{
  "data": {
    "a": {
      "slug": "hashicorp-vault",
      "name": "HashiCorp Vault + Vault MCP Server",
      "vendor": "HashiCorp (IBM)",
      "vendorUrl": "https://developer.hashicorp.com/vault",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Secrets management platform for storing credentials and controlling application access.",
      "url": "https://www.anchorterminal.com/tools/hashicorp-vault",
      "markdownUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json",
      "repo": "https://github.com/hashicorp/vault",
      "license": "BUSL-1.1 (Vault), MPL-2.0 (MCP server)",
      "transports": [
        "http",
        "stdio",
        "streamable-http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Every request carries a Vault token in `X-Vault-Token` (or as an HTTP bearer token). Machines get a token from an auth method such as AppRole, Kubernetes, JWT/OIDC, AWS, GCP, Azure, TLS certificates and more. Enterprise 2.0.3+ lets a registered agent present an OAuth 2.0 JWT from your identity provider directly, with RAR claims (RFC 9396) narrowing paths. The MCP server reads VAULT_ADDR, VAULT_TOKEN and VAULT_NAMESPACE, or takes them as headers in HTTP mode.",
      "pricing": "freemium",
      "pricingNotes": "Vault Community is free to run under the BUSL-1.1, which forbids selling a competing hosted product. HCP Vault Dedicated is hourly per cluster on the IBM price list. Development extra small $0.61644 an hour, Essentials small $1.57799, medium $3.16299, large $7.48857, Standard small $1.84299, medium $3.69099, large $9.40599, plus $72.92 a month per product client. Prices are indicative and exclude tax. Vault Enterprise self-managed is quoted, and the 2.1.0 licence added Agentic IAM terms. HCP has a $500 pay-as-you-go credit (https://www.ibm.com/products/hashicorp/pricing, https://www.hashicorp.com/en/pricing).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 16,
      "popularity": {
        "githubStars": 36234,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.hashicorp.com/vault/docs",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "auth.agent-identity"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "source-available",
        "freemium",
        "mcp",
        "local",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.2,
        "grade": "B",
        "agentReady": false,
        "rank": 283,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 77,
          "payments": 30,
          "reliability": 71,
          "schema": 74,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-4: The official Vault MCP server fixed cross-user credential inheritance through a shared MCP session ID on 2026-07-28 and an SSRF through a VAULT_ADDR query parameter on 2026-08-11, but the newest binary and Docker image are still 0.2.0 from 2025-09-24 and no advisory was published (https://github.com/hashicorp/vault-mcp-server/commits/main, https://releases.hashicorp.com/vault-mcp-server/)",
          "-1: Vault 2.0.3 (2026-06-17) fixed a LIST ACL bypass where a trailing slash skipped a more specific deny rule; fixed and documented in the changelog, so it decays (https://github.com/hashicorp/vault/blob/main/CHANGELOG.md)"
        ],
        "verdict": "Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.",
        "bestFor": "Platform teams that already run Vault or need dynamic database and cloud credentials with leases, and for enterprises that want agent identities with ceiling policies.",
        "strengths": [
          "Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after",
          "Path policies with explicit deny, audit devices on every edition, and Agent Registry with ceiling policies on Enterprise",
          "Auth methods for every major cloud, Kubernetes, JWT/OIDC and AppRole",
          "Three releases between 4 August and 16 September 2026 with a dated changelog that names each CVE fixed",
          "Each server generates its own OpenAPI document at /v1/sys/internal/specs/openapi"
        ],
        "weaknesses": [
          "The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased",
          "Agentic IAM, control groups and the OAuth resource server are Enterprise only",
          "BUSL-1.1, not an OSI licence, and HCP Vault Secrets was retired within two years of launch",
          "No llms.txt, and the only official client library is Go",
          "HCP client pricing ($72.92 a client a month) can dwarf the cluster price for many agents, and no SLA is published"
        ],
        "agentNotes": [
          "Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call",
          "Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request",
          "For KV v2, GET /v1/\u003cmount\u003e/data/\u003cpath\u003e and read data.data, and pass cas on writes so a retry can't overwrite a newer version",
