{
  "data": {
    "a": {
      "slug": "keeper-secrets-manager",
      "name": "Keeper Secrets Manager",
      "vendor": "Keeper Security, Inc.",
      "vendorUrl": "https://www.keepersecurity.com/secrets-manager.html",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Keeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the `ksm` CLI or a local MCP server, decrypting on the client.",
      "url": "https://www.anchorterminal.com/tools/keeper-secrets-manager",
      "markdownUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json",
      "repo": "https://github.com/Keeper-Security/secrets-manager",
      "license": "Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "keeper-secrets-manager-core"
        },
        {
          "registry": "pypi",
          "name": "keeper-secrets-manager-cli"
        },
        {
          "registry": "npm",
          "name": "@keeper-security/secrets-manager-core"
        }
      ],
      "auth": "api-key",
      "authNotes": "Access is granted by a person. A vault user whose role allows it creates a Secrets Manager application, shares folders or records with it, and adds a client device, which yields a one-time access token or a Base64 configuration. The client redeems the token once, registers its own ECC public key and signs every later request with the private key, so no bearer secret is reused. Devices are IP-locked by default, can be given an access expiry and are revoked individually.",
      "pricing": "paid",
      "pricingNotes": "Secrets Manager is an add-on to Keeper's business password manager plans, licensed per user per year, and included with KeeperPAM. The add-ons page shows Custom Pricing and Request a Quote for it, so there is no public figure. A 14-day business trial needs no credit card and can enable Secrets Manager, so an agent's owner can start without a contract. Base plan prices are drawn by script and were blank to our reader (https://www.keepersecurity.com/pricing/business-add-ons/, https://www.keepersecurity.com/trial/keeper-free-trial/, checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Secrets Manager docs, the SDK repository or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 19,
      "popularity": {
        "githubStars": 117,
        "npmWeekly": 52332,
        "pypiWeekly": 45154,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.keeper.io/en/keeperpam/secrets-manager/overview",
      "llmsTxt": "https://docs.keeper.io/llms.txt",
      "capabilities": [
        "secrets.store",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.rotate"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "zero-knowledge",
        "mcp",
        "cli",
        "python",
        "javascript",
        "java",
        "go",
        "dotnet",
        "ruby",
        "rust",
        "llms-txt",
        "sales-led",
        "status-page",
        "bug-bounty",
        "soc2",
        "fedramp"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.4,
        "grade": "B",
        "agentReady": false,
        "rank": 159,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 92,
          "payments": 20,
          "reliability": 76,
          "schema": 71,
          "security": 86,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.",
        "bestFor": "Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.",
        "strengths": [
          "Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone",
          "Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page",
          "An application sees only the shared folders and records assigned to it, read-only unless shared as editable",
          "Official MIT MCP server with 19 typed tools, masked values by default and confirmation for writes, deletes and unmasking",
          "SDKs for Python, Java, JavaScript, .NET, Go, Ruby and Rust in one MIT repository, with 5 tagged releases since 15 September 2026"
        ],
        "weaknesses": [
          "Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote",
          "No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with `{\"error\":\"throttled\"}`",
          "No OpenAPI or documented raw HTTP use for `/api/rest/sm/v1`. The SDKs are the only supported route",
          "The Node MCP guide links a GitHub repository that returned 404 on 8 October 2026",
          "Rotation needs a KeeperPAM licence and a Keeper Gateway, and access events are read in the separately sold reporting module"
        ],
        "agentNotes": [
          "Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token",
          "Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context",
          "Expect HTTP 403 with `{\"error\":\"throttled\"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits",
          "A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address",
          "Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.4
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 92,
          "payments": 20,
          "reliability": 76,
          "schema": 71,
          "security": 86,
          "transparency": 58
        },
        "provenanceScore": 98
      },
      "connect": {
