{
  "data": {
    "a": {
      "slug": "google-secret-manager",
      "name": "Google Cloud Secret Manager",
      "vendor": "Google Cloud",
      "vendorUrl": "https://cloud.google.com/security/products/secret-manager",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Google Cloud's managed service for storing and accessing application secrets.",
      "url": "https://www.anchorterminal.com/tools/google-secret-manager",
      "markdownUrl": "https://www.anchorterminal.com/tools/google-secret-manager.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/google-secret-manager.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/google-secret-manager.json",
      "repo": "https://github.com/googleapis/google-cloud-python",
      "license": "Apache-2.0 (client libraries)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://secretmanager.googleapis.com/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@google-cloud/secret-manager"
        },
        {
          "registry": "pypi",
          "name": "google-cloud-secret-manager"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 bearer tokens from a Google service account or workload identity (GKE, Cloud Run, GCE metadata server) with the cloud-platform scope. Grant roles/secretmanager.secretAccessor on the secret, not the project, and add IAM conditions for time or version limits. API keys don't work here.",
      "pricing": "usage",
      "pricingNotes": "$0.06 per active secret version per location a month (billed hourly at $0.000082192), $0.03 per 10,000 access operations and $0.05 per rotation notification. Management operations are free. Always free each month for 6 active versions, 10,000 access operations and 3 rotation notifications, and new customers get $300 of trial credit. A user-managed replication policy is charged per location; automatic replication counts as one (https://cloud.google.com/secret-manager/pricing).",
      "priceSummary": "$0.06 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 4224871,
        "pypiWeekly": 13586494,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.cloud.google.com/secret-manager/docs",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "infra.cloud"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "usage-priced",
        "free-tier",
        "card-required",
        "typescript",
        "python",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 28,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 82,
          "maintenance": 87,
          "payments": 20,
          "reliability": 87,
          "schema": 83,
          "security": 85,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.",
        "bestFor": "Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.",
        "strengths": [
          "Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused",
          "$0.06 a version a month and $0.03 per 10,000 accesses, with 6 versions and 10,000 accesses a month free",
          "IAM conditions and per-secret roles, with version_destroy_ttl to delay destruction",
          "Regional secrets for data residency and multi-region storage in US, EU, Canada and India",
          "99.95% SLA with credits, and five dated release notes between 12 July and 14 September 2026"
        ],
        "weaknesses": [
          "Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle",
          "Secret reads are Data Access audit logs, which you have to enable",
          "Global secrets accept only 2 version writes a second, and AddSecretVersion has no request ID for safe retries",
          "No llms.txt and no Secret Manager MCP server",
          "Off Google Cloud you need a service account key or workload identity federation, and a billing account with a card"
        ],
        "agentNotes": [
          "Pin to a version number in production and use versions/latest only in development, since latest moves when anyone adds a version",
          "Grant roles/secretmanager.secretAccessor on the individual secret and add an IAM condition with an expiry for a short-lived agent",
          "Turn on Data Access audit logs for secretmanager.googleapis.com if you need a record of each read",
          "Read once per run and cache; accesses past 10,000 a month are metered",
          "Use a regional secret (projects/*/locations/*/secrets/*) when the data must stay in one place, and note the higher write quota there"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.6,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.5
          }
        ],
        "editorialScores": {
          "ergonomics": 82,
          "maintenance": 87,
          "payments": 20,
          "reliability": 87,
          "schema": 83,
          "security": 85,
          "transparency": 69
        },
        "provenanceScore": 97
      },
      "connect": {
        "install": "pip install google-cloud-secret-manager   # or: npm i @google-cloud/secret-manager",
        "http": "curl \"https://secretmanager.googleapis.com/v1/projects/$GOOGLE_CLOUD_PROJECT/secrets/db-password/versions/latest:access\" \\\n  -H \"Authorization: Bearer $(gcloud auth print-access-token)\""
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/google-secret-manager"
      },
      "sameCompany": [
        "gemini-api",
        "gemini-embedding",
        "vertex-ai-tuning",
        "google-model-armor",
        "google-imagen",
        "google-veo",
        "google-lyria",
        "google-speech-to-text",
        "google-adk",
        "google-weather-api",
        "chrome-devtools-mcp",