          "If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount",
          "Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.2
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 77,
          "payments": 30,
          "reliability": 71,
          "schema": 74,
          "security": 86,
          "transparency": 65
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "docker run --rm -p 8200:8200 hashicorp/vault server -dev   # or download vault-mcp-server from releases.hashicorp.com",
        "http": "curl -H \"X-Vault-Token: $VAULT_TOKEN\" \"$VAULT_ADDR/v1/secret/data/myapp\"",
        "claudeCode": "claude mcp add vault -e VAULT_ADDR=$VAULT_ADDR -e VAULT_TOKEN=$VAULT_TOKEN -- vault-mcp-server stdio",
        "config": {
          "mcpServers": {
            "vault": {
              "args": [
                "run",
                "-i",
                "--rm",
                "-e",
                "VAULT_ADDR",
                "-e",
                "VAULT_TOKEN",
                "hashicorp/vault-mcp-server"
              ],
              "command": "docker",
              "env": {
                "VAULT_ADDR": "${VAULT_ADDR}",
                "VAULT_TOKEN": "${VAULT_TOKEN}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/hashicorp-vault"
      },
      "sameCompany": [
        "terraform-mcp"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "HCP Vault Dedicated, product client",
          "unit": "account-month",
          "usd": 72.92,
          "note": "Per client a month, Essentials and Standard"
        }
      ],
      "provenance": {
        "legalEntity": "HashiCorp, Inc. (an IBM company)",
        "domain": "hashicorp.com",
        "domainRegistered": "2011-04-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.hashicorp.com/en/terms-of-service",
        "privacy": "https://www.hashicorp.com/en/privacy",
        "statusPage": "https://status.hashicorp.com",
        "changelog": "https://github.com/hashicorp/vault/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The website terms name HashiCorp, Inc. and were last updated March 2018. The privacy policy (20 April 2026) gives HashiCorp, an IBM Company, c/o 1 North Castle Drive, Armonk, New York, and notes the IBM acquisition closed on 27 February 2025.",
          "security.txt has Contact, Policy and Encryption but no Expires field.",
          "HCP prices come from the IBM price table and are marked indicative, varying by country.",
          "status.hashicorp.com runs on incident.io. From 1 July to 1 October 2026 it posted nothing against HCP Vault Dedicated; it did post a DR cluster creation failure on HCP (6 August) and a releases.hashicorp.com outage (26 September).",
          "The Vault MCP server's newest published build is 0.2.0 (24 September 2025) on releases.hashicorp.com and Docker Hub, although its VERSION file and changelog say 0.2.1."
        ],
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hashicorp-vault.json",
      "live": {
        "slug": "hashicorp-vault",
        "vendorStatus": {
          "page": "https://status.hashicorp.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:07.926675528Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "hashicorp/vault",
            "version": "v2.1.2",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:15:31.846830697Z"
          }
        ],
        "githubStars": 36356,
        "securityTxt": {
          "url": "https://hashicorp.com/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:38:30.658630559Z"
        },
        "domain": {
          "domain": "hashicorp.com",
          "registered": "2011-04-30",
          "source": "https://rdap.verisign.com/com/v1/domain/hashicorp.com",
          "checkedAt": "2026-10-04T13:10:23.718306751Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/hashicorp/vault/main/CHANGELOG.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:21.688347943Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0620845f2f7e"
          },
          {
            "url": "https://www.ibm.com/support/pages/hcp-vault-secrets-end-life",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:24.005680337Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e24e2e2b51c3"
          },
          {
            "url": "https://www.hashicorp.com/en/pricing",
            "kind": "pricing",
            "status": 429,
            "checkedAt": "2026-10-08T18:28:08.092212572Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.ibm.com/products/hashicorp/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:21.778439253Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0e262eb503c4"
          },
          {
            "url": "https://www.hashicorp.com/en/privacy",
            "kind": "privacy",
            "status": 429,
