Head to head · Secrets store · October 2026 research run
Keeper Secrets Manager vs Pulumi ESC
Pulumi ESC scores 71.1 (BB) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 3 of 7 scored categories. Keeper Secrets Manager leads on reliability, security & auth, maintenance & community and transparency & trust. Both do secrets store.
Which one, for what
Good for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.
Ahead on
- Reliability, 76 against 60
- Security & auth, 86 against 79
- Maintenance & community, 92 against 82
- Transparency & trust, 78 against 65
Also in its favour
- Runs on your own machine
Watch for
Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote
Pulumi ESC BB
Good for Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.
Ahead on
- Schema & documentation, 82 against 71
- Agent ergonomics, 75 against 63
- Payments & pricing, 55 against 20
Also in its favour
- Agent-ready, a grade of BB or better
- A hosted endpoint, with nothing to install
- Free to start without a card
Watch for
Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise
Score by category
| Category | Weight this run | Keeper Secrets Manager | Pulumi ESC | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 76 | 60 | Keeper Secrets Manager +16 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 71 | 82 | Pulumi ESC +11 |
| Agent ergonomics | 13%16.2 | 63 | 75 | Pulumi ESC +12 |
| Security & auth | 14%17.5 | 86 | 79 | Keeper Secrets Manager +7 |
| Payments & pricing | 10%12.5 | 20 | 55 | Pulumi ESC +35 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 92 | 82 | Keeper Secrets Manager +10 |
| Transparency & trust | 7%8.8 | 78 | 65 | Keeper Secrets Manager +13 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 69.4 · B | 71.1 · BB |
Facts side by side
| Fact | Keeper Secrets Manager | Pulumi ESC |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Keeper Security, Inc. | Pulumi Corporation |
| Hosted endpoint | no (local only) | https://api.pulumi.com |
| Transports | HTTP, stdio | HTTP |
| Auth | API key | OAuth or key |
| Pricing | Paid | Freemium |
| x402 | no | no |
| Licence | Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT | Proprietary service under Pulumi's Terms & Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0 |
| Tools exposed | 19 | none |
| Read-only variant documented | yes | yes |
| llms.txt | yes | yes |
| Last release | 2026-10-06 | 2026-10-07 |
| Terms last updated | no date given | no date given |
| Privacy policy last updated | no date given | no date given |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | not found in the text | not found in the text |
| Terms restrict benchmarking | not found in the text | not found in the text |
| Terms or service can change without notice | not found in the text | yes |
| Arbitration or class-action waiver | yes | not found in the text |
| Popularity | 117 stars, 52k npm/wk, 45k PyPI/wk | 21k npm/wk, 54k PyPI/wk |
Verdicts
Keeper Secrets Manager
Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.
Pulumi ESC
An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.
Before you call either
Keeper Secrets Manager
- Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token
- Run commands under
ksm execso secrets arrive as environment variables and stay out of the model's context - Expect HTTP 403 with
{"error":"throttled"}under load. The Python SDK retries five times from 11 seconds, so allow for long waits - A device is locked to the IP address it first connects from unless it was created with
--unlock-ip. Check this before running from a dynamic address - Leave
--auto-approveoff on the MCP server. It removes confirmation for deletes and for unmasking values
Pulumi ESC
- Use
pulumi env, notesc. The standalone CLI stopped at v0.26.0 and gets no security fixes - Read one value with
pulumi env open <org>/<project>/<env> <property path>so the whole environment doesn't enter context - Run tools with
pulumi env run <env> -- <cmd>, which filters secret values from the command's output unless -i is set - Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk
- Send
Authorization: token <token>andAccept: application/vnd.pulumi+8on REST calls, and expect 409 when an environment changed since it was read - Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed
Questions
Which is better for AI agents, Keeper Secrets Manager or Pulumi ESC?
Pulumi ESC scores 71.1 (BB) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 3 of 7 scored categories. Keeper Secrets Manager leads on reliability, security & auth, maintenance & community and transparency & trust.
Do Keeper Secrets Manager and Pulumi ESC need an API key?
Keeper Secrets Manager needs an API key. Pulumi ESC takes an API key or an OAuth sign-in.
Can an agent call Keeper Secrets Manager and Pulumi ESC without installing anything?
Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed. Pulumi ESC has a hosted endpoint at https://api.pulumi.com.
Other comparisons with Keeper Secrets Manager or Pulumi ESC
- 1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager
- 1Password service accounts, SDKs and Environments MCP vs Pulumi ESC
- Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager
- Akeyless (SecretlessAI and MCP server) vs Pulumi ESC
- AWS Secrets Manager vs Keeper Secrets Manager
- AWS Secrets Manager vs Pulumi ESC
- Azure Key Vault vs Keeper Secrets Manager
- Azure Key Vault vs Pulumi ESC
- Bitwarden Secrets Manager vs Keeper Secrets Manager
- Bitwarden Secrets Manager vs Pulumi ESC
- Doppler vs Keeper Secrets Manager
- Doppler vs Pulumi ESC
- Google Cloud Secret Manager vs Keeper Secrets Manager
- Google Cloud Secret Manager vs Pulumi ESC
- HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager
- HashiCorp Vault + Vault MCP Server vs Pulumi ESC
- Infisical vs Keeper Secrets Manager
- Infisical vs Pulumi ESC
- Keeper Secrets Manager vs Phase
- Phase vs Pulumi ESC
Machine-readable
- This page as Markdown
/compare/keeper-secrets-manager-vs-pulumi-esc.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/keeper-secrets-manager.json·/api/v1/tools/pulumi-esc.json - From a terminal
anchor compare keeper-secrets-manager pulumi-esc(the CLI) - Over MCP
compare_tools {"a": "keeper-secrets-manager", "b": "pulumi-esc"}at/mcp, no key