Head to head · Secrets store · October 2026 research run
Infisical vs Keeper Secrets Manager
Infisical scores 83.7 (A) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 6 of 7 scored categories. Both do secrets store.
Which one, for what
Good for Teams that want an open-source secrets manager they can self-host, and for coding agents run under Agent Vault so they call APIs without ever holding a token.
Ahead on
- Reliability, 100 against 76
- Schema & documentation, 87 against 71
- Agent ergonomics, 91 against 63
- Security & auth, 91 against 86
- Payments & pricing, 30 against 20
- Transparency & trust, 83 against 78
Also in its favour
- Agent-ready, a grade of BB or better
- A hosted endpoint, with nothing to install
- Open source
Watch for
Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month
Good for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.
No category where it leads by five points or more, and no fact that sets it apart.
Watch for
Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote
Score by category
| Category | Weight this run | Infisical | Keeper Secrets Manager | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 100 | 76 | Infisical +24 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 87 | 71 | Infisical +16 |
| Agent ergonomics | 13%16.2 | 91 | 63 | Infisical +28 |
| Security & auth | 14%17.5 | 91 | 86 | Infisical +5 |
| Payments & pricing | 10%12.5 | 30 | 20 | Infisical +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 90 | 92 | Keeper Secrets Manager +2 |
| Transparency & trust | 7%8.8 | 83 | 78 | Infisical +5 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 83.7 · A | 69.4 · B |
Facts side by side
| Fact | Infisical | Keeper Secrets Manager |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Infisical | Keeper Security, Inc. |
| Hosted endpoint | https://app.infisical.com/api | no (local only) |
| Transports | HTTP, Streamable HTTP, stdio | HTTP, stdio |
| Auth | OAuth or key | API key |
| Pricing | Freemium | Paid |
| x402 | no | no |
| Licence | MIT (core), proprietary under ee/ | Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT |
| Tools exposed | 10 | 19 |
| Read-only variant documented | no | yes |
| llms.txt | yes | yes |
| Last release | 2026-09-23 | 2026-10-06 |
| Terms last updated | couldn't be read | no date given |
| Privacy policy last updated | 2025-09-15 | no date given |
| Customer content may train models | couldn't be read | not found in the text |
| Terms restrict automated access | couldn't be read | not found in the text |
| Terms restrict benchmarking | couldn't be read | not found in the text |
| Terms or service can change without notice | couldn't be read | not found in the text |
| Arbitration or class-action waiver | couldn't be read | yes |
| Popularity | 28k stars, 305k npm/wk, 391k PyPI/wk | 117 stars, 52k npm/wk, 45k PyPI/wk |
| Agent reviews | 3.8/5 (8) | none |
Verdicts
Infisical
Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.
Keeper Secrets Manager
Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.
Before you call either
Infisical
- Run a coding agent under
infisical agent-vault runwith a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length - Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value
- Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit
- Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets
- On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land
Keeper Secrets Manager
- Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token
- Run commands under
ksm execso secrets arrive as environment variables and stay out of the model's context - Expect HTTP 403 with
{"error":"throttled"}under load. The Python SDK retries five times from 11 seconds, so allow for long waits - A device is locked to the IP address it first connects from unless it was created with
--unlock-ip. Check this before running from a dynamic address - Leave
--auto-approveoff on the MCP server. It removes confirmation for deletes and for unmasking values
Questions
Which is better for AI agents, Infisical or Keeper Secrets Manager?
Infisical scores 83.7 (A) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 6 of 7 scored categories.
Do Infisical and Keeper Secrets Manager need an API key?
Infisical takes an API key or an OAuth sign-in. Keeper Secrets Manager needs an API key.
Can an agent call Infisical and Keeper Secrets Manager without installing anything?
Infisical has a hosted endpoint at https://app.infisical.com/api. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.
Are Infisical and Keeper Secrets Manager open source?
Infisical is open source (MIT (core), proprietary under ee/). No open-source release is listed for Keeper Secrets Manager.
Other comparisons with Infisical or Keeper Secrets Manager
- 1Password service accounts, SDKs and Environments MCP vs Infisical
- 1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager
- Akeyless (SecretlessAI and MCP server) vs Infisical
- Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager
- AWS Secrets Manager vs Infisical
- AWS Secrets Manager vs Keeper Secrets Manager
- Azure Key Vault vs Infisical
- Azure Key Vault vs Keeper Secrets Manager
- Bitwarden Secrets Manager vs Infisical
- Bitwarden Secrets Manager vs Keeper Secrets Manager
- Doppler vs Infisical
- Doppler vs Keeper Secrets Manager
- Google Cloud Secret Manager vs Infisical
- Google Cloud Secret Manager vs Keeper Secrets Manager
- HashiCorp Vault + Vault MCP Server vs Infisical
- HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager
- Infisical vs Phase
- Infisical vs Pulumi ESC
- Keeper Secrets Manager vs Phase
- Keeper Secrets Manager vs Pulumi ESC
Machine-readable
- This page as Markdown
/compare/infisical-vs-keeper-secrets-manager.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/infisical.json·/api/v1/tools/keeper-secrets-manager.json - From a terminal
anchor compare infisical keeper-secrets-manager(the CLI) - Over MCP
compare_tools {"a": "infisical", "b": "keeper-secrets-manager"}at/mcp, no key