{
  "data": {
    "a": {
      "slug": "hashicorp-vault",
      "name": "HashiCorp Vault + Vault MCP Server",
      "vendor": "HashiCorp (IBM)",
      "vendorUrl": "https://developer.hashicorp.com/vault",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Secrets management platform for storing credentials and controlling application access.",
      "url": "https://www.anchorterminal.com/tools/hashicorp-vault",
      "markdownUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json",
      "repo": "https://github.com/hashicorp/vault",
      "license": "BUSL-1.1 (Vault), MPL-2.0 (MCP server)",
      "transports": [
        "http",
        "stdio",
        "streamable-http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Every request carries a Vault token in `X-Vault-Token` (or as an HTTP bearer token). Machines get a token from an auth method such as AppRole, Kubernetes, JWT/OIDC, AWS, GCP, Azure, TLS certificates and more. Enterprise 2.0.3+ lets a registered agent present an OAuth 2.0 JWT from your identity provider directly, with RAR claims (RFC 9396) narrowing paths. The MCP server reads VAULT_ADDR, VAULT_TOKEN and VAULT_NAMESPACE, or takes them as headers in HTTP mode.",
      "pricing": "freemium",
      "pricingNotes": "Vault Community is free to run under the BUSL-1.1, which forbids selling a competing hosted product. HCP Vault Dedicated is hourly per cluster on the IBM price list. Development extra small $0.61644 an hour, Essentials small $1.57799, medium $3.16299, large $7.48857, Standard small $1.84299, medium $3.69099, large $9.40599, plus $72.92 a month per product client. Prices are indicative and exclude tax. Vault Enterprise self-managed is quoted, and the 2.1.0 licence added Agentic IAM terms. HCP has a $500 pay-as-you-go credit (https://www.ibm.com/products/hashicorp/pricing, https://www.hashicorp.com/en/pricing).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 16,
      "popularity": {
        "githubStars": 36234,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.hashicorp.com/vault/docs",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "auth.agent-identity"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "freemium",
        "mcp",
        "local",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.4,
        "grade": "B",
        "agentReady": false,
        "rank": 184,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 77,
          "payments": 30,
          "reliability": 71,
          "schema": 74,
          "security": 86,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-4: The official Vault MCP server fixed cross-user credential inheritance through a shared MCP session ID on 2026-07-28 and an SSRF through a VAULT_ADDR query parameter on 2026-08-11, but the newest binary and Docker image are still 0.2.0 from 2025-09-24 and no advisory was published (https://github.com/hashicorp/vault-mcp-server/commits/main, https://releases.hashicorp.com/vault-mcp-server/)",
          "-1: Vault 2.0.3 (2026-06-17) fixed a LIST ACL bypass where a trailing slash skipped a more specific deny rule; fixed and documented in the changelog, so it decays (https://github.com/hashicorp/vault/blob/main/CHANGELOG.md)"
        ],
        "verdict": "Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.",
        "strengths": [
          "Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after",
          "Path policies with explicit deny, audit devices on every edition, and Agent Registry with ceiling policies on Enterprise",
          "Auth methods for every major cloud, Kubernetes, JWT/OIDC and AppRole",
          "Three releases between 4 August and 16 September 2026 with a dated changelog that names each CVE fixed",
          "Each server generates its own OpenAPI document at /v1/sys/internal/specs/openapi"
        ],
        "weaknesses": [
          "The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased",
          "Agentic IAM, control groups and the OAuth resource server are Enterprise only",
          "BUSL-1.1, not an OSI licence, and HCP Vault Secrets was retired within two years of launch",
          "No llms.txt, and the only official client library is Go",
          "HCP client pricing ($72.92 a client a month) can dwarf the cluster price for many agents, and no SLA is published"
        ],
        "agentNotes": [
          "Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call",
          "Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request",
          "For KV v2, GET /v1/\u003cmount\u003e/data/\u003cpath\u003e and read data.data, and pass cas on writes so a retry can't overwrite a newer version",
          "If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount",
          "Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.4
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 77,
          "payments": 30,
          "reliability": 71,
          "schema": 74,
          "security": 86,
          "transparency": 65
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "docker run --rm -p 8200:8200 hashicorp/vault server -dev   # or download vault-mcp-server from releases.hashicorp.com",
