Pulumi ESC
by Pulumi Corporation HTTP API in Secrets & credential vaults
Hosted Agent-ready
Pulumi Corporation · pulumi.com since 2017 · status page · who's behind it
Pulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs.
Good for Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.
Is this your product? Claim this listing or verify it
Assessment. An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.
Facts
- Transport
- HTTP
- Endpoint
https://api.pulumi.com- Auth
- OAuth or key
- Pricing
- Freemium · $0.01 / 1k req
- x402
- No
- Licence
- Proprietary service under Pulumi's Terms & Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0
- Packages
npm@pulumi/esc-sdkpypipulumi-esc-sdkgogithub.com/pulumi/esc-sdk/sdk- llms.txt
- published
- Last release
- npm / week
- 21k
- PyPI / week
- 54k
- Surface graded
- Managed Pulumi Cloud at https://api.pulumi.com, reached through
pulumi env, the REST API and the ESC SDKs - Free edition
- 1 user, 25 secrets, 10,000 API calls a month, no card. Personal tokens only
- Paid editions
- Essentials $40 a month, Pro $400, Enterprise $2,000, each including the same number of credits at $1 a credit
- Unit prices
- Managed secret $0.50 a month on Essentials, $0.75 on Pro, $1.00 on Enterprise. API calls $0.10 per 10,000. Plaintext config free
- Agent accounts
- The CLI creates an ephemeral individual account when run under an agent with no credentials. Write access for 72 hours, claim within 30 days
- Credentials
- Personal, organisation (Essentials up) and team (Pro up) tokens with expiry up to two years, and OIDC token exchange with a 25-hour default maximum
- Dynamic credentials
- Login providers for AWS, Azure, Google Cloud, GitHub, Snowflake, Vault, Doppler and Infisical
- External stores
- AWS Secrets Manager and Parameter Store, Azure Key Vault, Google Secret Manager, HashiCorp Vault, 1Password, Doppler and Infisical
- Rotation
- Rotators for AWS IAM, Azure app secrets, MySQL, Postgres, Snowflake users and passwords, run by
pulumi env rotateor on a schedule, keeping two valid secrets - Audit
- environment-open, environment-read-open and environment-decrypted events with user, time and source IP. Pro and Enterprise
- Approvals
- Update approvals and open approvals by ruleset. Pro and Enterprise
- SDKs
- TypeScript @pulumi/esc-sdk, Python pulumi-esc-sdk, Go github.com/pulumi/esc-sdk/sdk and .NET Pulumi.Esc.Sdk, all 0.14.0 (15 June 2026), Apache-2.0
- MCP server
- The Pulumi MCP server at https://mcp.ai.pulumi.com/mcp lists no ESC tools in its docs
- Self-hosting
- Enterprise edition only, through sales
- Status
- status.pulumi.com on Atlassian Statuspage, with an ESC component
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it
- Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page
- OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default
- Separate read, open and write scopes per environment, with open approvals and update approvals on Pro and Enterprise
- Prices published per unit, $0.50 a secret a month on Essentials and $0.10 per 10,000 API calls, with a free edition and no card
Weaknesses
- Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise
- No API rate limit with numbers was found in the reviewed documentation
- No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date
- The official Pulumi MCP server lists no ESC tools, and the standalone esc CLI was retired at v0.26.0 on 9 July 2026
- A 42-minute major incident on 6 October 2026 affected inbound OIDC on the API and ESC, with no detail published
- The free edition has personal tokens only, which carry all of the user's permissions
Before you call it notes for agents
- Use
pulumi env, notesc. The standalone CLI stopped at v0.26.0 and gets no security fixes - Read one value with
pulumi env open <org>/<project>/<env> <property path>so the whole environment doesn't enter context - Run tools with
pulumi env run <env> -- <cmd>, which filters secret values from the command's output unless -i is set - Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk
- Send
Authorization: token <token>andAccept: application/vnd.pulumi+8on REST calls, and expect 409 when an environment changed since it was read - Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed
Who's behind it provenance 82/100
- Legal entity namedPulumi Corporation20/20
- Domain agepulumi.com, registered 2017-02-13 (9 years)11/15
- Endpoint on the vendor's domainapi.pulumi.com15/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 1 clause that costs points6.3/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagestatus.pulumi.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 2 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, changes without notice and cut-off without notice or for any reason.