        "install": "pip3 install keeper-secrets-manager-cli   # or: pip3 install keeper-secrets-manager-core, npm install @keeper-security/secrets-manager-core",
        "http": "ksm profile init XX:XXXX   # one-time access token from the vault\nksm secret list   # values decrypt on the client, so plain curl can't read them",
        "claudeCode": "/plugin marketplace add Keeper-Security/keeper-agent-kit\n/plugin install keeper-secrets@keeper-security",
        "config": {
          "mcpServers": {
            "ksm": {
              "args": [
                "run",
                "-i",
                "--rm",
                "-e",
                "KSM_CONFIG_BASE64=YOUR_BASE64_CONFIG_STRING_HERE",
                "keeper/keeper-mcp-server:latest"
              ],
              "command": "docker"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/keeper-secrets-manager"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Keeper Security, Inc.",
        "domain": "keepersecurity.com",
        "domainRegistered": "2007-04-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.keepersecurity.com/legal/terms-of-use/#saas-terms",
        "privacy": "https://www.keepersecurity.com/legal/terms-of-use/?s=privacy",
        "statusPage": "https://statuspage.keeper.io",
        "changelog": "https://docs.keeper.io/release-notes/enterprise/keeper-secrets-manager/2026",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "Keeper publishes its website terms, SaaS Terms of Use, partner terms, privacy policy and Service Level Objectives as sections of one page at www.keepersecurity.com/legal/terms-of-use/. The SaaS section governs the service and the `?s=privacy` view is the privacy policy. The old `/termsofuse.html` and `/privacypolicy.html` addresses redirect there.",
          "The SaaS terms name Keeper Security, Inc., 311 W. Monroe Street, Suite 406, Chicago, IL 60606, with Keeper Security EMEA Limited and Keeper Security APAC KK for other regions. The page links legacy terms for the period before 9 March 2026.",
          "The SaaS terms forbid a customer to perform penetration or load testing on the services, and the website terms prohibit scraping or automated data collection on the website.",
          "www.keepersecurity.com/.well-known/security.txt answers with a Bugcrowd contact and Expires 2026-12-31T23:59:59Z.",
          "The SDKs call https://\u003cregion host\u003e/api/rest/sm/v1, where the host is keepersecurity.com, keepersecurity.eu, keepersecurity.com.au, keepersecurity.ca, keepersecurity.jp or govcloud.keepersecurity.us.",
          "The status page and the docs sit on keeper.io. statuspage.keeper.io is Atlassian Statuspage with a Keeper Secrets Manager component.",
          "RDAP for keepersecurity.com gives a registration date of 2007-04-12."
        ],
        "score": 98
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.json",
      "live": {
        "slug": "keeper-secrets-manager",
        "vendorStatus": {
          "page": "https://statuspage.keeper.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T22:39:26.371198882Z"
        },
        "updatedAt": "2026-10-08T22:39:26.371198882Z"
      }
    },
    "answer": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on reliability and payments \u0026 pricing.",
    "b": {
      "slug": "phase",
      "name": "Phase",
      "vendor": "Phi Security Inc.",
      "vendorUrl": "https://phase.dev",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Phase is an open-source secrets manager from Phi Security Inc. with end-to-end encryption, service accounts, secret rotation and audit logs. Agents reach it through a REST API, a CLI and SDKs, on Phase Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/phase",
      "markdownUrl": "https://www.anchorterminal.com/tools/phase.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/phase.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/phase.json",
      "repo": "https://github.com/phasehq/console",
      "license": "MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.phase.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@phase.dev/phase-node"
        },
        {
          "registry": "pypi",
          "name": "phase-dev"
        },
        {
          "registry": "go",
          "name": "github.com/phasehq/golang-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs in to the console with Google, GitHub or GitLab, creates a service account and a token with an optional expiry, and the agent sends it as `Authorization: Bearer ServiceAccount \u003ctoken\u003e`. Personal access tokens use `Bearer User \u003ctoken\u003e` and inherit the user's role. Tokens can also be created and deleted over the API for service accounts with server-side key management. Workloads on AWS or Azure can log in with an external identity and receive a token with a TTL. Access follows the account's role and its apps and environments, not the individual token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 5 users or service accounts, 3 apps, 3 environments, 24-hour audit logs and 120 API requests a minute. Pro is $10 a user a month ($120 billed yearly) with a 14-day trial, unlimited apps, rotation, custom roles, network access policies, 90-day audit logs and 240 requests a minute. Enterprise is $25 a user a month ($300 yearly) with dynamic secrets, OIDC SSO, SCIM, log forwarding and a 99.99 per cent uptime SLA listed. Only human users are charged, and service accounts are free. The pricing page does not say whether a card is taken. Self-hosting the MIT core is free, and the Pro and Enterprise tiers need a licence (https://phase.dev/pricing/).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the API reference or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 928,
