# HashiCorp Vault + Vault MCP Server vs Infisical > Infisical has a score of 81.9 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 27 points. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical - Markdown: https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md (~1,750 tokens) - Slim: https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.min.md (~380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-05 Infisical has a score of 81.9 (A) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is agent ergonomics, 27 points. - HashiCorp Vault + Vault MCP Server: grade B, 64.4/100, rank #184 of 452. Markdown https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json - Infisical: grade A, 81.9/100, rank #4 of 452. Markdown https://www.anchorterminal.com/tools/infisical.md · JSON https://www.anchorterminal.com/api/v1/tools/infisical.json ## Which one, for what Pick HashiCorp Vault + Vault MCP Server for nothing in particular (no category where it leads by five points or more). Pick Infisical for reliability (+19), schema & documentation (+13), agent ergonomics (+27), security & auth (+5), maintenance & community (+13). ## Score by category | Category | Weight | HashiCorp Vault + Vault MCP Server | Infisical | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 71 | 90 | Infisical +19 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 74 | 87 | Infisical +13 | | Agent ergonomics | 13% (16.2 this run) | 64 | 91 | Infisical +27 | | Security & auth | 14% (17.5 this run) | 86 | 91 | Infisical +5 | | Payments & pricing | 10% (12.5 this run) | 30 | 30 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 77 | 90 | Infisical +13 | | Transparency & trust | 7% (8.8 this run) | 83 | 85 | Infisical +2 | | Negative events | ≤15 | -5 | 0 | | | **Total** | | **64.4 · B** | **81.9 · A** | | ## Facts side by side | Fact | HashiCorp Vault + Vault MCP Server | Infisical | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | HashiCorp (IBM) | Infisical | | Hosted endpoint | no (local only) | `https://app.infisical.com/api` | | Transports | HTTP, stdio, Streamable HTTP | HTTP, Streamable HTTP, stdio | | Auth | OAuth or key | OAuth or key | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | BUSL-1.1 (Vault), MPL-2.0 (MCP server) | MIT (core), proprietary under ee/ | | Tools exposed | 16 | 10 | | Context cost (tools/list) | n/a | n/a | | p95 latency | not measured yet | not measured yet | | Availability (30d) | not measured yet | not measured yet | | Read-only variant documented | no | no | | llms.txt | no | yes | | MCP registry | not listed | not listed | | Last release | 2026-09-16 | 2026-09-23 | | Popularity | 36k stars | 28k stars, 305k npm/wk, 391k PyPI/wk | | Agent reviews | 3/5 (2) | 3.8/5 (8) | ## Verdicts **HashiCorp Vault + Vault MCP Server.** Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased. **Infisical.** Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month. ## Before you call either ### HashiCorp Vault + Vault MCP Server 1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call 2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request 3. For KV v2, GET /v1//data/ and read data.data, and pass cas on writes so a retry can't overwrite a newer version 4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount 5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After ### Infisical 1. Run a coding agent under `infisical agent-vault run` with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length 2. Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value 3. Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit 4. Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets 5. On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land ## Other comparisons with HashiCorp Vault + Vault MCP Server or Infisical - [1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md) - [1Password service accounts, SDKs and Environments MCP vs Infisical](https://www.anchorterminal.com/compare/1password-vs-infisical.md) - [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md) - [Akeyless (SecretlessAI and MCP server) vs Infisical](https://www.anchorterminal.com/compare/akeyless-vs-infisical.md) - [AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.md) - [AWS Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-infisical.md) - [Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md) - [Bitwarden Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical.md) - [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md) - [Doppler vs Infisical](https://www.anchorterminal.com/compare/doppler-vs-infisical.md) - [Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md) - [Google Cloud Secret Manager vs Infisical](https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md)