            "checkedAt": "2026-10-08T18:28:10.109372947Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.hashicorp.com/en/terms-of-service",
            "kind": "terms",
            "status": 429,
            "checkedAt": "2026-10-08T18:28:12.110069978Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-08T21:06:07.926675528Z"
      }
    },
    "answer": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments \u0026 pricing.",
    "b": {
      "slug": "keeper-secrets-manager",
      "name": "Keeper Secrets Manager",
      "vendor": "Keeper Security, Inc.",
      "vendorUrl": "https://www.keepersecurity.com/secrets-manager.html",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Keeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the `ksm` CLI or a local MCP server, decrypting on the client.",
      "url": "https://www.anchorterminal.com/tools/keeper-secrets-manager",
      "markdownUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json",
      "repo": "https://github.com/Keeper-Security/secrets-manager",
      "license": "Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "keeper-secrets-manager-core"
        },
        {
          "registry": "pypi",
          "name": "keeper-secrets-manager-cli"
        },
        {
          "registry": "npm",
          "name": "@keeper-security/secrets-manager-core"
        }
      ],
      "auth": "api-key",
      "authNotes": "Access is granted by a person. A vault user whose role allows it creates a Secrets Manager application, shares folders or records with it, and adds a client device, which yields a one-time access token or a Base64 configuration. The client redeems the token once, registers its own ECC public key and signs every later request with the private key, so no bearer secret is reused. Devices are IP-locked by default, can be given an access expiry and are revoked individually.",
      "pricing": "paid",
      "pricingNotes": "Secrets Manager is an add-on to Keeper's business password manager plans, licensed per user per year, and included with KeeperPAM. The add-ons page shows Custom Pricing and Request a Quote for it, so there is no public figure. A 14-day business trial needs no credit card and can enable Secrets Manager, so an agent's owner can start without a contract. Base plan prices are drawn by script and were blank to our reader (https://www.keepersecurity.com/pricing/business-add-ons/, https://www.keepersecurity.com/trial/keeper-free-trial/, checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Secrets Manager docs, the SDK repository or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 19,
      "popularity": {
        "githubStars": 117,
        "npmWeekly": 52332,
        "pypiWeekly": 45154,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.keeper.io/en/keeperpam/secrets-manager/overview",
      "llmsTxt": "https://docs.keeper.io/llms.txt",
      "capabilities": [
        "secrets.store",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.rotate"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "zero-knowledge",
        "mcp",
        "cli",
        "python",
        "javascript",
        "java",
        "go",
        "dotnet",
        "ruby",
        "rust",
        "llms-txt",
        "sales-led",
        "status-page",
        "bug-bounty",
        "soc2",
        "fedramp"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.4,
        "grade": "B",
        "agentReady": false,
        "rank": 159,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 92,
          "payments": 20,
          "reliability": 76,
          "schema": 71,
          "security": 86,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.",
        "bestFor": "Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.",
        "strengths": [
          "Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone",
          "Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page",
          "An application sees only the shared folders and records assigned to it, read-only unless shared as editable",
          "Official MIT MCP server with 19 typed tools, masked values by default and confirmation for writes, deletes and unmasking",
          "SDKs for Python, Java, JavaScript, .NET, Go, Ruby and Rust in one MIT repository, with 5 tagged releases since 15 September 2026"
        ],
        "weaknesses": [
          "Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote",
          "No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with `{\"error\":\"throttled\"}`",
          "No OpenAPI or documented raw HTTP use for `/api/rest/sm/v1`. The SDKs are the only supported route",
          "The Node MCP guide links a GitHub repository that returned 404 on 8 October 2026",
          "Rotation needs a KeeperPAM licence and a Keeper Gateway, and access events are read in the separately sold reporting module"