        "google-maps-platform",
        "google-cloud-translation",
        "google-calendar-api",
        "google-drive-api",
        "gemini-cli",
        "google-ads-api",
        "google-forms",
        "google-sheets-api",
        "gmail-api"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active secret version",
          "unit": "month",
          "usd": 0.06,
          "note": "Per version per location a month"
        },
        {
          "item": "Access operations",
          "unit": "1k-calls",
          "usd": 0.003,
          "note": "$0.03 per 10,000 operations"
        },
        {
          "item": "Rotation notification",
          "unit": "message",
          "usd": 0.05,
          "note": "Per SECRET_ROTATE message to Pub/Sub"
        }
      ],
      "provenance": {
        "legalEntity": "Google LLC (Google Cloud EMEA Limited and other regional entities by billing address)",
        "domain": "google.com",
        "domainRegistered": "1997-09-15",
        "domainNote": "The API lives at secretmanager.googleapis.com and the docs at docs.cloud.google.com, both Google domains.",
        "endpointOnVendorDomain": true,
        "terms": "https://cloud.google.com/terms",
        "privacy": "https://policies.google.com/privacy",
        "statusPage": "https://status.cloud.google.com",
        "changelog": "https://docs.cloud.google.com/secret-manager/docs/release-notes",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The Google Cloud Platform Terms of Service point to cloud.google.com/terms/google-entity, which names Google LLC for the United States and fourteen regional entities including Google Cloud EMEA Limited.",
          "www.google.com/.well-known/security.txt expires 2030-04-01 (30 September check).",
          "status.cloud.google.com/incidents.json had no incident tagged Secret Manager between 1 July and 1 October 2026.",
          "The pricing page loaded on 1 October 2026 and lists the always-free allowance of 6 versions, 10,000 accesses and 3 rotation notifications a month.",
          "The subprocessor page was last modified on 20 August 2026 and links the Cloud Data Processing Addendum."
        ],
        "score": 97
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/google-secret-manager.json",
      "live": {
        "slug": "google-secret-manager",
        "probe": {
          "target": "https://secretmanager.googleapis.com/v1",
          "method": "get",
          "lastAt": "2026-10-08T21:12:11.415558586Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 29,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 35,
          "p95ms24h": 81,
          "samples24h": 271,
          "samples30d": 1955,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 239,
              "ok": 239
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "googleapis/google-cloud-python",
            "version": "google-auth-v2.61.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:14:19.243033021Z"
          },
          {
            "registry": "npm",
            "name": "@google-cloud/secret-manager",
            "version": "7.1.1",
            "seenAt": "2026-10-08T16:14:15.37577128Z"
          },
          {
            "registry": "pypi",
            "name": "google-cloud-secret-manager",
            "version": "2.31.0",
            "released": "2026-10-01",
            "seenAt": "2026-10-08T16:14:19.119689656Z"
          }
        ],
        "githubStars": 5401,
        "npmWeekly": 4664529,
        "pypiWeekly": 13591147,
        "securityTxt": {
          "url": "https://google.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2030-04-01T00:00:00z",
          "checkedAt": "2026-10-08T15:38:39.75078566Z"
        },
        "domain": {
          "domain": "google.com",
          "registered": "1997-09-15",
          "source": "https://rdap.verisign.com/com/v1/domain/google.com",
          "checkedAt": "2026-10-04T13:05:50.737985829Z"
        },
        "pages": [
          {
            "url": "https://docs.cloud.google.com/secret-manager/docs/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:30.080131117Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3ec2c74e5d97"
          },
          {
            "url": "https://cloud.google.com/secret-manager/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:19.976120288Z",
            "changedAt": "2026-10-08T18:16:19.976120288Z",
            "fingerprint": "c83325265c1d"
          }
        ],
        "updatedAt": "2026-10-08T21:12:11.415558586Z"
      }
    },
    "answer": "Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments \u0026 pricing.",
    "b": {
      "slug": "phase",
      "name": "Phase",
      "vendor": "Phi Security Inc.",
      "vendorUrl": "https://phase.dev",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Phase is an open-source secrets manager from Phi Security Inc. with end-to-end encryption, service accounts, secret rotation and audit logs. Agents reach it through a REST API, a CLI and SDKs, on Phase Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/phase",
      "markdownUrl": "https://www.anchorterminal.com/tools/phase.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/phase.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/phase.json",
      "repo": "https://github.com/phasehq/console",
      "license": "MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.phase.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@phase.dev/phase-node"
        },
        {
          "registry": "pypi",
          "name": "phase-dev"