        "npmWeekly": 2485,
        "pypiWeekly": 235,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.phase.dev",
      "llmsTxt": "https://docs.phase.dev/llms.txt",
      "capabilities": [
        "secrets.store",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "secrets.rotate"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "cli",
        "llms-txt",
        "go",
        "typescript",
        "python",
        "eu",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-04",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 194,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 56,
          "maintenance": 83,
          "payments": 25,
          "reliability": 91,
          "schema": 58,
          "security": 83,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.",
        "bestFor": "Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.",
        "strengths": [
          "Service account tokens take an expiry and can be created and deleted through `/v1/service-accounts/:id/tokens`, and service accounts are free on every plan",
          "The CLI's AI mode redacts `secret` and `sealed` values and blocks `printenv`, `env` and `phase shell` when it detects an agent",
          "Every reveal and every REST fetch of a secret is recorded as a `READ` event with actor and IP address",
          "MIT outside the `ee/` directories, self-hosted with Docker Compose or Kubernetes, with no outbound usage telemetry per the docs",
          "Eleven console versions between 24 July and 8 October 2026, and no incident on the status page since 30 June 2026"
        ],
        "weaknesses": [
          "No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations",
          "No pagination, field selection or idempotency keys were found in the API reference, and errors are a single free-text `error` string",
          "The Free plan keeps audit logs for 24 hours. Rotation, custom roles and network access policies need Pro, and dynamic secrets need Enterprise",
          "The REST API works only on apps with server-side encryption enabled, which gives up end-to-end encryption for that app",
          "The pricing page lists a Phase Agents Relay credential proxy on every plan, but no documentation or CLI command for it was found"
        ],
        "agentNotes": [
          "Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets",
          "Send `Authorization: Bearer ServiceAccount \u003ctoken\u003e` for a service account and `Bearer User \u003ctoken\u003e` for a personal access token. The token type is part of the header",
          "Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429",
          "Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE`",
          "Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 56,
          "maintenance": 83,
          "payments": 25,
          "reliability": 91,
          "schema": 58,
          "security": 83,
          "transparency": 58
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "curl -fsSL https://pkg.phase.dev/install.sh | sh   # or: brew tap phasehq/cli \u0026\u0026 brew install phase",
        "http": "curl -G https://api.phase.dev/v1/secrets/ -H \"Authorization: Bearer ServiceAccount $PHASE_TOKEN\" \\\n  -d app_id=$PHASE_APP_ID -d env=development",
        "claudeCode": "phase ai enable"
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/phase"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 10,
          "note": "$120 a user billed yearly. Service accounts free"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "$300 a user billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Phi Security Inc.",
        "domain": "phase.dev",
        "domainRegistered": "2023-02-03",
        "endpointOnVendorDomain": true,
        "terms": "https://phase.dev/legal/terms/",
        "privacy": "https://phase.dev/legal/privacy/",
        "statusPage": "https://phase.statuspage.io",
        "changelog": "https://phase.dev/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 6 October 2025) name Phi Security Inc. and cover the website, the Phase Console and the self-hosted version. The site footer gives 8 The Green, Ste A, Dover, DE 19901, United States.",
          "The privacy policy (last updated 11 March 2026) covers phase.dev and the services, gives no retention period in days and refers to the trust centre for the subprocessor list.",
          "security.txt at phase.dev expires on 10 December 2030, lists three contact addresses and points to `SECURITY.md` in the console repository.",