        ],
        "agentNotes": [
          "Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token",
          "Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context",
          "Expect HTTP 403 with `{\"error\":\"throttled\"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits",
          "A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address",
          "Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.4
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 92,
          "payments": 20,
          "reliability": 76,
          "schema": 71,
          "security": 86,
          "transparency": 58
        },
        "provenanceScore": 98
      },
      "connect": {
        "install": "pip3 install keeper-secrets-manager-cli   # or: pip3 install keeper-secrets-manager-core, npm install @keeper-security/secrets-manager-core",
        "http": "ksm profile init XX:XXXX   # one-time access token from the vault\nksm secret list   # values decrypt on the client, so plain curl can't read them",
        "claudeCode": "/plugin marketplace add Keeper-Security/keeper-agent-kit\n/plugin install keeper-secrets@keeper-security",
        "config": {
          "mcpServers": {
            "ksm": {
              "args": [
                "run",
                "-i",
                "--rm",
                "-e",
                "KSM_CONFIG_BASE64=YOUR_BASE64_CONFIG_STRING_HERE",
                "keeper/keeper-mcp-server:latest"
              ],
              "command": "docker"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/keeper-secrets-manager"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Keeper Security, Inc.",
        "domain": "keepersecurity.com",
        "domainRegistered": "2007-04-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.keepersecurity.com/legal/terms-of-use/#saas-terms",
        "privacy": "https://www.keepersecurity.com/legal/terms-of-use/?s=privacy",
        "statusPage": "https://statuspage.keeper.io",
        "changelog": "https://docs.keeper.io/release-notes/enterprise/keeper-secrets-manager/2026",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "Keeper publishes its website terms, SaaS Terms of Use, partner terms, privacy policy and Service Level Objectives as sections of one page at www.keepersecurity.com/legal/terms-of-use/. The SaaS section governs the service and the `?s=privacy` view is the privacy policy. The old `/termsofuse.html` and `/privacypolicy.html` addresses redirect there.",
          "The SaaS terms name Keeper Security, Inc., 311 W. Monroe Street, Suite 406, Chicago, IL 60606, with Keeper Security EMEA Limited and Keeper Security APAC KK for other regions. The page links legacy terms for the period before 9 March 2026.",
          "The SaaS terms forbid a customer to perform penetration or load testing on the services, and the website terms prohibit scraping or automated data collection on the website.",
          "www.keepersecurity.com/.well-known/security.txt answers with a Bugcrowd contact and Expires 2026-12-31T23:59:59Z.",
          "The SDKs call https://\u003cregion host\u003e/api/rest/sm/v1, where the host is keepersecurity.com, keepersecurity.eu, keepersecurity.com.au, keepersecurity.ca, keepersecurity.jp or govcloud.keepersecurity.us.",
          "The status page and the docs sit on keeper.io. statuspage.keeper.io is Atlassian Statuspage with a Keeper Secrets Manager component.",
          "RDAP for keepersecurity.com gives a registration date of 2007-04-12."
        ],
        "score": 98
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.json",
      "live": {
        "slug": "keeper-secrets-manager",
        "vendorStatus": {
          "page": "https://statuspage.keeper.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:10.265244465Z"
        },
        "updatedAt": "2026-10-08T21:06:10.265244465Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "HashiCorp (IBM)",
        "b": "Keeper Security, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio, Streamable HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "BUSL-1.1 (Vault), MPL-2.0 (MCP server)",
        "b": "Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "16",
        "b": "19",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-16",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "36k stars",
        "b": "117 stars, 52k npm/wk, 45k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, HashiCorp Vault + Vault MCP Server or Keeper Secrets Manager?"
      },
      {
        "answer": "HashiCorp Vault + Vault MCP Server takes an API key or an OAuth sign-in. Keeper Secrets Manager needs an API key.",
        "question": "Do HashiCorp Vault + Vault MCP Server and Keeper Secrets Manager need an API key?"
