# Phase vs Pulumi ESC > Pulumi ESC scores 71.1 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Phase leads on reliability and transparency & trust. Both do secrets store. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/phase-vs-pulumi-esc - Markdown: https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md (~2,500 tokens) - Slim: https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.min.md (~680 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 Pulumi ESC scores 71.1 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Phase leads on reliability and transparency & trust. Both do secrets store. - Phase: grade B, 68/100, rank #194 of 722. Markdown https://www.anchorterminal.com/tools/phase.md · JSON https://www.anchorterminal.com/api/v1/tools/phase.json - Pulumi ESC: grade BB, 71.1/100, rank #120 of 722. Markdown https://www.anchorterminal.com/tools/pulumi-esc.md · JSON https://www.anchorterminal.com/api/v1/tools/pulumi-esc.json ## Which one, for what ### Phase (B) Good for: Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI. Ahead on: - Reliability, 91 against 60 - Transparency & trust, 73 against 65 Also in its favour: - Open source Watch for: No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations ### Pulumi ESC (BB) Good for: Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup. Ahead on: - Schema & documentation, 82 against 58 - Agent ergonomics, 75 against 56 - Payments & pricing, 55 against 25 Also in its favour: - Agent-ready, a grade of BB or better - Free to start without a card Watch for: Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise ## Score by category | Category | Weight | Phase | Pulumi ESC | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 91 | 60 | Phase +31 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 58 | 82 | Pulumi ESC +24 | | Agent ergonomics | 13% (16.2 this run) | 56 | 75 | Pulumi ESC +19 | | Security & auth | 14% (17.5 this run) | 83 | 79 | Phase +4 | | Payments & pricing | 10% (12.5 this run) | 25 | 55 | Pulumi ESC +30 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 83 | 82 | Phase +1 | | Transparency & trust | 7% (8.8 this run) | 73 | 65 | Phase +8 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **68 · B** | **71.1 · BB** | | ## Facts side by side | Fact | Phase | Pulumi ESC | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Phi Security Inc. | Pulumi Corporation | | Hosted endpoint | `https://api.phase.dev` | `https://api.pulumi.com` | | Transports | HTTP | HTTP | | Auth | OAuth or key | OAuth or key | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence | Proprietary service under Pulumi's Terms & Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0 | | Read-only variant documented | no | yes | | llms.txt | yes | yes | | Last release | 2026-10-04 | 2026-10-07 | | Terms last updated | 2025-10-06 | no date given | | Privacy policy last updated | 2026-03-11 | no date given | | Customer content may train models | not found in the text | not found in the text | | Terms restrict automated access | yes | not found in the text | | Terms restrict benchmarking | yes | not found in the text | | Terms or service can change without notice | not found in the text | yes | | Arbitration or class-action waiver | not found in the text | not found in the text | | Popularity | 928 stars, 2.5k npm/wk, 235 PyPI/wk | 21k npm/wk, 54k PyPI/wk | ## Verdicts **Phase.** Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours. **Pulumi ESC.** An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation. ## Before you call either ### Phase 1. Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets 2. Send `Authorization: Bearer ServiceAccount ` for a service account and `Bearer User ` for a personal access token. The token type is part of the header 3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429 4. Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE` 5. Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself ### Pulumi ESC 1. Use `pulumi env`, not `esc`. The standalone CLI stopped at v0.26.0 and gets no security fixes 2. Read one value with `pulumi env open // ` so the whole environment doesn't enter context 3. Run tools with `pulumi env run -- `, which filters secret values from the command's output unless -i is set 4. Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk 5. Send `Authorization: token ` and `Accept: application/vnd.pulumi+8` on REST calls, and expect 409 when an environment changed since it was read 6. Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed ## Questions ### Which is better for AI agents, Phase or Pulumi ESC? Pulumi ESC scores 71.1 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Phase leads on reliability and transparency & trust. ### Do Phase and Pulumi ESC need an API key? Both take an API key or an OAuth sign-in. ### Can an agent call Phase and Pulumi ESC without installing anything? Yes. Phase has a hosted endpoint at https://api.phase.dev and Pulumi ESC at https://api.pulumi.com. ### Are Phase and Pulumi ESC open source? Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence). No open-source release is listed for Pulumi ESC. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.json, and with the fewest tokens: https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "phase", "b": "pulumi-esc"}`. From a terminal: `anchor compare phase pulumi-esc` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/phase.json and https://www.anchorterminal.com/api/v1/tools/pulumi-esc.json ## Other comparisons with Phase or Pulumi ESC - [1Password service accounts, SDKs and Environments MCP vs Phase](https://www.anchorterminal.com/compare/1password-vs-phase.md) - [1Password service accounts, SDKs and Environments MCP vs Pulumi ESC](https://www.anchorterminal.com/compare/1password-vs-pulumi-esc.md) - [Akeyless (SecretlessAI and MCP server) vs Phase](https://www.anchorterminal.com/compare/akeyless-vs-phase.md) - [Akeyless (SecretlessAI and MCP server) vs Pulumi ESC](https://www.anchorterminal.com/compare/akeyless-vs-pulumi-esc.md) - [AWS Secrets Manager vs Phase](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.md) - [AWS Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-pulumi-esc.md) - [Azure Key Vault vs Phase](https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.md) - [Azure Key Vault vs Pulumi ESC](https://www.anchorterminal.com/compare/azure-key-vault-vs-pulumi-esc.md) - [Bitwarden Secrets Manager vs Phase](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.md) - [Bitwarden Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-pulumi-esc.md) - [Doppler vs Phase](https://www.anchorterminal.com/compare/doppler-vs-phase.md) - [Doppler vs Pulumi ESC](https://www.anchorterminal.com/compare/doppler-vs-pulumi-esc.md) - [Google Cloud Secret Manager vs Phase](https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.md) - [Google Cloud Secret Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/google-secret-manager-vs-pulumi-esc.md) - [HashiCorp Vault + Vault MCP Server vs Phase](https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.md) - [HashiCorp Vault + Vault MCP Server vs Pulumi ESC](https://www.anchorterminal.com/compare/hashicorp-vault-vs-pulumi-esc.md) - [Infisical vs Phase](https://www.anchorterminal.com/compare/infisical-vs-phase.md) - [Infisical vs Pulumi ESC](https://www.anchorterminal.com/compare/infisical-vs-pulumi-esc.md) - [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md) - [Keeper Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.md)