        },
        {
          "registry": "go",
          "name": "github.com/phasehq/golang-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs in to the console with Google, GitHub or GitLab, creates a service account and a token with an optional expiry, and the agent sends it as `Authorization: Bearer ServiceAccount \u003ctoken\u003e`. Personal access tokens use `Bearer User \u003ctoken\u003e` and inherit the user's role. Tokens can also be created and deleted over the API for service accounts with server-side key management. Workloads on AWS or Azure can log in with an external identity and receive a token with a TTL. Access follows the account's role and its apps and environments, not the individual token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 5 users or service accounts, 3 apps, 3 environments, 24-hour audit logs and 120 API requests a minute. Pro is $10 a user a month ($120 billed yearly) with a 14-day trial, unlimited apps, rotation, custom roles, network access policies, 90-day audit logs and 240 requests a minute. Enterprise is $25 a user a month ($300 yearly) with dynamic secrets, OIDC SSO, SCIM, log forwarding and a 99.99 per cent uptime SLA listed. Only human users are charged, and service accounts are free. The pricing page does not say whether a card is taken. Self-hosting the MIT core is free, and the Pro and Enterprise tiers need a licence (https://phase.dev/pricing/).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the API reference or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 928,
        "npmWeekly": 2485,
        "pypiWeekly": 235,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.phase.dev",
      "llmsTxt": "https://docs.phase.dev/llms.txt",
      "capabilities": [
        "secrets.store",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "secrets.rotate"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "cli",
        "llms-txt",
        "go",
        "typescript",
        "python",
        "eu",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-04",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 194,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 56,
          "maintenance": 83,
          "payments": 25,
          "reliability": 91,
          "schema": 58,
          "security": 83,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.",
        "bestFor": "Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.",
        "strengths": [
          "Service account tokens take an expiry and can be created and deleted through `/v1/service-accounts/:id/tokens`, and service accounts are free on every plan",
          "The CLI's AI mode redacts `secret` and `sealed` values and blocks `printenv`, `env` and `phase shell` when it detects an agent",
          "Every reveal and every REST fetch of a secret is recorded as a `READ` event with actor and IP address",
          "MIT outside the `ee/` directories, self-hosted with Docker Compose or Kubernetes, with no outbound usage telemetry per the docs",
          "Eleven console versions between 24 July and 8 October 2026, and no incident on the status page since 30 June 2026"
        ],
        "weaknesses": [
          "No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations",
          "No pagination, field selection or idempotency keys were found in the API reference, and errors are a single free-text `error` string",
          "The Free plan keeps audit logs for 24 hours. Rotation, custom roles and network access policies need Pro, and dynamic secrets need Enterprise",
          "The REST API works only on apps with server-side encryption enabled, which gives up end-to-end encryption for that app",
          "The pricing page lists a Phase Agents Relay credential proxy on every plan, but no documentation or CLI command for it was found"
        ],
        "agentNotes": [
          "Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets",
          "Send `Authorization: Bearer ServiceAccount \u003ctoken\u003e` for a service account and `Bearer User \u003ctoken\u003e` for a personal access token. The token type is part of the header",
          "Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429",
          "Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE`",
          "Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 56,
          "maintenance": 83,
          "payments": 25,
          "reliability": 91,
          "schema": 58,
          "security": 83,
          "transparency": 58
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "curl -fsSL https://pkg.phase.dev/install.sh | sh   # or: brew tap phasehq/cli \u0026\u0026 brew install phase",
        "http": "curl -G https://api.phase.dev/v1/secrets/ -H \"Authorization: Bearer ServiceAccount $PHASE_TOKEN\" \\\n  -d app_id=$PHASE_APP_ID -d env=development",
        "claudeCode": "phase ai enable"
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/phase"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 10,
          "note": "$120 a user billed yearly. Service accounts free"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "$300 a user billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Phi Security Inc.",
        "domain": "phase.dev",
        "domainRegistered": "2023-02-03",
        "endpointOnVendorDomain": true,
        "terms": "https://phase.dev/legal/terms/",
        "privacy": "https://phase.dev/legal/privacy/",
        "statusPage": "https://phase.statuspage.io",