Says the terms or the service can change without noticecosts points
You acknowledge and agree that the form and nature of the Pulumi Services which Pulumi provides may change from time to time without prior notice to you, subject to the terms in Section 4.3.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
9.4 You agree that Pulumi, in its sole discretion and for any or no reason, may terminate your account or any part thereof.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Washington
15.6 The Terms, and your relationship with Pulumi under the Terms, shall be governed by the laws of the State of Washington without regard to its conflict of laws provisions.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
…YOU EXPRESSLY UNDERSTAND AND AGREE THAT PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
4.3 If any charge owed by you is 30 days or more overdue, Pulumi may, without limiting its other rights and remedies, suspend your access to Pulumi Services until such amounts are paid in full, provided we have given you 10 or more days' prior notice that your account is overdue.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives seven days of notice before a change
If we change the Terms in any substantive way, we will give you at least seven (7) days’ notice before the changes take effect, during which period of time you may reject the changes by terminating your account.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
1.3 You may not use the Pulumi Services if you are a person barred from receiving the Pulumi Services under the laws of the United States or other countries, including the country in which you are resident or from which you use the Pulumi Services.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Pulumi may use the customer's trade names, trademarks and logos in marketing materials and customer lists at its sole discretion.
8.4 You agree that Pulumi, in its sole discretion, may use your trade names, trademarks, service marks, logos, domain names and other distinctive brand features in presentations, marketing materials, customer lists, financial reports and Web site listings
Noted by a second reader on 2026-10-08.
The agreement renews automatically for periods equal to the initial term unless either party asks to end it at least 30 days before the term ends.
shall be automatically renewed for additional periods of the same duration as the Initial Service Term (collectively, the “Term”), unless either party requests termination at least thirty (30) days prior to the end of the then-current term.
Noted by a second reader on 2026-10-08.
The liability clause says Pulumi is not liable to the customer for direct damages as well as indirect, incidental, special, consequential or exemplary ones.
PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 4,245 words
Privacy policy gives no date, states 7 of 8, 1 to know
TL;DR Gives no date. States 7 of the 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
With third–party social networks, advertising networks and websites, which usually act as separate controllers, so that Pulumi can market and advertise on third party platforms and websites;
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
Please read this Privacy Statement carefully to learn how we collect, use, share and otherwise process information relating to individuals ("Personal Data"), and your rights and choices regarding our processing of your Personal Data.
The basic statement a privacy policy exists to make.
Says how long data is kept
We may retain your Personal Data for a period of time consistent with the original purpose of collection (see "Purposes for which we process Personal Data and on what legal basis" section above).
Says when data sent to the service is deleted.
Says who else receives the data
We may also collect information about you from other sources, including third parties from whom we have purchased Personal Data, and combine this information with Personal Data provided by you.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
…through which our customers may create their own websites and applications running on our platforms, sell or offer their own products and services, send electronic communications to other individuals, and collect and analyze Personal Data from individuals.
A plain statement either way.
Says what rights people have over their data
…is necessary for our legitimate interests to advertise our websites or, where necessary, to the extent you have provided your prior separate consent (please also view "Your rights relating to your Personal Data" below to learn how you can control how your Personal Data is processed by Pulumi for marketing purposes);
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@pulumi.com
If you have questions or complaints regarding Pulumi's Privacy Statement or associated practices, please contact us at privacy@pulumi.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
In this event, we will ensure that such recipient offers an adequate level of protection, for instance by entering into standard contractual clauses for the transfer of data as approved by the European Commission (Art.
The countries data goes to and the safeguard used.
The statement says it does not apply to the cloud products and services through which customers create and run their own websites and applications.
This Privacy Statement does not apply to the extent we offer our customers various cloud products and services through which our customers may create their own websites and applications running on our platforms
Noted by a second reader on 2026-10-08.