      },
      {
        "answer": "HashiCorp Vault + Vault MCP Server runs on your own machine, with no hosted endpoint listed. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call HashiCorp Vault + Vault MCP Server and Keeper Secrets Manager without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 30 against 20"
        ],
        "also": null,
        "goodFor": "Platform teams that already run Vault or need dynamic database and cloud credentials with leases, and for enterprises that want agent identities with ceiling policies.",
        "slug": "hashicorp-vault",
        "watchFor": "The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased"
      },
      {
        "aheadOn": [
          "Reliability, 76 against 71",
          "Maintenance \u0026 community, 92 against 77"
        ],
        "also": [
          "No incidents deducted, where HashiCorp Vault + Vault MCP Server loses 5 points for them"
        ],
        "goodFor": "Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.",
        "slug": "keeper-secrets-manager",
        "watchFor": "Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote"
      }
    ],
    "job": {
      "capability": "secrets.store",
      "name": "Secrets store"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.json",
        "title": "AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager.json",
        "title": "AWS Secrets Manager vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-key-vault-vs-hashicorp-vault.json",
        "title": "Azure Key Vault vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/azure-key-vault-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager.json",
        "title": "Azure Key Vault vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.json",
        "title": "Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager.json",
        "title": "Bitwarden Secrets Manager vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.json",
        "title": "Doppler vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager.json",
        "title": "Doppler vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.json",
        "title": "Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.json",
        "title": "Google Cloud Secret Manager vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.json",
        "title": "HashiCorp Vault + Vault MCP Server vs Infisical",
        "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.json",
        "title": "HashiCorp Vault + Vault MCP Server vs Phase",
        "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-pulumi-esc.json",
        "title": "HashiCorp Vault + Vault MCP Server vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-pulumi-esc"
      },
      {
        "json": "https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager.json",
        "title": "Infisical vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.json",
        "title": "Keeper Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.json",
        "title": "Keeper Secrets Manager vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc"
      }
    ],
    "scores": [
      {
        "by": 5,
        "edge": "keeper-secrets-manager",
        "hashicorp-vault": 71,
        "keeper-secrets-manager": 76,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "hashicorp-vault",
        "hashicorp-vault": 74,
        "keeper-secrets-manager": 71,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 1,
        "edge": "hashicorp-vault",
        "hashicorp-vault": 64,
        "keeper-secrets-manager": 63,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 0,
        "edge": "",
        "hashicorp-vault": 86,
        "keeper-secrets-manager": 86,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 10,
        "edge": "hashicorp-vault",
        "hashicorp-vault": 30,
        "keeper-secrets-manager": 20,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "edge": "keeper-secrets-manager",
        "hashicorp-vault": 77,
        "keeper-secrets-manager": 92,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 2,
        "edge": "hashicorp-vault",
        "hashicorp-vault": 80,
        "keeper-secrets-manager": 78,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments \u0026 pricing. Both do secrets store.",
    "verdicts": {
      "hashicorp-vault": "Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.",
      "keeper-secrets-manager": "Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager",
    "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.md",
    "slim": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.min.md"
  },
  "markdown": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments \u0026 pricing. Both do secrets store.\n\n- HashiCorp Vault + Vault MCP Server: grade B, 64.2/100, rank #283 of 722. Markdown https://www.anchorterminal.com/tools/hashicorp-vault.md · JSON https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json\n- Keeper Secrets Manager: grade B, 69.4/100, rank #159 of 722. Markdown https://www.anchorterminal.com/tools/keeper-secrets-manager.md · JSON https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json\n\n## Which one, for what\n\n### HashiCorp Vault + Vault MCP Server (B)\n\nGood for: Platform teams that already run Vault or need dynamic database and cloud credentials with leases, and for enterprises that want agent identities with ceiling policies.\n\nAhead on:\n- Payments \u0026 pricing, 30 against 20\n\nWatch for: The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased\n\n### Keeper Secrets Manager (B)\n\nGood for: Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.