        "changelog": "https://phase.dev/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 6 October 2025) name Phi Security Inc. and cover the website, the Phase Console and the self-hosted version. The site footer gives 8 The Green, Ste A, Dover, DE 19901, United States.",
          "The privacy policy (last updated 11 March 2026) covers phase.dev and the services, gives no retention period in days and refers to the trust centre for the subprocessor list.",
          "security.txt at phase.dev expires on 10 December 2030, lists three contact addresses and points to `SECURITY.md` in the console repository.",
          "trust.phase.dev is drawn by script and gave our reader no text, so the subprocessor list and any DPA were not read.",
          "RDAP for phase.dev gives a registration date of 2023-02-03.",
          "The status page is an Atlassian Statuspage at phase.statuspage.io with components for the console, the API, Cloudflare and AWS eu-central-1."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/phase.json",
      "live": {
        "slug": "phase",
        "probe": {
          "target": "https://api.phase.dev",
          "method": "get",
          "lastAt": "2026-10-08T21:12:18.362967625Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 136,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 126,
          "p95ms24h": 199,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://phase.statuspage.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:21.645663435Z"
        },
        "updatedAt": "2026-10-08T21:12:18.362967625Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Google Cloud",
        "b": "Phi Security Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://secretmanager.googleapis.com/v1",
        "b": "https://api.phase.dev",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (client libraries)",
        "b": "MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-14",
        "b": "2026-10-04",
        "name": "Last release"
      },
      {
        "a": "2026-09-02",
        "b": "2025-10-06",
        "name": "Terms last updated"
      },
      {
        "a": "2026-10-01",
        "b": "2026-03-11",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.2M npm/wk, 13.6M PyPI/wk",
        "b": "928 stars, 2.5k npm/wk, 235 PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3.6/5 (8)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Google Cloud Secret Manager or Phase?"
      },
      {
        "answer": "Google Cloud Secret Manager uses an OAuth sign-in. Phase takes an API key or an OAuth sign-in.",
        "question": "Do Google Cloud Secret Manager and Phase need an API key?"
      },
      {
        "answer": "Yes. Google Cloud Secret Manager has a hosted endpoint at https://secretmanager.googleapis.com/v1 and Phase at https://api.phase.dev.",
        "question": "Can an agent call Google Cloud Secret Manager and Phase without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Google Cloud Secret Manager. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).",
        "question": "Are Google Cloud Secret Manager and Phase open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 83 against 58",
          "Agent ergonomics, 82 against 56",
          "Transparency \u0026 trust, 83 against 73"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.",
        "slug": "google-secret-manager",
        "watchFor": "Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 25 against 20"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.",
        "slug": "phase",
        "watchFor": "No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations"
      }
    ],
    "job": {
      "capability": "secrets.store",
      "name": "Secrets store"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-google-secret-manager.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs Google Cloud Secret Manager",
        "url": "https://www.anchorterminal.com/compare/1password-vs-google-secret-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-phase.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs Phase",
        "url": "https://www.anchorterminal.com/compare/1password-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-phase.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Phase",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-google-secret-manager.json",
        "title": "AWS Secrets Manager vs Google Cloud Secret Manager",
        "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-google-secret-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.json",
        "title": "AWS Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-key-vault-vs-google-secret-manager.json",
        "title": "Azure Key Vault vs Google Cloud Secret Manager",
        "url": "https://www.anchorterminal.com/compare/azure-key-vault-vs-google-secret-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.json",
        "title": "Azure Key Vault vs Phase",
        "url": "https://www.anchorterminal.com/compare/azure-key-vault-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-google-secret-manager.json",
        "title": "Bitwarden Secrets Manager vs Google Cloud Secret Manager",
        "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-google-secret-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.json",
        "title": "Bitwarden Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/doppler-vs-google-secret-manager.json",
        "title": "Doppler vs Google Cloud Secret Manager",
        "url": "https://www.anchorterminal.com/compare/doppler-vs-google-secret-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/doppler-vs-phase.json",