Pulumi collects business contact details and web behaviour data from third party data providers for targeted advertising and profiling.
‘intent data’ which is web user behavior data, IP addresses, social handles, LinkedIn URL and custom profiles from third party data providers for the purposes of targeted advertising, delivering relevant email content, event promotion and profiling;
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,514 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms & Conditions govern use of the Pulumi Services and name Pulumi Corporation, 601 Union St., Suite 1415, Seattle, WA 98101, with Washington law and King County courts. We found no date on the page.
The privacy statement covers customers who register to use the services and gives privacy@pulumi.com as contact. We found no date on the page.
www.pulumi.com/.well-known/security.txt and www.pulumi.com/security.txt both return 404. The security page gives security@pulumi.com and a PGP key.
status.pulumi.com is Atlassian Statuspage with an ESC component. Its incident feed goes back to October 2023.
No data processing addendum or subprocessor list was found on www.pulumi.com. The addresses we tried returned 404 and the sitemap lists neither.
RDAP for pulumi.com gives a registration date of 2017-02-13.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 19:08 UTC
Probed every five minutes at https://api.pulumi.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 4 minutes ago
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| www.pulumi.com/releases/changelog | changelog | 41 minutes ago · 200 | no change seen |
| www.pulumi.com/pricing | pricing | 41 minutes ago · 200 | no change seen |
| www.pulumi.com/privacy | privacy | 41 minutes ago · 200 | no change seen |
| www.pulumi.com/terms-and-conditions | terms | 41 minutes ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/pulumi-esc.json
Notable
- Agent accounts give an AI agent a free ephemeral Pulumi Cloud account with ESC and no signup. Write access lasts 72 hours and a person has 30 days to claim it source
- The standalone esc CLI was retired with v0.26.0 on 9 July 2026. Every command is now
pulumi envin the Pulumi CLI source pulumi apicalls any REST endpoint with the CLI's credentials, lists the OpenAPI operations as JSON and writes errors as a one-line JSON envelope source- Rotated secrets keep two valid credentials at a time, so instances that haven't picked up the new one keep working source
- Audit logs record every environment open, read and decrypt with user, time and source IP, on Pro and Enterprise source
- A major incident on 6 October 2026 affected inbound OIDC on the API and ESC for 42 minutes source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 12.0 | |
| Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.3 | |
| OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15). | |||
| Agent ergonomics | 13%16.2 | 12.2 | |
pulumi env open takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and pulumi api --paginate follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and pulumi api writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and --dry-run validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15). | |||
| Security & auth | 14%17.5 | 13.8 | |
OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in pulumi env run. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20). | |||
| Payments & pricing | 10%12.5 | 6.9 | |
| No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.2 | |
Pulumi CLI v3.268.0, which carries pulumi env, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10). | |||
| Transparency & trusteditorial 48, provenance 82 | 7%8.8 | 5.7 | |
| The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 71.1 · BB | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Pulumi ESC, or have the agent fetch /fixes/pulumi-esc.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Pulumi ESC From Anchor Terminal's listing at https://www.anchorterminal.com/tools/pulumi-esc, the October 2026 research run, assessed 8 October 2026. Grade BB, 71.1 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Pulumi ESC: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 60 out of 100, up to 8 more on the total Why it scored 60: Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 55 out of 100, up to 5.6 more on the total Why it scored 55: No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Agent ergonomics, 75 out of 100, up to 4.1 more on the total Why it scored 75: `pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and `pulumi api --paginate` follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and `pulumi api` writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and `--dry-run` validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Security & auth, 79 out of 100, up to 3.7 more on the total Why it scored 79: OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in `pulumi env run`. