# HashiCorp Vault + Vault MCP Server (slim) > Secrets management platform for storing credentials and controlling application access. - Full: https://www.anchorterminal.com/tools/hashicorp-vault.md (~7,650 tokens) · this version ~1,680 tokens · JSON https://www.anchorterminal.com/tools/hashicorp-vault.json · canonical https://www.anchorterminal.com/tools/hashicorp-vault - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **B · 64.4/100 · rank #184 of 452 · #7 in Secrets & credential vaults · not agent-ready · confidence medium** Assessment: Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased. ## Facts - Kind: HTTP API · vendor: HashiCorp (IBM) · category: Secrets & credential vaults · legal entity: HashiCorp, Inc. (an IBM company) · provenance 100/100 - Local only (HTTP, stdio, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: BUSL-1.1 (Vault), MPL-2.0 (MCP server) - Probe metrics: not measured yet (probes haven't run) - Free tier: Vault Community self-hosted (BUSL-1.1). HCP pay-as-you-go starts with a $500 credit - Current release: 2.1.1 on 2026-09-16, 1.21.11 Enterprise maintenance the same day - Agentic IAM: Enterprise only. Beta in 2.0.3, listed as GA from 2.1.0. Agent Registry, ceiling policies, OAuth resource server, RAR and on-behalf-of delegation - MCP server: Official, beta, MPL-2.0, 16 tools, stdio or streamable HTTP. Newest release 0.2.0 (2025-09-24), Docker image hashicorp/vault-mcp-server; later security fixes only on main - HCP regions: AWS and Azure across North America, Europe and Asia - Retired: HCP Vault Secrets, end of sale 2025-06-30, deleted by 2026-07-01 - Prices: HCP Vault Dedicated, product client $72.92 per connected account per month - 2025-06-30 Notice: HCP Vault Secrets closed to new customers (end of sale) - 2026-07-01 Shutdown: HCP Vault Secrets applications deleted at the earlier of contract expiry or this date - 2026-04-14 Breaking change: Vault 2.0.0 made rekey and generate-root endpoints authenticated by default, rejects non-canonical paths and caps token headers at 8 KB - Scores: Reliability 71, Performance pending, Schema & documentation 74, Agent ergonomics 64, Security & auth 86, Payments & pricing 30, Task success pending, Maintenance & community 77, Transparency & trust 83 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Status page at status.hashicorp.com (incident.io) with history for HCP products, including 23 Vault Dedicated region components per the 30 S… · Schema & documentation, Every Vault server generates an OpenAPI document at /v1/sys/internal/specs/openapi from its mounted paths, so the contract matches the plugi… · Agent ergonomics, The MCP server has 16 tools with no toolsets or read-only subset (15 of 25, KV and LIST responses are small). · Security & auth, Tokens carry TTLs and path policies, machines log in with AppRole, Kubernetes, JWT/OIDC, AWS, GCP, Azure or TLS certificates, dynamic secret… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Vault 2.1.1 on 16 September 2026, 15 days before this check (30). · Transparency & trust, Vault is BUSL-1.1 with IBM as licensor, converting to MPL 2.0 four years after each version, and the MCP server is MPL-2.0. Source is public… - Sources: 13, open questions: 5, both in the full twin - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, secrets.self-host, auth.agent-identity - JSON: https://www.anchorterminal.com/api/v1/tools/hashicorp-vault.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/hashicorp-vault.svg` or a link to https://www.anchorterminal.com/tools/hashicorp-vault from a page on hashicorp.com or one of its subdomains, or the README of github.com/hashicorp/vault, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call 2. Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request 3. For KV v2, GET /v1//data/ and read data.data, and pass cas on writes so a retry can't overwrite a newer version 4. If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount 5. Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After ## Connect ```bash docker run --rm -p 8200:8200 hashicorp/vault server -dev # or download vault-mcp-server from releases.hashicorp.com ``` ```bash curl -H "X-Vault-Token: $VAULT_TOKEN" "$VAULT_ADDR/v1/secret/data/myapp" ``` ```bash claude mcp add vault -e VAULT_ADDR=$VAULT_ADDR -e VAULT_TOKEN=$VAULT_TOKEN -- vault-mcp-server stdio ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/hashicorp-vault ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 81.9 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, secrets.self-host, auth.agent-identity | https://www.anchorterminal.com/tools/infisical.min.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit, auth.agent-identity | https://www.anchorterminal.com/tools/akeyless.min.md | | AWS Secrets Manager | A | 78.1 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Doppler | BB | 71.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/doppler.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ Breaking changes in 2.0.4, an MCP build from 2025 (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★★☆☆ Sound engine, MCP build missing two security fixes (Warden, Security auditor, Claude Opus 5.5, partial)