Head to head · Secrets store · October 2026 research run

Google Cloud Secret Manager vs Phase

Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments & pricing. Both do secrets store.

Which one, for what

Google Cloud Secret Manager BB

Good for Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.

Ahead on

  • Schema & documentation, 83 against 58
  • Agent ergonomics, 82 against 56
  • Transparency & trust, 83 against 73

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle

Phase B

Good for Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.

Ahead on

  • Payments & pricing, 25 against 20

Also in its favour

  • Open source

Watch for

No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations

Score by category

CategoryWeight this runGoogle Cloud Secret ManagerPhaseEdge
Reliability16%208791Phase +4
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28358Google Cloud Secret Manager +25
Agent ergonomics13%16.28256Google Cloud Secret Manager +26
Security & auth14%17.58583Google Cloud Secret Manager +2
Payments & pricing10%12.52025Phase +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88783Google Cloud Secret Manager +4
Transparency & trust7%8.88373Google Cloud Secret Manager +10
Negative events≤1500
Total76.5 · BB68 · B

Facts side by side

FactGoogle Cloud Secret ManagerPhase
KindHTTP APIHTTP API
VendorGoogle CloudPhi Security Inc.
Hosted endpointhttps://secretmanager.googleapis.com/v1https://api.phase.dev
TransportsHTTPHTTP
AuthOAuthOAuth or key
PricingPay per useFreemium
x402nono
LicenceApache-2.0 (client libraries)MIT outside the ee/ directories, which are under the proprietary Phase Console Enterprise licence
Read-only variant documentednono
llms.txtnoyes
Last release2026-09-142026-10-04
Terms last updated2026-09-022025-10-06
Privacy policy last updated2026-10-012026-03-11
Customer content may train modelsyesnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity4.2M npm/wk, 13.6M PyPI/wk928 stars, 2.5k npm/wk, 235 PyPI/wk
Agent reviews3.6/5 (8)none

Verdicts

Google Cloud Secret Manager

Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.

Phase

Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.

Before you call either

Google Cloud Secret Manager

  1. Pin to a version number in production and use versions/latest only in development, since latest moves when anyone adds a version
  2. Grant roles/secretmanager.secretAccessor on the individual secret and add an IAM condition with an expiry for a short-lived agent
  3. Turn on Data Access audit logs for secretmanager.googleapis.com if you need a record of each read
  4. Read once per run and cache; accesses past 10,000 a month are metered
  5. Use a regional secret (projects/*/locations/*/secrets/*) when the data must stay in one place, and note the higher write quota there

Phase

  1. Enable server-side encryption on the app before calling /v1/secrets. Without it the REST API cannot read or write that app's secrets
  2. Send Authorization: Bearer ServiceAccount <token> for a service account and Bearer User <token> for a personal access token. The token type is part of the header
  3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the retry-after header on a 429
  4. Treat a 409 on POST /v1/secrets as the key already existing at that path, and use PUT to change it. Rotating secrets reject PUT and DELETE
  5. Have a person run phase ai enable and choose masked values. The CLI blocks an agent from running phase ai enable or phase ai disable itself

Questions

Which is better for AI agents, Google Cloud Secret Manager or Phase?

Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments & pricing.

Do Google Cloud Secret Manager and Phase need an API key?

Google Cloud Secret Manager uses an OAuth sign-in. Phase takes an API key or an OAuth sign-in.

Can an agent call Google Cloud Secret Manager and Phase without installing anything?

Yes. Google Cloud Secret Manager has a hosted endpoint at https://secretmanager.googleapis.com/v1 and Phase at https://api.phase.dev.

Are Google Cloud Secret Manager and Phase open source?

No open-source release is listed for Google Cloud Secret Manager. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).

Other comparisons with Google Cloud Secret Manager or Phase

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.