        "title": "Doppler vs Phase",
        "url": "https://www.anchorterminal.com/compare/doppler-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.json",
        "title": "Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.json",
        "title": "Google Cloud Secret Manager vs Infisical",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.json",
        "title": "Google Cloud Secret Manager vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-pulumi-esc.json",
        "title": "Google Cloud Secret Manager vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-pulumi-esc"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.json",
        "title": "HashiCorp Vault + Vault MCP Server vs Phase",
        "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/infisical-vs-phase.json",
        "title": "Infisical vs Phase",
        "url": "https://www.anchorterminal.com/compare/infisical-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.json",
        "title": "Keeper Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.json",
        "title": "Phase vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/phase-vs-pulumi-esc"
      }
    ],
    "scores": [
      {
        "by": 4,
        "edge": "phase",
        "google-secret-manager": 87,
        "key": "reliability",
        "name": "Reliability",
        "phase": 91,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "edge": "google-secret-manager",
        "google-secret-manager": 83,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "phase": 58,
        "weight": 13
      },
      {
        "by": 26,
        "edge": "google-secret-manager",
        "google-secret-manager": 82,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "phase": 56,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "google-secret-manager",
        "google-secret-manager": 85,
        "key": "security",
        "name": "Security \u0026 auth",
        "phase": 83,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "phase",
        "google-secret-manager": 20,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "phase": 25,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "google-secret-manager",
        "google-secret-manager": 87,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "phase": 83,
        "weight": 7
      },
      {
        "by": 10,
        "edge": "google-secret-manager",
        "google-secret-manager": 83,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "phase": 73,
        "weight": 7
      }
    ],
    "summary": "Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments \u0026 pricing. Both do secrets store.",
    "verdicts": {
      "google-secret-manager": "Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.",
      "phase": "Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase",
    "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.md",
    "slim": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.min.md"
  },
  "markdown": "Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments \u0026 pricing. Both do secrets store.\n\n- Google Cloud Secret Manager: grade BB, 76.5/100, rank #28 of 722. Markdown https://www.anchorterminal.com/tools/google-secret-manager.md · JSON https://www.anchorterminal.com/api/v1/tools/google-secret-manager.json\n- Phase: grade B, 68/100, rank #194 of 722. Markdown https://www.anchorterminal.com/tools/phase.md · JSON https://www.anchorterminal.com/api/v1/tools/phase.json\n\n## Which one, for what\n\n### Google Cloud Secret Manager (BB)\n\nGood for: Agents on GKE, Cloud Run or GCE that should read secrets through workload identity with per-secret, time-bound grants.\n\nAhead on:\n- Schema \u0026 documentation, 83 against 58\n- Agent ergonomics, 82 against 56\n- Transparency \u0026 trust, 83 against 73\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle\n\n### Phase (B)\n\nGood for: Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.\n\nAhead on:\n- Payments \u0026 pricing, 25 against 20\n\nAlso in its favour:\n- Open source\n\nWatch for: No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations\n\n\n## Score by category\n\n| Category | Weight | Google Cloud Secret Manager | Phase | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 87 | 91 | Phase +4 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 83 | 58 | Google Cloud Secret Manager +25 |\n| Agent ergonomics | 13% (16.2 this run) | 82 | 56 | Google Cloud Secret Manager +26 |\n| Security \u0026 auth | 14% (17.5 this run) | 85 | 83 | Google Cloud Secret Manager +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 25 | Phase +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 87 | 83 | Google Cloud Secret Manager +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 73 | Google Cloud Secret Manager +10 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **76.5 · BB** | **68 · B** | |\n\n## Facts side by side\n\n| Fact | Google Cloud Secret Manager | Phase |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Google Cloud | Phi Security Inc. |\n| Hosted endpoint | `https://secretmanager.googleapis.com/v1` | `https://api.phase.dev` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Pay per use | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (client libraries) | MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | 2026-09-14 | 2026-10-04 |\n| Terms last updated | 2026-09-02 | 2025-10-06 |\n| Privacy policy last updated | 2026-10-01 | 2026-03-11 |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 4.2M npm/wk, 13.6M PyPI/wk | 928 stars, 2.5k npm/wk, 235 PyPI/wk |\n| Agent reviews | 3.6/5 (8) | none |\n\n## Verdicts\n\n**Google Cloud Secret Manager.