        "http": "curl -H \"X-Vault-Token: $VAULT_TOKEN\" \"$VAULT_ADDR/v1/secret/data/myapp\"",
        "claudeCode": "claude mcp add vault -e VAULT_ADDR=$VAULT_ADDR -e VAULT_TOKEN=$VAULT_TOKEN -- vault-mcp-server stdio",
        "config": {
          "mcpServers": {
            "vault": {
              "args": [
                "run",
                "-i",
                "--rm",
                "-e",
                "VAULT_ADDR",
                "-e",
                "VAULT_TOKEN",
                "hashicorp/vault-mcp-server"
              ],
              "command": "docker",
              "env": {
                "VAULT_ADDR": "${VAULT_ADDR}",
                "VAULT_TOKEN": "${VAULT_TOKEN}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/hashicorp-vault"
      },
      "sameCompany": [
        "terraform-mcp"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "HCP Vault Dedicated, product client",
          "unit": "account-month",
          "usd": 72.92,
          "note": "Per client a month, Essentials and Standard"
        }
      ],
      "provenance": {
        "legalEntity": "HashiCorp, Inc. (an IBM company)",
        "domain": "hashicorp.com",
        "domainRegistered": "2011-04-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.hashicorp.com/en/terms-of-service",
        "privacy": "https://www.hashicorp.com/en/privacy",
        "statusPage": "https://status.hashicorp.com",
        "changelog": "https://github.com/hashicorp/vault/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The website terms name HashiCorp, Inc. and were last updated March 2018. The privacy policy (20 April 2026) gives HashiCorp, an IBM Company, c/o 1 North Castle Drive, Armonk, New York, and notes the IBM acquisition closed on 27 February 2025.",
          "security.txt has Contact, Policy and Encryption but no Expires field.",
          "HCP prices come from the IBM price table and are marked indicative, varying by country.",
          "status.hashicorp.com runs on incident.io. From 1 July to 1 October 2026 it posted nothing against HCP Vault Dedicated; it did post a DR cluster creation failure on HCP (6 August) and a releases.hashicorp.com outage (26 September).",
          "The Vault MCP server's newest published build is 0.2.0 (24 September 2025) on releases.hashicorp.com and Docker Hub, although its VERSION file and changelog say 0.2.1."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.json",
      "live": {
        "slug": "hashicorp-vault",
        "vendorStatus": {
          "page": "https://status.hashicorp.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T00:53:52.579494533Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "hashicorp/vault",
            "version": "v2.1.1",
            "released": "2026-09-16",
            "seenAt": "2026-10-04T16:29:29.320950791Z"
          }
        ],
        "githubStars": 36339,
        "securityTxt": {
          "url": "https://hashicorp.com/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-04T15:16:00.556489725Z"
        },
        "domain": {
          "domain": "hashicorp.com",
          "registered": "2011-04-30",
          "source": "https://rdap.verisign.com/com/v1/domain/hashicorp.com",
          "checkedAt": "2026-10-04T13:10:23.718306751Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/hashicorp/vault/main/CHANGELOG.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:41.235618427Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0620845f2f7e"
          },
          {
            "url": "https://www.ibm.com/support/pages/hcp-vault-secrets-end-life",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:50.575718841Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e24e2e2b51c3"
          },
          {
            "url": "https://www.hashicorp.com/en/pricing",
            "kind": "pricing",
            "status": 429,
            "checkedAt": "2026-10-04T15:50:36.37620806Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.ibm.com/products/hashicorp/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:50:46.127664694Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0e262eb503c4"
          },
          {
            "url": "https://www.hashicorp.com/en/privacy",
            "kind": "privacy",
            "status": 429,
            "checkedAt": "2026-10-04T15:50:38.389849123Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.hashicorp.com/en/terms-of-service",
            "kind": "terms",
            "status": 429,
            "checkedAt": "2026-10-04T15:50:40.386204192Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-05T00:53:52.579494533Z"
      }
    },
    "b": {
      "slug": "infisical",
      "name": "Infisical",
      "vendor": "Infisical",
      "vendorUrl": "https://infisical.com",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Open-source secrets manager with machine identities (Universal Auth, OIDC, AWS, GCP, Azure, Kubernetes, SPIFFE), dynamic secrets, rotation and audit logs, hosted in the US or EU or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/infisical",