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 5. Transparency & trust, 65 out of 100, up to 3.1 more on the total Made of editorial 48, provenance 82. Why it scored 65: The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: pulumi.com, registered 2017-02-13 (9 years) (11 of 15) - Terms of service: read, states 5 of the 7 things a reader expects, and has 1 clause that costs points (6.3 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10) - security.txt: not found (0 of 10) ## 6. Schema & documentation, 82 out of 100, up to 2.9 more on the total Why it scored 82: OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 7. Maintenance & community, 82 out of 100, up to 1.6 more on the total Why it scored 82: Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - The lead named an `esc` CLI. The standalone esc CLI was retired at v0.26.0 on 9 July 2026 and ESC now ships only as `pulumi env` in the Pulumi CLI. - No API rate limit with numbers was found in the docs we read or in the OpenAPI document. - The pricing page lists an uptime commitment from Essentials up. We found no document giving the figure. - No data processing addendum, subprocessor list or dated terms were found on www.pulumi.com. - unchecked: GitHub star counts and the issue trackers of pulumi/pulumi and pulumi/esc-sdk, because the GitHub API refused us for its rate limit. - unchecked: whether the Pulumi CLI sends telemetry and how to turn it off. - unchecked: the self-hosted edition, which is Enterprise only and sold through sales. The grade is for the managed service. ## Weaknesses - Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise - No API rate limit with numbers was found in the reviewed documentation - No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date - The official Pulumi MCP server lists no ESC tools, and the standalone esc CLI was retired at v0.26.0 on 9 July 2026 - A 42-minute major incident on 6 October 2026 affected inbound OIDC on the API and ESC, with no detail published - The free edition has personal tokens only, which carry all of the user's permissions ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Use `pulumi env`, not `esc`. The standalone CLI stopped at v0.26.0 and gets no security fixes - Read one value with `pulumi env open <org>/<project>/<env> <property path>` so the whole environment doesn't enter context - Run tools with `pulumi env run <env> -- <cmd>`, which filters secret values from the command's output unless -i is set - Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk - Send `Authorization: token <token>` and `Accept: application/vnd.pulumi+8` on REST calls, and expect 409 when an environment changed since it was read - Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- The lead named an
escCLI. The standalone esc CLI was retired at v0.26.0 on 9 July 2026 and ESC now ships only aspulumi envin the Pulumi CLI. - No API rate limit with numbers was found in the docs we read or in the OpenAPI document.
- The pricing page lists an uptime commitment from Essentials up. We found no document giving the figure.
- No data processing addendum, subprocessor list or dated terms were found on www.pulumi.com.
- unchecked: GitHub star counts and the issue trackers of pulumi/pulumi and pulumi/esc-sdk, because the GitHub API refused us for its rate limit.
- unchecked: whether the Pulumi CLI sends telemetry and how to turn it off.
- unchecked: the self-hosted edition, which is Enterprise only and sold through sales. The grade is for the managed service.
Sources 28
- ESC documentation pulumi.com · seen 2026-10-08
- pricing, free edition and per-unit prices pulumi.com · seen 2026-10-08
- OpenAPI document api.pulumi.com · seen 2026-10-08
- llms.txt pulumi.com · seen 2026-10-08
- REST API basics, authentication and headers pulumi.com · seen 2026-10-08
- pulumi api guide, pagination and error envelope pulumi.com · seen 2026-10-08
- CLI exit codes pulumi.com · seen 2026-10-08
- agent accounts pulumi.com · seen 2026-10-08
- access tokens pulumi.com · seen 2026-10-08
- OIDC issuers pulumi.com · seen 2026-10-08
- environment RBAC scopes pulumi.com · seen 2026-10-08
- audit log events pulumi.com · seen 2026-10-08
- ESC audit logs pulumi.com · seen 2026-10-08
- approvals pulumi.com · seen 2026-10-08
- rotators pulumi.com · seen 2026-10-08
- migration from the standalone esc CLI pulumi.com · seen 2026-10-08
- MCP server tools pulumi.com · seen 2026-10-08
- status incidents status.pulumi.com · seen 2026-10-08
- security page pulumi.com · seen 2026-10-08
- security whitepaper pulumi.com · seen 2026-10-08
- terms pulumi.com · seen 2026-10-08
- privacy statement pulumi.com · seen 2026-10-08
- changelog pulumi.com · seen 2026-10-08
- Pulumi CLI releases github.com · seen 2026-10-08
- standalone esc repository, README and changelog github.com · seen 2026-10-08
- SDK repository, changelog and CI github.com · seen 2026-10-08
- TypeScript SDK on npm registry.npmjs.org · seen 2026-10-08
- Python SDK on PyPI pypi.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $0.01 / 1k req Free edition with 25 secrets and 10,000 API calls a month for one user, no card. Essentials is $40 a month, Pro $400 and Enterprise $2,000, each including that many credits, with a managed secret at $0.50, $0.75 or $1.00 a month and API calls at $0.10 per 10,000. An agent can start with no contract through the free edition or an agent account (https://www.pulumi.com/pricing/, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| ESC API calls | $0.01 | per 1,000 requests | $0.10 per 10,000. First 10,000 a month free on the free edition |
| Essentials edition | $40 | per month (plan) | Includes 40 credits. A managed secret is $0.50 a month |
| Pro edition | $400 | per month (plan) | Includes 400 credits. A managed secret is $0.75 a month |
| Enterprise edition | $2000 | per month (plan) | Includes 2,000 credits. A managed secret is $1.00 a month |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/pulumi-esc.xml, or this listing's score history at history.json.
