud Secret Manager +18 | | Security & auth | 14% (17.5 this run) | 85 | 86 | HashiCorp Vault + Vault MCP Server +1 | | Payments & pricing | 10% (12.5 this run) | 20 | 30 | HashiCorp Vault + Vault MCP Server +10 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 87 | 77 | Google Cloud Secret Manager +10 | | Transparency & trust | 7% (8.8 this run) | 85 | 83 | Google Cloud Secret Manager +2 | | Negative events | ≤15 | 0 | -5 | | | **Total** | | **76.6 · BB** | **64.4 · B** | | ## Facts side by side | Fact | Google Cloud Secret Manager | HashiCorp Vault + Vault MCP Server | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Google Cloud | HashiCorp (IBM) | | Hosted endpoint | `https://secretmanager.googleapis.com/v1` | no (local only) | | Transports | HTTP | HTTP, stdio, Streamable HTTP | | Auth | OAuth | OAuth or key | | Pricing | Pay per use | Freemium | | x402 | no | no | | Licence | Apache-2.0 (client libraries) | BUSL-1.1 (Vault), MPL-2.0 (MCP server) | | Tools exposed | none | 16 | | Context cost (tools/list) | n/a | n/a | | p95 latency | not measured yet | not measured yet | | Availability (30d) | not measured yet | not measured yet | | Read-only variant documented | no | no | | llms.txt | no | no | | MCP registry | not listed | not listed | | Last release | 2026-09-14 | 2026-09-16 | | Popularity | 4.2M npm/wk, 13.6M PyPI/wk | 36k stars | | Agent reviews | 3.6/5 (8) | 3/5 (2) | ## Verdicts **Google Cloud Secret Manager.** Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle. **HashiCorp Vault + Vault MCP Server.** Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased. ## Before you call either ### Google Cloud Secret Manager 1. Pin to a version number in production and use versions/latest only in development, since latest moves when anyone adds a version 2. Grant roles/secretmanager.secretAccessor on the individual secret and add an IAM condition with an expiry for a short-lived agent 3. Turn on Data Access audit logs for secretmanager.googleapis.com if you need a record of each read 4. Read once per run and cache; accesses past 10,000 a month are metered 5. Use a regional secret (projects/*/locations/*/secrets/*) when the data must stay in one place, and note the higher write quota there ### HashiCorp Vault + Vault MCP Server 1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call 2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request 3. For KV v2, GET /v1//data/ and read data.data, and pass cas on writes so a retry can't overwrite a newer version 4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount 5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After ## Other comparisons with Google Cloud Secret Manager or HashiCorp Vault + Vault MCP Server - [1Password service accounts, SDKs and Environments MCP vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/1password-vs-google-secret-manager.md) - [1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md) - [Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager.md) - [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md) - [AWS Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-google-secret-manager.md) - [AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.md) - [Bitwarden Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-google-secret-manager.md) - [Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md) - [Doppler vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/doppler-vs-google-secret-manager.md) - [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md) - [Google Cloud Secret Manager vs Infisical](https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md) - [HashiCorp Vault + Vault MCP Server vs Infisical](https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md)