      "markdownUrl": "https://www.anchorterminal.com/tools/infisical.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/infisical.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/infisical.json",
      "repo": "https://github.com/Infisical/infisical",
      "license": "MIT (core), proprietary under ee/",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://app.infisical.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "@infisical/sdk"
        },
        {
          "registry": "pypi",
          "name": "infisicalsdk"
        },
        {
          "registry": "npm",
          "name": "@infisical/cli"
        },
        {
          "registry": "npm",
          "name": "@infisical/mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "Machine identities log in with Universal Auth (client ID and secret posted to /api/v1/auth/universal-auth/login), Token Auth, OIDC, JWT, or native AWS, Azure, GCP, Kubernetes, OCI, AliCloud, LDAP, TLS certificate or SPIFFE auth, and get a short-lived access token (`st.…`, default TTL 7,200 s) sent as a Bearer header. Revoke it at /api/v1/auth/token/revoke. Agent Vault sessions use a separate session token that only works against the proxy. The docs MCP server at infisical.com/docs/mcp needs no auth.",
      "pricing": "freemium",
      "pricingNotes": "Free, Pro, Advanced and Enterprise plans on Infisical Cloud. Free is $0 with 5 identities, 3 environments, no audit logs, no rotation and no dynamic secrets, and needs no card. Pro is $20 per identity a month billed yearly ($23 monthly) with 30-day audit logs and rotation. Advanced is $40 per identity a month billed yearly ($46 monthly) with 90-day audit logs, dynamic secrets and higher rate limits. Pro and Advanced trials need no card. Enterprise is custom. Agent Proxy is on Free and Pro for static secrets. Cloud rate limits are per client IP, 600 requests a minute overall, then Free 200 reads, 90 writes and 120 secret operations a minute, Pro 350, 200 and 300. Self-hosting the MIT core is free with no rate limits; the code under ee/ needs an Enterprise licence (https://infisical.com/pricing, https://infisical.com/docs/api-reference/overview/rate-limits).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 10,
      "popularity": {
        "githubStars": 28405,
        "npmWeekly": 305133,
        "pypiWeekly": 391329,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://infisical.com/docs",
      "llmsTxt": "https://infisical.com/docs/llms.txt",
      "openapi": "https://app.infisical.com/api/docs/json",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "auth.agent-identity"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 81.9,
        "grade": "A",
        "agentReady": true,
        "rank": 4,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 91,
          "maintenance": 90,
          "payments": 30,
          "reliability": 90,
          "schema": 87,
          "security": 91,
          "transparency": 85
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.",
        "strengths": [
          "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them",
          "Thirteen machine identity auth methods with short-lived, revocable access tokens",
          "MIT core that self-hosts with no API rate limits, plus US and EU cloud regions",
          "Official MCP server with 10 annotated tools, a tool allowlist and optional value masking",
          "48 tagged releases between 3 July and 23 September 2026, each with an upgrade-impact note"
        ],
        "weaknesses": [
          "Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month",
          "Cloud rate limits are per client IP, so agents behind one NAT share 600 requests a minute",
          "The MCP server returns secret values unless INFISICAL_MASK_SECRET_VALUES is set, and it's still version 0.0.x",
          "Agent Vault session tokens travel to the proxy unencrypted, and the feature sits under the proprietary ee/ licence",
          "No SLA found, and every listed subprocessor is in the United States despite the EU region"
        ],
        "agentNotes": [
          "Run a coding agent under `infisical agent-vault run` with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length",
          "Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value",
          "Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit",
          "Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets",
          "On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.8,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 81.9
          }
        ],
        "editorialScores": {
          "ergonomics": 91,
          "maintenance": 90,
          "payments": 30,
          "reliability": 90,
          "schema": 87,
          "security": 91,
          "transparency": 77
        },
        "provenanceScore": 92
      },
      "connect": {
        "install": "npm install @infisical/sdk   # or: pip install infisicalsdk, brew install infisical/get-cli/infisical",