\n\nAhead on:\n- Reliability, 76 against 71\n- Maintenance \u0026 community, 92 against 77\n\nAlso in its favour:\n- No incidents deducted, where HashiCorp Vault + Vault MCP Server loses 5 points for them\n\nWatch for: Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote\n\n\n## Score by category\n\n| Category | Weight | HashiCorp Vault + Vault MCP Server | Keeper Secrets Manager | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 76 | Keeper Secrets Manager +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 74 | 71 | HashiCorp Vault + Vault MCP Server +3 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 63 | HashiCorp Vault + Vault MCP Server +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 86 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 20 | HashiCorp Vault + Vault MCP Server +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 92 | Keeper Secrets Manager +15 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 80 | 78 | HashiCorp Vault + Vault MCP Server +2 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **64.2 · B** | **69.4 · B** | |\n\n## Facts side by side\n\n| Fact | HashiCorp Vault + Vault MCP Server | Keeper Secrets Manager |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | HashiCorp (IBM) | Keeper Security, Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, stdio, Streamable HTTP | HTTP, stdio |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | BUSL-1.1 (Vault), MPL-2.0 (MCP server) | Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT |\n| Tools exposed | 16 | 19 |\n| Read-only variant documented | no | yes |\n| llms.txt | no | yes |\n| Last release | 2026-09-16 | 2026-10-06 |\n| Terms last updated | couldn't be read | no date given |\n| Privacy policy last updated | couldn't be read | no date given |\n| Customer content may train models | couldn't be read | not found in the text |\n| Terms restrict automated access | couldn't be read | not found in the text |\n| Terms restrict benchmarking | couldn't be read | not found in the text |\n| Terms or service can change without notice | couldn't be read | not found in the text |\n| Arbitration or class-action waiver | couldn't be read | yes |\n| Popularity | 36k stars | 117 stars, 52k npm/wk, 45k PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**HashiCorp Vault + Vault MCP Server.** Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.\n\n**Keeper Secrets Manager.** Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.\n\n## Before you call either\n\n### HashiCorp Vault + Vault MCP Server\n\n1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call\n2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request\n3. For KV v2, GET /v1/\u003cmount\u003e/data/\u003cpath\u003e and read data.data, and pass cas on writes so a retry can't overwrite a newer version\n4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount\n5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After\n\n### Keeper Secrets Manager\n\n1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token\n2. Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context\n3. Expect HTTP 403 with `{\"error\":\"throttled\"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits\n4. A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address\n5. Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values\n\n## Questions\n\n### Which is better for AI agents, HashiCorp Vault + Vault MCP Server or Keeper Secrets Manager?\n\nKeeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments \u0026 pricing.\n\n### Do HashiCorp Vault + Vault MCP Server and Keeper Secrets Manager need an API key?\n\nHashiCorp Vault + Vault MCP Server takes an API key or an OAuth sign-in. Keeper Secrets Manager needs an API key.\n\n### Can an agent call HashiCorp Vault + Vault MCP Server and Keeper Secrets Manager without installing anything?\n\nHashiCorp Vault + Vault MCP Server runs on your own machine, with no hosted endpoint listed. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.json, and with the fewest tokens: https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"hashicorp-vault\", \"b\": \"keeper-secrets-manager\"}`. From a terminal: `anchor compare hashicorp-vault keeper-secrets-manager`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json and https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json\n\n## Other comparisons with HashiCorp Vault + Vault MCP Server or Keeper Secrets Manager\n\n- [1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/1password-vs-hashicorp-vault.md)\n- [1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/akeyless-vs-hashicorp-vault.md)\n- [Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.md)\n- [AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-hashicorp-vault.md)\n- [AWS Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager.md)\n- [Azure Key Vault vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/azure-key-vault-vs-hashicorp-vault.md)\n- [Azure Key Vault vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager.md)\n- [Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-hashicorp-vault.md)\n- [Bitwarden Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager.md)\n- [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md)\n- [Doppler vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager.md)\n- [Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/google-secret-manager-vs-hashicorp-vault.md)\n- [Google Cloud Secret Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.md)\n- [HashiCorp Vault + Vault MCP Server vs Infisical](https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md)\n- [HashiCorp Vault + Vault MCP Server vs Phase](https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.md)\n- [HashiCorp Vault + Vault MCP Server vs Pulumi ESC](https://www.anchorterminal.com/compare/hashicorp-vault-vs-pulumi-esc.md)\n- [Infisical vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager.md)\n- [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md)\n- [Keeper Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager",
        "url": ""
      }
    ],
    "description": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against HashiCorp Vault + Vault MCP Server's 64.2 (B), and leads in 2 of 7 scored categories. HashiCorp Vault + Vault MCP Server leads on payments \u0026 pricing. Both do secrets store. Category scores, facts, verdicts and…",
    "facts": [
      "HashiCorp Vault + Vault MCP Server B 64.2",
      "Keeper Secrets Manager B 69.4",
      "scores"
    ],
    "h1": "HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager",
    "image": "https://www.anchorterminal.com/assets/og/compare-hashicorp-vault-vs-keeper-secrets-manager.png",
    "path": "/compare/hashicorp-vault-vs-keeper-secrets-manager",
    "published": "2026-10-01",
    "section": "tools",
    "title": "HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager"
  },
  "tokens": {
    "markdown": 2750,
    "slim": 780
  },
  "version": 1
}
