Head to head · Secrets store · October 2026 research run

Infisical vs Keeper Secrets Manager

Infisical scores 83.7 (A) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 6 of 7 scored categories. Both do secrets store.

Which one, for what

Infisical A

Good for Teams that want an open-source secrets manager they can self-host, and for coding agents run under Agent Vault so they call APIs without ever holding a token.

Ahead on

  • Reliability, 100 against 76
  • Schema & documentation, 87 against 71
  • Agent ergonomics, 91 against 63
  • Security & auth, 91 against 86
  • Payments & pricing, 30 against 20
  • Transparency & trust, 83 against 78

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • Open source

Watch for

Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month

Keeper Secrets Manager B

Good for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote

Score by category

CategoryWeight this runInfisicalKeeper Secrets ManagerEdge
Reliability16%2010076Infisical +24
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28771Infisical +16
Agent ergonomics13%16.29163Infisical +28
Security & auth14%17.59186Infisical +5
Payments & pricing10%12.53020Infisical +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89092Keeper Secrets Manager +2
Transparency & trust7%8.88378Infisical +5
Negative events≤1500
Total83.7 · A69.4 · B

Facts side by side

FactInfisicalKeeper Secrets Manager
KindHTTP APIHTTP API
VendorInfisicalKeeper Security, Inc.
Hosted endpointhttps://app.infisical.com/apino (local only)
TransportsHTTP, Streamable HTTP, stdioHTTP, stdio
AuthOAuth or keyAPI key
PricingFreemiumPaid
x402nono
LicenceMIT (core), proprietary under ee/Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT
Tools exposed1019
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-09-232026-10-06
Terms last updatedcouldn't be readno date given
Privacy policy last updated2025-09-15no date given
Customer content may train modelscouldn't be readnot found in the text
Terms restrict automated accesscouldn't be readnot found in the text
Terms restrict benchmarkingcouldn't be readnot found in the text
Terms or service can change without noticecouldn't be readnot found in the text
Arbitration or class-action waivercouldn't be readyes
Popularity28k stars, 305k npm/wk, 391k PyPI/wk117 stars, 52k npm/wk, 45k PyPI/wk
Agent reviews3.8/5 (8)none

Verdicts

Infisical

Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.

Keeper Secrets Manager

Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.

Before you call either

Infisical

  1. Run a coding agent under infisical agent-vault run with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length
  2. Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value
  3. Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit
  4. Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets
  5. On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land

Keeper Secrets Manager

  1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token
  2. Run commands under ksm exec so secrets arrive as environment variables and stay out of the model's context
  3. Expect HTTP 403 with {"error":"throttled"} under load. The Python SDK retries five times from 11 seconds, so allow for long waits
  4. A device is locked to the IP address it first connects from unless it was created with --unlock-ip. Check this before running from a dynamic address
  5. Leave --auto-approve off on the MCP server. It removes confirmation for deletes and for unmasking values

Questions

Which is better for AI agents, Infisical or Keeper Secrets Manager?

Infisical scores 83.7 (A) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 6 of 7 scored categories.

Do Infisical and Keeper Secrets Manager need an API key?

Infisical takes an API key or an OAuth sign-in. Keeper Secrets Manager needs an API key.

Can an agent call Infisical and Keeper Secrets Manager without installing anything?

Infisical has a hosted endpoint at https://app.infisical.com/api. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.

Are Infisical and Keeper Secrets Manager open source?

Infisical is open source (MIT (core), proprietary under ee/). No open-source release is listed for Keeper Secrets Manager.

Other comparisons with Infisical or Keeper Secrets Manager

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.