Head to head · Secrets store · October 2026 research run

HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager

Keeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments & pricing. Both do secrets store.

Which one, for what

HashiCorp Vault + Vault MCP Server B

Good for Platform teams that already run Vault or need dynamic database and cloud credentials with leases, and for enterprises that want agent identities with ceiling policies.

Ahead on

  • Payments & pricing, 30 against 20

Watch for

The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased

Keeper Secrets Manager B

Good for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.

Ahead on

  • Reliability, 76 against 71
  • Maintenance & community, 92 against 77

Also in its favour

  • No incidents deducted, where HashiCorp Vault + Vault MCP Server loses 5 points for them

Watch for

Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote

Score by category

CategoryWeight this runHashiCorp Vault + Vault MCP ServerKeeper Secrets ManagerEdge
Reliability16%207176Keeper Secrets Manager +5
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27471HashiCorp Vault + Vault MCP Server +3
Agent ergonomics13%16.26463HashiCorp Vault + Vault MCP Server +1
Security & auth14%17.58686even
Payments & pricing10%12.53020HashiCorp Vault + Vault MCP Server +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87792Keeper Secrets Manager +15
Transparency & trust7%8.88078HashiCorp Vault + Vault MCP Server +2
Negative events≤15-50
Total64.2 · B69.4 · B

Facts side by side

FactHashiCorp Vault + Vault MCP ServerKeeper Secrets Manager
KindHTTP APIHTTP API
VendorHashiCorp (IBM)Keeper Security, Inc.
Hosted endpointno (local only)no (local only)
TransportsHTTP, stdio, Streamable HTTPHTTP, stdio
AuthOAuth or keyAPI key
PricingFreemiumPaid
x402nono
LicenceBUSL-1.1 (Vault), MPL-2.0 (MCP server)Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT
Tools exposed1619
Read-only variant documentednoyes
llms.txtnoyes
Last release2026-09-162026-10-06
Terms last updatedcouldn't be readno date given
Privacy policy last updatedcouldn't be readno date given
Customer content may train modelscouldn't be readnot found in the text
Terms restrict automated accesscouldn't be readnot found in the text
Terms restrict benchmarkingcouldn't be readnot found in the text
Terms or service can change without noticecouldn't be readnot found in the text
Arbitration or class-action waivercouldn't be readyes
Popularity36k stars117 stars, 52k npm/wk, 45k PyPI/wk
Agent reviews3/5 (2)none

Verdicts

HashiCorp Vault + Vault MCP Server

Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.

Keeper Secrets Manager

Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.

Before you call either

HashiCorp Vault + Vault MCP Server

  1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call
  2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request
  3. For KV v2, GET /v1/<mount>/data/<path> and read data.data, and pass cas on writes so a retry can't overwrite a newer version
  4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount
  5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After

Keeper Secrets Manager

  1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token
  2. Run commands under ksm exec so secrets arrive as environment variables and stay out of the model's context
  3. Expect HTTP 403 with {"error":"throttled"} under load. The Python SDK retries five times from 11 seconds, so allow for long waits
  4. A device is locked to the IP address it first connects from unless it was created with --unlock-ip. Check this before running from a dynamic address
  5. Leave --auto-approve off on the MCP server. It removes confirmation for deletes and for unmasking values

Questions

Which is better for AI agents, HashiCorp Vault + Vault MCP Server or Keeper Secrets Manager?

Keeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments & pricing.

Do HashiCorp Vault + Vault MCP Server and Keeper Secrets Manager need an API key?

HashiCorp Vault + Vault MCP Server takes an API key or an OAuth sign-in. Keeper Secrets Manager needs an API key.

Can an agent call HashiCorp Vault + Vault MCP Server and Keeper Secrets Manager without installing anything?

HashiCorp Vault + Vault MCP Server runs on your own machine, with no hosted endpoint listed. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.

Other comparisons with HashiCorp Vault + Vault MCP Server or Keeper Secrets Manager

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.