# Azure Key Vault (slim) > Microsoft Azure's managed store for secrets, encryption keys and TLS certificates. Applications read secrets over a REST API or the Azure SDKs and CLI, signing in with Microsoft Entra ID and authorised by Azure role assignments. - Full: https://www.anchorterminal.com/tools/azure-key-vault.md (~9,200 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/azure-key-vault.json · canonical https://www.anchorterminal.com/tools/azure-key-vault - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 74.7/100 · rank #60 of 722 · #4 in Secrets & credential vaults · agent-ready · confidence medium** Assessment: Access runs on Microsoft Entra ID tokens and Azure roles that can be scoped to one secret, with soft delete, a 99.99 per cent SLA and a public OpenAPI contract. Secret rotation needs an Event Grid trigger and a function the owner writes, audit logging is off until enabled, and an Azure subscription needs a person and a payment card. ## Facts - Kind: HTTP API · vendor: Microsoft Corporation · category: Secrets & credential vaults · legal entity: Microsoft Corporation · provenance 86/100 - Endpoint: `https://.vault.azure.net` (HTTP) - Auth: OAuth · pricing: Pay per use · x402: no · licence: Proprietary service under Microsoft's Product Terms. The Azure SDK client libraries are MIT - Probe metrics: not measured yet (probes haven't run) - API: REST data plane at https://.vault.azure.net, 12 secrets operations (get, set, update, delete, list, versions, backup, restore, and four for deleted secrets). Stable API version 2025-07-01. Vaults are created through Azure Resource Manager, control plane version 2026-02-01 - Credentials: Microsoft Entra ID bearer tokens only. Managed identities on Azure, service principals elsewhere. Roles assignable down to one secret - Rate limits: Per vault per region, 4,000 transactions per 10 seconds, 300 for secret creation and key or certificate import combined. A subscription gets five times the vault limit - Limits: 25 KB a secret, 25 results a list page, no cap on secrets or versions in a vault. Backup fails above 500 versions - Deletion: Soft delete keeps deleted vaults and secrets recoverable for 7 to 90 days (90 by default). Purge protection blocks early purging - Rotation: Keys rotate by policy. Secrets rotate through an Event Grid near-expiry event, raised 30 days before expiry, and an Azure Function the owner supplies - Audit: AuditEvent logs through a diagnostic setting to a storage account, event hub or Azure Monitor, with caller identity and IP address, readable within 10 minutes. Not on by default - SLA: 99.99% monthly uptime for transactions other than creating, updating or deleting vaults, keys or secrets. Credits of 10% below 99.99% and 25% below 99% - Tiers: Standard (software cryptography validated to FIPS 140 Level 1) and Premium (keys in HSMs validated to FIPS 140-3 Level 3). Secrets cost the same in both - SDKs: Python azure-keyvault-secrets 4.11.3 (2 October 2026), JavaScript @azure/keyvault-secrets 4.11.2, .NET Azure.Security.KeyVault.Secrets 4.11.2, Go azsecrets v1.5.0, and Java. MIT - MCP server: None dedicated. The Azure MCP Server, listed separately, has Key Vault secret, key and certificate tools with consent prompts and a read-only mode - Prices: Secrets operations $0.003 per 1,000 tool calls; Certificate renewal request $3 per transaction - Scores: Reliability 87, Performance pending, Schema & documentation 85, Agent ergonomics 75, Security & auth 86, Payments & pricing 20, Task success pending, Maintenance & community 80, Transparency & trust 77 · total over the 7 assessed categories - Why: Reliability, Hosted reading. · Schema & documentation, A public OpenAPI 2.0 document for the secrets data plane, version 2025-07-01, with 12 operations (25). · Agent ergonomics, API reading. · Security & auth, Microsoft Entra ID OAuth 2.0 bearer tokens in a header, managed identities for workloads on Azure, and no API keys (30). · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Read as a closed service with official SDKs. · Transparency & trust, Closed service under Microsoft's Product Terms, with MIT client libraries (15 of 30). - Sources: 31, open questions: 9, both in the full twin - Capabilities: secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate, infra.azure - JSON: https://www.anchorterminal.com/api/v1/tools/azure-key-vault.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/azure-key-vault.svg` or a link to https://www.anchorterminal.com/tools/azure-key-vault from a page on microsoft.com or one of its subdomains, or the README of github.com/Azure/azure-rest-api-specs, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Request a token for the resource https://vault.azure.net and send it as a Bearer header. Every call must carry `api-version`, such as 2025-07-01, because there is no default 2. Ask for the Key Vault Secrets User role on the vault or the single secret. Key Vault Reader returns metadata only, not values 3. Cache secret values in memory. A vault allows 4,000 reads and 300 secret creations per 10 seconds, and a subscription five times that 4. On 429 wait 1, 2, 4, 8 then 16 seconds. Throttled requests do not count against the limit 5. Don't retry Set Secret blindly. Each successful call creates a new version of the secret ## Connect ```bash pip install azure-keyvault-secrets azure-identity # or: npm i @azure/keyvault-secrets @azure/identity ``` ```bash GET https://.vault.azure.net/secrets/?api-version=2025-07-01 Authorization: Bearer ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/azure-key-vault ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 83.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/infisical.min.md | | AWS Secrets Manager | BB | 77.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.5 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/akeyless.min.md | | Doppler | BB | 71.4 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/doppler.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)