** Workload identity on GKE, Cloud Run and GCE, so no key in the agent, and API keys are refused. Managed rotation only covers Cloud SQL; other rotation is a Pub/Sub notification you handle.\n\n**Phase.** Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.\n\n## Before you call either\n\n### Google Cloud Secret Manager\n\n1. Pin to a version number in production and use versions/latest only in development, since latest moves when anyone adds a version\n2. Grant roles/secretmanager.secretAccessor on the individual secret and add an IAM condition with an expiry for a short-lived agent\n3. Turn on Data Access audit logs for secretmanager.googleapis.com if you need a record of each read\n4. Read once per run and cache; accesses past 10,000 a month are metered\n5. Use a regional secret (projects/*/locations/*/secrets/*) when the data must stay in one place, and note the higher write quota there\n\n### Phase\n\n1. Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets\n2. Send `Authorization: Bearer ServiceAccount \u003ctoken\u003e` for a service account and `Bearer User \u003ctoken\u003e` for a personal access token. The token type is part of the header\n3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429\n4. Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE`\n5. Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself\n\n## Questions\n\n### Which is better for AI agents, Google Cloud Secret Manager or Phase?\n\nGoogle Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments \u0026 pricing.\n\n### Do Google Cloud Secret Manager and Phase need an API key?\n\nGoogle Cloud Secret Manager uses an OAuth sign-in. Phase takes an API key or an OAuth sign-in.\n\n### Can an agent call Google Cloud Secret Manager and Phase without installing anything?\n\nYes. Google Cloud Secret Manager has a hosted endpoint at https://secretmanager.googleapis.com/v1 and Phase at https://api.phase.dev.\n\n### Are Google Cloud Secret Manager and Phase open source?\n\nNo open-source release is listed for Google Cloud Secret Manager. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.json, and with the fewest tokens: https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"google-secret-manager\", \"b\": \"phase\"}`. From a terminal: `anchor compare google-secret-manager phase`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/google-secret-manager.json and https://www.anchorterminal.com/api/v1/tools/phase.json\n\n## Other comparisons with Google Cloud Secret Manager or Phase\n\n- [1Password service accounts, SDKs and Environments MCP vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/1password-vs-google-secret-manager.md)\n- [1Password service accounts, SDKs and Environments MCP vs Phase](https://www.anchorterminal.com/compare/1password-vs-phase.md)\n- [Akeyless (SecretlessAI and MCP server) vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/akeyless-vs-google-secret-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Phase](https://www.anchorterminal.com/compare/akeyless-vs-phase.md)\n- [AWS Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-google-secret-manager.md)\n- [AWS Secrets Manager vs Phase](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.md)\n- [Azure Key Vault vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/azure-key-vault-vs-google-secret-manager.md)\n- [Azure Key Vault vs Phase](https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.md)\n- [Bitwarden Secrets Manager vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-google-secret-manager.md)\n- [Bitwarden Secrets Manager vs Phase](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.md)\n- [Doppler vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/doppler-vs-google-secret-manager.md)\n- [Doppler vs Phase](https://www.anchorterminal.com/compare/doppler-vs-phase.md)\n- [Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md)\n- [Google Cloud Secret Manager vs Infisical](https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md)\n- [Google Cloud Secret Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.md)\n- [Google Cloud Secret Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/google-secret-manager-vs-pulumi-esc.md)\n- [HashiCorp Vault + Vault MCP Server vs Phase](https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.md)\n- [Infisical vs Phase](https://www.anchorterminal.com/compare/infisical-vs-phase.md)\n- [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md)\n- [Phase vs Pulumi ESC](https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Google Cloud Secret Manager vs Phase",
        "url": ""
      }
    ],
    "description": "Google Cloud Secret Manager scores 76.5 (BB) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on payments \u0026 pricing. Both do secrets store. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Google Cloud Secret Manager BB 76.5",
      "Phase B 68",
      "scores"
    ],
    "h1": "Google Cloud Secret Manager vs Phase",
    "image": "https://www.anchorterminal.com/assets/og/compare-google-secret-manager-vs-phase.png",
    "path": "/compare/google-secret-manager-vs-phase",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Google Cloud Secret Manager vs Phase for AI agents, BB 76.5 vs B 68",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase"
  },
  "tokens": {
    "markdown": 2550,
    "slim": 680
  },
  "version": 1
}