          "trust.phase.dev is drawn by script and gave our reader no text, so the subprocessor list and any DPA were not read.",
          "RDAP for phase.dev gives a registration date of 2023-02-03.",
          "The status page is an Atlassian Statuspage at phase.statuspage.io with components for the console, the API, Cloudflare and AWS eu-central-1."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/phase.json",
      "live": {
        "slug": "phase",
        "probe": {
          "target": "https://api.phase.dev",
          "method": "get",
          "lastAt": "2026-10-08T22:39:55.467014516Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 117,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 119,
          "p95ms24h": 199,
          "samples24h": 36,
          "samples30d": 36,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 36,
              "ok": 36
            }
          ]
        },
        "vendorStatus": {
          "page": "https://phase.statuspage.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T22:39:36.439853631Z"
        },
        "updatedAt": "2026-10-08T22:39:55.467014516Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Keeper Security, Inc.",
        "b": "Phi Security Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.phase.dev",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT",
        "b": "MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence",
        "name": "Licence"
      },
      {
        "a": "19",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-10-04",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2025-10-06",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2026-03-11",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "117 stars, 52k npm/wk, 45k PyPI/wk",
        "b": "928 stars, 2.5k npm/wk, 235 PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on reliability and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Keeper Secrets Manager or Phase?"
      },
      {
        "answer": "Keeper Secrets Manager needs an API key. Phase takes an API key or an OAuth sign-in.",
        "question": "Do Keeper Secrets Manager and Phase need an API key?"
      },
      {
        "answer": "Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed. Phase has a hosted endpoint at https://api.phase.dev.",
        "question": "Can an agent call Keeper Secrets Manager and Phase without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Keeper Secrets Manager. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).",
        "question": "Are Keeper Secrets Manager and Phase open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 71 against 58",
          "Agent ergonomics, 63 against 56",
          "Maintenance \u0026 community, 92 against 83",
          "Transparency \u0026 trust, 78 against 73"
        ],
        "also": [
          "Runs on your own machine"
        ],
        "goodFor": "Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.",
        "slug": "keeper-secrets-manager",
        "watchFor": "Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote"
      },
      {
        "aheadOn": [
          "Reliability, 91 against 76",
          "Payments \u0026 pricing, 25 against 20"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Open source"
        ],
        "goodFor": "Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.",
        "slug": "phase",
        "watchFor": "No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations"
      }
    ],
    "job": {
      "capability": "secrets.store",
      "name": "Secrets store"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/1password-vs-phase.json",
        "title": "1Password service accounts, SDKs and Environments MCP vs Phase",
        "url": "https://www.anchorterminal.com/compare/1password-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/akeyless-vs-phase.json",
        "title": "Akeyless (SecretlessAI and MCP server) vs Phase",
        "url": "https://www.anchorterminal.com/compare/akeyless-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager.json",
        "title": "AWS Secrets Manager vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.json",
        "title": "AWS Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager.json",
        "title": "Azure Key Vault vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.json",
        "title": "Azure Key Vault vs Phase",
        "url": "https://www.anchorterminal.com/compare/azure-key-vault-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager.json",
        "title": "Bitwarden Secrets Manager vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.json",
        "title": "Bitwarden Secrets Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager.json",
        "title": "Doppler vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/doppler-vs-phase.json",
        "title": "Doppler vs Phase",
        "url": "https://www.anchorterminal.com/compare/doppler-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.json",
        "title": "Google Cloud Secret Manager vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.json",
        "title": "Google Cloud Secret Manager vs Phase",
