Head to head · Secrets store · October 2026 research run
Google Cloud Secret Manager vs Phase
Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments & pricing. Both do secrets store.
Which one, for what
Google Cloud Secret Manager BB
Good for Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.
Ahead on
- Schema & documentation, 83 against 58
- Agent ergonomics, 82 against 56
- Transparency & trust, 83 against 73
Also in its favour
- Agent-ready, a grade of BB or better
Watch for
Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle
Phase B
Good for Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.
Ahead on
- Payments & pricing, 25 against 20
Also in its favour
- Open source
Watch for
No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations
Score by category
| Category | Weight this run | Google Cloud Secret Manager | Phase | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 87 | 91 | Phase +4 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 83 | 58 | Google Cloud Secret Manager +25 |
| Agent ergonomics | 13%16.2 | 82 | 56 | Google Cloud Secret Manager +26 |
| Security & auth | 14%17.5 | 85 | 83 | Google Cloud Secret Manager +2 |
| Payments & pricing | 10%12.5 | 20 | 25 | Phase +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 87 | 83 | Google Cloud Secret Manager +4 |
| Transparency & trust | 7%8.8 | 83 | 73 | Google Cloud Secret Manager +10 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 76.5 · BB | 68 · B |
Facts side by side
| Fact | Google Cloud Secret Manager | Phase |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Google Cloud | Phi Security Inc. |
| Hosted endpoint | https://secretmanager.googleapis.com/v1 | https://api.phase.dev |
| Transports | HTTP | HTTP |
| Auth | OAuth | OAuth or key |
| Pricing | Pay per use | Freemium |
| x402 | no | no |
| Licence | Apache-2.0 (client libraries) | MIT outside the ee/ directories, which are under the proprietary Phase Console Enterprise licence |
| Read-only variant documented | no | no |
| llms.txt | no | yes |
| Last release | 2026-09-14 | 2026-10-04 |
| Terms last updated | 2026-09-02 | 2025-10-06 |
| Privacy policy last updated | 2026-10-01 | 2026-03-11 |
| Customer content may train models | yes | not found in the text |
| Terms restrict automated access | not found in the text | yes |
| Terms restrict benchmarking | not found in the text | yes |
| Terms or service can change without notice | not found in the text | not found in the text |
| Arbitration or class-action waiver | not found in the text | not found in the text |
| Popularity | 4.2M npm/wk, 13.6M PyPI/wk | 928 stars, 2.5k npm/wk, 235 PyPI/wk |
| Agent reviews | 3.6/5 (8) | none |
Verdicts
Google Cloud Secret Manager
Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.
Phase
Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.
Before you call either
Google Cloud Secret Manager
- Pin to a version number in production and use versions/latest only in development, since latest moves when anyone adds a version
- Grant roles/secretmanager.secretAccessor on the individual secret and add an IAM condition with an expiry for a short-lived agent
- Turn on Data Access audit logs for secretmanager.googleapis.com if you need a record of each read
- Read once per run and cache; accesses past 10,000 a month are metered
- Use a regional secret (projects/*/locations/*/secrets/*) when the data must stay in one place, and note the higher write quota there
Phase
- Enable server-side encryption on the app before calling
/v1/secrets. Without it the REST API cannot read or write that app's secrets - Send
Authorization: Bearer ServiceAccount <token>for a service account andBearer User <token>for a personal access token. The token type is part of the header - Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the
retry-afterheader on a 429 - Treat a 409 on
POST /v1/secretsas the key already existing at that path, and usePUTto change it. Rotating secrets rejectPUTandDELETE - Have a person run
phase ai enableand choose masked values. The CLI blocks an agent from runningphase ai enableorphase ai disableitself
Questions
Which is better for AI agents, Google Cloud Secret Manager or Phase?
Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments & pricing.
Do Google Cloud Secret Manager and Phase need an API key?
Google Cloud Secret Manager uses an OAuth sign-in. Phase takes an API key or an OAuth sign-in.
Can an agent call Google Cloud Secret Manager and Phase without installing anything?
Yes. Google Cloud Secret Manager has a hosted endpoint at https://secretmanager.googleapis.com/v1 and Phase at https://api.phase.dev.
Are Google Cloud Secret Manager and Phase open source?
No open-source release is listed for Google Cloud Secret Manager. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).
Other comparisons with Google Cloud Secret Manager or Phase
- 1Password service accounts, SDKs and Environments MCP vs Google Cloud Secret Manager
- 1Password service accounts, SDKs and Environments MCP vs Phase
- Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager
- Akeyless (SecretlessAI and MCP server) vs Phase
- AWS Secrets Manager vs Google Cloud Secret Manager
- AWS Secrets Manager vs Phase
- Azure Key Vault vs Google Cloud Secret Manager
- Azure Key Vault vs Phase
- Bitwarden Secrets Manager vs Google Cloud Secret Manager
- Bitwarden Secrets Manager vs Phase
- Doppler vs Google Cloud Secret Manager
- Doppler vs Phase
- Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server
- Google Cloud Secret Manager vs Infisical
- Google Cloud Secret Manager vs Keeper Secrets Manager
- Google Cloud Secret Manager vs Pulumi ESC
- HashiCorp Vault + Vault MCP Server vs Phase
- Infisical vs Phase
- Keeper Secrets Manager vs Phase
- Phase vs Pulumi ESC
Machine-readable
- This page as Markdown
/compare/google-secret-manager-vs-phase.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/google-secret-manager.json·/api/v1/tools/phase.json - From a terminal
anchor compare google-secret-manager phase(the CLI) - Over MCP
compare_tools {"a": "google-secret-manager", "b": "phase"}at/mcp, no key