Connect
Install
curl -fsSL https://get.pulumi.com | sh
First request
curl -H "Authorization: token $PULUMI_ACCESS_TOKEN" \
-H "Accept: application/vnd.pulumi+8" \
https://api.pulumi.com/api/user
Through letme picks today, calling later
GET https://letme.dev/pulumi-esc
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Infisical AAWS Secrets Manager BBGoogle Cloud Secret Manager BBAzure Key Vault BBAkeyless (SecretlessAI and MCP server) BBDoppler BB
Head to head 1Password service accounts, SDKs and Environments MCP vs Pulumi ESC · Akeyless (SecretlessAI and MCP server) vs Pulumi ESC · AWS Secrets Manager vs Pulumi ESC · Azure Key Vault vs Pulumi ESC · Bitwarden Secrets Manager vs Pulumi ESC · Doppler vs Pulumi ESC · Google Cloud Secret Manager vs Pulumi ESC · HashiCorp Vault + Vault MCP Server vs Pulumi ESC · Infisical vs Pulumi ESC
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Infisical Infisical | A | 83.7 | secrets.store secrets.rotate secrets.machine-identity secrets.audit | no |
| AWS Secrets Manager Amazon Web Services | BB | 77.7 | secrets.store secrets.rotate secrets.machine-identity secrets.audit | no |
| Google Cloud Secret Manager Google Cloud | BB | 76.5 | secrets.store secrets.rotate secrets.machine-identity secrets.audit | no |
| Azure Key Vault Microsoft Corporation | BB | 74.7 | secrets.store secrets.machine-identity secrets.audit secrets.rotate | no |
| Akeyless (SecretlessAI and MCP server) Akeyless | BB | 73.6 | secrets.store secrets.rotate secrets.machine-identity secrets.audit | no |
| Doppler Doppler | BB | 71.4 | secrets.store secrets.rotate secrets.machine-identity secrets.audit | no |
Machine-readable
- JSON
/api/v1/tools/pulumi-esc.json· historyhistory.json· badge/badges/pulumi-esc.svg· changes feed/feeds/tools/pulumi-esc.xml - Markdown
/tools/pulumi-esc.md· slim/tools/pulumi-esc.min.md(or sendAccept: text/markdown) - Fix list
/fixes/pulumi-esc.md·/fixes/pulumi-esc.json - From a terminal
anchor tool pulumi-esc --md(the CLI) · over MCPget_tool {"slug": "pulumi-esc"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/pulumi-esc"><img src="https://www.anchorterminal.com/badges/pulumi-esc.svg" alt="Pulumi ESC on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/pulumi-esc)<a href="https://www.anchorterminal.com/tools/pulumi-esc">Pulumi ESC on Anchor Terminal</a>It counts on a page on pulumi.com or one of its subdomains, or the README of github.com/pulumi/esc-sdk.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "pulumi-esc", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