        "url": "https://www.anchorterminal.com/compare/google-secret-manager-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.json",
        "title": "HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.json",
        "title": "HashiCorp Vault + Vault MCP Server vs Phase",
        "url": "https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager.json",
        "title": "Infisical vs Keeper Secrets Manager",
        "url": "https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager"
      },
      {
        "json": "https://www.anchorterminal.com/compare/infisical-vs-phase.json",
        "title": "Infisical vs Phase",
        "url": "https://www.anchorterminal.com/compare/infisical-vs-phase"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.json",
        "title": "Keeper Secrets Manager vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc"
      },
      {
        "json": "https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.json",
        "title": "Phase vs Pulumi ESC",
        "url": "https://www.anchorterminal.com/compare/phase-vs-pulumi-esc"
      }
    ],
    "scores": [
      {
        "by": 15,
        "edge": "phase",
        "keeper-secrets-manager": 76,
        "key": "reliability",
        "name": "Reliability",
        "phase": 91,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "edge": "keeper-secrets-manager",
        "keeper-secrets-manager": 71,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "phase": 58,
        "weight": 13
      },
      {
        "by": 7,
        "edge": "keeper-secrets-manager",
        "keeper-secrets-manager": 63,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "phase": 56,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "keeper-secrets-manager",
        "keeper-secrets-manager": 86,
        "key": "security",
        "name": "Security \u0026 auth",
        "phase": 83,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "phase",
        "keeper-secrets-manager": 20,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "phase": 25,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "keeper-secrets-manager",
        "keeper-secrets-manager": 92,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "phase": 83,
        "weight": 7
      },
      {
        "by": 5,
        "edge": "keeper-secrets-manager",
        "keeper-secrets-manager": 78,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "phase": 73,
        "weight": 7
      }
    ],
    "summary": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on reliability and payments \u0026 pricing. Both do secrets store.",
    "verdicts": {
      "keeper-secrets-manager": "Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.",
      "phase": "Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase",
    "json": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md",
    "slim": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.min.md"
  },
  "markdown": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on reliability and payments \u0026 pricing. Both do secrets store.\n\n- Keeper Secrets Manager: grade B, 69.4/100, rank #159 of 722. Markdown https://www.anchorterminal.com/tools/keeper-secrets-manager.md · JSON https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json\n- Phase: grade B, 68/100, rank #194 of 722. Markdown https://www.anchorterminal.com/tools/phase.md · JSON https://www.anchorterminal.com/api/v1/tools/phase.json\n\n## Which one, for what\n\n### Keeper Secrets Manager (B)\n\nGood for: Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.\n\nAhead on:\n- Schema \u0026 documentation, 71 against 58\n- Agent ergonomics, 63 against 56\n- Maintenance \u0026 community, 92 against 83\n- Transparency \u0026 trust, 78 against 73\n\nAlso in its favour:\n- Runs on your own machine\n\nWatch for: Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote\n\n### Phase (B)\n\nGood for: Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.\n\nAhead on:\n- Reliability, 91 against 76\n- Payments \u0026 pricing, 25 against 20\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Open source\n\nWatch for: No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations\n\n\n## Score by category\n\n| Category | Weight | Keeper Secrets Manager | Phase | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 76 | 91 | Phase +15 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 71 | 58 | Keeper Secrets Manager +13 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 56 | Keeper Secrets Manager +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 83 | Keeper Secrets Manager +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 25 | Phase +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 92 | 83 | Keeper Secrets Manager +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 78 | 73 | Keeper Secrets Manager +5 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **69.4 · B** | **68 · B** | |\n\n## Facts side by side\n\n| Fact | Keeper Secrets Manager | Phase |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Keeper Security, Inc. | Phi Security Inc. |\n| Hosted endpoint | no (local only) | `https://api.phase.dev` |\n| Transports | HTTP, stdio | HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT | MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence |\n| Tools exposed | 19 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-06 | 2026-10-04 |\n| Terms last updated | no date given | 2025-10-06 |\n| Privacy policy last updated | no date given | 2026-03-11 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 117 stars, 52k npm/wk, 45k PyPI/wk | 928 stars, 2.5k npm/wk, 235 PyPI/wk |\n\n## Verdicts\n\n**Keeper Secrets Manager.** Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.\n\n**Phase.** Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.\n\n## Before you call either\n\n### Keeper Secrets Manager\n\n1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token\n2. Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context\n3. Expect HTTP 403 with `{\"error\":\"throttled\"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits\n4. A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address\n5. Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values\n\n### Phase\n\n1. Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets\n2. Send `Authorization: Bearer ServiceAccount \u003ctoken\u003e` for a service account and `Bearer User \u003ctoken\u003e` for a personal access token. The token type is part of the header\n3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429\n4. Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE`\n5. Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself\n\n## Questions\n\n### Which is better for AI agents, Keeper Secrets Manager or Phase?\n\nKeeper Secrets Manager scores 69.4 (B) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on reliability and payments \u0026 pricing.\n\n### Do Keeper Secrets Manager and Phase need an API key?\n\nKeeper Secrets Manager needs an API key. Phase takes an API key or an OAuth sign-in.\n\n### Can an agent call Keeper Secrets Manager and Phase without installing anything?\n\nKeeper Secrets Manager runs on your own machine, with no hosted endpoint listed. Phase has a hosted endpoint at https://api.phase.dev.\n\n### Are Keeper Secrets Manager and Phase open source?\n\nNo open-source release is listed for Keeper Secrets Manager. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.json, and with the fewest tokens: https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"keeper-secrets-manager\", \"b\": \"phase\"}`. From a terminal: `anchor compare keeper-secrets-manager phase`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json and https://www.anchorterminal.com/api/v1/tools/phase.json\n\n## Other comparisons with Keeper Secrets Manager or Phase\n\n- [1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager.md)\n- [1Password service accounts, SDKs and Environments MCP vs Phase](https://www.anchorterminal.com/compare/1password-vs-phase.md)\n- [Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.md)\n- [Akeyless (SecretlessAI and MCP server) vs Phase](https://www.anchorterminal.com/compare/akeyless-vs-phase.md)\n- [AWS Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager.md)\n- [AWS Secrets Manager vs Phase](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.md)\n- [Azure Key Vault vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager.md)\n- [Azure Key Vault vs Phase](https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.md)\n- [Bitwarden Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager.md)\n- [Bitwarden Secrets Manager vs Phase](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.md)\n- [Doppler vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager.md)\n- [Doppler vs Phase](https://www.anchorterminal.com/compare/doppler-vs-phase.md)\n- [Google Cloud Secret Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.md)\n- [Google Cloud Secret Manager vs Phase](https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.md)\n- [HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.md)\n- [HashiCorp Vault + Vault MCP Server vs Phase](https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.md)\n- [Infisical vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager.md)\n- [Infisical vs Phase](https://www.anchorterminal.com/compare/infisical-vs-phase.md)\n- [Keeper Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.md)\n- [Phase vs Pulumi ESC](https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Keeper Secrets Manager vs Phase",
        "url": ""
      }
    ],
    "description": "Keeper Secrets Manager scores 69.4 (B) on agent readiness against Phase's 68 (B), and leads in 5 of 7 scored categories. Phase leads on reliability and payments \u0026 pricing. Both do secrets store. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Keeper Secrets Manager B 69.4",
      "Phase B 68",
      "scores"
    ],
    "h1": "Keeper Secrets Manager vs Phase",
    "image": "https://www.anchorterminal.com/assets/og/compare-keeper-secrets-manager-vs-phase.png",
    "path": "/compare/keeper-secrets-manager-vs-phase",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Keeper Secrets Manager vs Phase for AI agents, B 69.4 vs B 68",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase"
  },
  "tokens": {
    "markdown": 2600,
    "slim": 730
  },
  "version": 1
}