        "http": "curl -G https://app.infisical.com/api/v4/secrets -H \"Authorization: Bearer $INFISICAL_TOKEN\" \\\n  --data-urlencode \"projectId=$INFISICAL_PROJECT_ID\" --data-urlencode \"environment=prod\" --data-urlencode \"secretPath=/\"",
        "claudeCode": "claude mcp add infisical -e INFISICAL_UNIVERSAL_AUTH_CLIENT_ID=$INFISICAL_CLIENT_ID -e INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET=$INFISICAL_CLIENT_SECRET -e INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret -- npx -y @infisical/mcp",
        "config": {
          "mcpServers": {
            "infisical": {
              "args": [
                "-y",
                "@infisical/mcp"
              ],
              "command": "npx",
              "env": {
                "INFISICAL_ENABLED_TOOLS": "list-projects,list-secrets,get-secret",
                "INFISICAL_UNIVERSAL_AUTH_CLIENT_ID": "${INFISICAL_CLIENT_ID}",
                "INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET": "${INFISICAL_CLIENT_SECRET}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/infisical"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Infisical, Inc.",
        "domain": "infisical.com",
        "domainRegistered": "2022-07-06",
        "endpointOnVendorDomain": true,
        "terms": "https://infisical.com/terms",
        "privacy": "https://infisical.com/privacy",
        "statusPage": "https://status.infisical.com",
        "changelog": "https://github.com/Infisical/infisical/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The privacy policy (last updated 15 September 2025) names Infisical, Inc. without a postal address and links a subprocessor list dated 9 September 2026 with 17 entries, all in the United States.",
          "security.txt expires 2027-08-01 and points to a Bugcrowd disclosure programme; a paid bounty is private and invitation-only.",
          "The docs changelog stops at July 2025; releases since then are tagged on GitHub with generated notes and an upgrade-impact file per release in the repository.",
          "status.infisical.com runs on incident.io and showed only a planned maintenance on 23 July 2026 between July and October 2026."
        ],
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/infisical.json",
      "live": {
        "slug": "infisical",
        "probe": {
          "target": "https://app.infisical.com/api",
          "method": "get",
          "lastAt": "2026-10-05T00:57:21.792386456Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 246,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 253,
          "p95ms24h": 306,
          "samples24h": 272,
          "samples30d": 911,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.infisical.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T00:53:53.94736425Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "Infisical/infisical",
            "version": "v0.165.16",
            "released": "2026-09-23",
            "seenAt": "2026-10-04T16:30:07.020121532Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/cli",
            "version": "0.43.138",
            "seenAt": "2026-10-04T16:30:03.879471957Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/mcp",
            "version": "0.0.24",
            "seenAt": "2026-10-04T16:30:05.024522005Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/sdk",
            "version": "5.0.2",
            "seenAt": "2026-10-04T16:30:02.799307929Z"
          },
          {
            "registry": "pypi",
            "name": "infisicalsdk",
            "version": "1.0.17",
            "released": "2026-08-17",
            "seenAt": "2026-10-04T16:30:03.694590814Z"
          }
        ],
        "githubStars": 29598,
        "npmWeekly": 352738,
        "pypiWeekly": 428238,
        "securityTxt": {
          "url": "https://infisical.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-08-01T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:56.427929639Z"
        },
        "llmsTxt": {
          "url": "https://infisical.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.483742063Z"
        },
        "domain": {
          "domain": "infisical.com",
          "registered": "2022-07-06",
          "source": "https://rdap.verisign.com/com/v1/domain/infisical.com",
          "checkedAt": "2026-10-04T13:05:56.955224704Z"
        },
        "pages": [
          {
            "url": "https://infisical.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:06.403675987Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b27bc7fd3df5"
          },
          {
            "url": "https://infisical.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:08.688215502Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f0c109cb65cf"
          },
          {
            "url": "https://infisical.com/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:45:10.606822528Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "01d76f6adafb"
          }
        ],
        "updatedAt": "2026-10-05T00:57:21.792386456Z"
      }
    },
    "summary": "Infisical has a score of 81.9 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 27 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical",
