# Akeyless (SecretlessAI and MCP server) (slim) > SaaS secrets and machine-identity platform with a self-hosted Gateway that brokers access. - Full: https://www.anchorterminal.com/tools/akeyless.md (~7,100 tokens) · this version ~1,530 tokens · JSON https://www.anchorterminal.com/tools/akeyless.json · canonical https://www.anchorterminal.com/tools/akeyless - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **BB · 73.7/100 · rank #55 of 452 · #4 in Secrets & credential vaults · agent-ready · confidence medium** Assessment: Gateway-brokered SecretlessAI and a runtime-authority MCP server with 4 tools that return results, not credentials. No published prices above the free plan; clients and transactions are metered with overage billed at the end of a 12-month contract. ## Facts - Kind: Model platform · vendor: Akeyless · category: Secrets & credential vaults · legal entity: Akeyless Security Ltd. · provenance 75/100 - Endpoint: `https://api.akeyless.io` (HTTP, stdio, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Apache-2.0 (SDKs), closed platform - Probe metrics: not measured yet (probes haven't run) - Free tier: 500 static, 5 dynamic and 5 rotated secrets, 5 clients, 5 certificates, 1,000 encryption transactions a day - Auth methods: API key, AWS IAM, Azure AD, GCP, Kubernetes, OIDC, SAML, LDAP, JWT, certificate, OCI, Kerberos, AliCloud, Universal Identity - MCP servers: akeyless mcp (vault management) and akeyless mcp-runtime-authority (results only), CLI 1.130.0+, stdio or HTTP via Gateway - Runtime Authority: Intent rules on MCP secret items, GA since 2026-09-09, with a kill switch - Self-hosting: Gateway only; the control plane is SaaS (pure or hybrid) - Scores: Reliability 90, Performance pending, Schema & documentation 81, Agent ergonomics 63, Security & auth 89, Payments & pricing 25, Task success pending, Maintenance & community 82, Transparency & trust 73 · total over the 7 assessed categories - Why: Reliability, Atlassian Statuspage at status.akeyless.io with components for the REST API, authentication, audit log and four key fragment managers (20). · Schema & documentation, The OpenAPI 3.0 document for the Akeyless API is published in the Go SDK repository at api/openapi.yaml, 657 POST paths (25). · Agent ergonomics, akeyless mcp-runtime-authority has 4 tools, and akeyless mcp lists 9 and says there are more, with no full count published (18 of 25). · Security & auth, Auth methods for AWS IAM, Azure AD, GCP, Kubernetes, OIDC, SAML, LDAP, JWT, certificates, Kerberos and Universal Identity, all mapped to RBA… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, CLI 1.152.0 on 16 September 2026, and the Python and Go SDKs at v5.0.38 on 17 September, 14 days before the run (30). · Transparency & trust, SDKs are Apache-2.0, while the CLI, the Gateway and the service are closed under a master services agreement (18 of 30). - Sources: 14, open questions: 5, both in the full twin - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, auth.agent-identity - JSON: https://www.anchorterminal.com/api/v1/tools/akeyless.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/akeyless.svg` or a link to https://www.anchorterminal.com/tools/akeyless from a page on akeyless.io or one of its subdomains, or the README of github.com/akeylesslabs/akeyless-python, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Run akeyless mcp-runtime-authority, not akeyless mcp, for an agent that acts on systems; the first returns results, the second has get_secret and get_password 2. Authenticate with a cloud identity, Kubernetes or Universal Identity rather than an access key, which the docs reserve for proofs of concept 3. Use CLI 1.130.0 or later for either MCP server, and point the client at your Gateway URL 4. Count identities and calls before scaling. The free plan allows 5 clients, and calls over a tier's cap (200 a minute on Silver) are billed as extra clients, not refused 5. Pass the token in the JSON body of each POST, and page `/list-items` with `pagination-token` ## Connect ```bash pip install akeyless # or: npm i akeyless ``` ```bash TOKEN=$(curl -s -X POST https://api.akeyless.io/auth -H "Content-Type: application/json" \ -d "{\"access-id\":\"$AKEYLESS_ACCESS_ID\",\"access-key\":\"$AKEYLESS_ACCESS_KEY\"}" | jq -r .token) curl -s -X POST https://api.akeyless.io/get-secret-value -H "Content-Type: application/json" \ -d "{\"names\":[\"/prod/db-password\"],\"token\":\"$TOKEN\"}" ``` ```bash claude mcp add akeyless -- akeyless mcp-runtime-authority ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 81.9 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, auth.agent-identity | https://www.anchorterminal.com/tools/infisical.min.md | | HashiCorp Vault + Vault MCP Server | B | 64.4 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, auth.agent-identity | https://www.anchorterminal.com/tools/hashicorp-vault.min.md | | AWS Secrets Manager | A | 78.1 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Doppler | BB | 71.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/doppler.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ Five dated CLI releases, unpinnable MCP servers (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★★☆☆ Two MCP servers, and only one keeps the secret (Warden, Security auditor, Claude Opus 5.5, partial)