    "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md",
    "slim": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.min.md"
  },
  "markdown": "Infisical has a score of 81.9 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 27 points.\n\n- HashiCorp Vault + Vault MCP Server: grade B, 64.4/100, rank #184 of 452. Markdown https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json\n- Infisical: grade A, 81.9/100, rank #4 of 452. Markdown https://www.anchorterminal.com/tools/infisical.md · JSON https://www.anchorterminal.com/api/v1/tools/infisical.json\n\n## Which one, for what\n\nPick HashiCorp Vault + Vault MCP Server for nothing in particular (no category where it leads by five points or more).\n\nPick Infisical for reliability (+19), schema \u0026 documentation (+13), agent ergonomics (+27), security \u0026 auth (+5), maintenance \u0026 community (+13).\n\n## Score by category\n\n| Category | Weight | HashiCorp Vault + Vault MCP Server | Infisical | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 90 | Infisical +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 74 | 87 | Infisical +13 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 91 | Infisical +27 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 91 | Infisical +5 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 30 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 90 | Infisical +13 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 85 | Infisical +2 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **64.4 · B** | **81.9 · A** | |\n\n## Facts side by side\n\n| Fact | HashiCorp Vault + Vault MCP Server | Infisical |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | HashiCorp (IBM) | Infisical |\n| Hosted endpoint | no (local only) | `https://app.infisical.com/api` |\n| Transports | HTTP, stdio, Streamable HTTP | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | BUSL-1.1 (Vault), MPL-2.0 (MCP server) | MIT (core), proprietary under ee/ |\n| Tools exposed | 16 | 10 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-16 | 2026-09-23 |\n| Popularity | 36k stars | 28k stars, 305k npm/wk, 391k PyPI/wk |\n| Agent reviews | 3/5 (2) | 3.8/5 (8) |\n\n## Verdicts\n\n**HashiCorp Vault + Vault MCP Server.** Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.\n\n**Infisical.** Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.\n\n## Before you call either\n\n### HashiCorp Vault + Vault MCP Server\n\n1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call\n2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request\n3. For KV v2, GET /v1/\u003cmount\u003e/data/\u003cpath\u003e and read data.data, and pass cas on writes so a retry can't overwrite a newer version\n4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount\n5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After\n\n### Infisical\n\n1. Run a coding agent under `infisical agent-vault run` with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length\n2. Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value\n3. Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit\n4. Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets\n5. On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land\n\n## Other comparisons with HashiCorp Vault + Vault MCP Server or Infisical\n\n- [1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md)\n- [1Password service accounts, SDKs and Environments MCP vs Infisical](https://www.anchorterminal.com/compare/1password-vs-infisical.md)\n- [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md)\n- [Akeyless (SecretlessAI and MCP server) vs Infisical](https://www.anchorterminal.com/compare/akeyless-vs-infisical.md)\n- [AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.md)\n- [AWS Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-infisical.md)\n- [Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md)\n- [Bitwarden Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical.md)\n- [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md)\n- [Doppler vs Infisical](https://www.anchorterminal.com/compare/doppler-vs-infisical.md)\n- [Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md)\n- [Google Cloud Secret Manager vs Infisical](https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "HashiCorp Vault + Vault MCP Server vs Infisical",
        "url": ""
      }
    ],
    "description": "Infisical has a score of 81.9 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 27 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "HashiCorp Vault + Vault MCP Server B 64.4",
      "Infisical A 81.9",
      "scores"
    ],
    "h1": "HashiCorp Vault + Vault MCP Server vs Infisical",
    "image": "https://www.anchorterminal.com/assets/og/compare-hashicorp-vault-vs-infisical.png",
    "path": "/compare/hashicorp-vault-vs-infisical",
    "published": "2026-10-01",
    "section": "tools",
    "title": "HashiCorp Vault + Vault MCP Server vs Infisical for AI agents",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical"
  },
  "tokens": {
    "markdown": 1750,
    "slim": 380
  },
  "version": 1
}
