{
  "data": {
    "similar": [
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/infisical.json",
        "name": "Infisical",
        "score": 83.7,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "infisical"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/aws-secrets-manager.json",
        "name": "AWS Secrets Manager",
        "score": 77.7,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "aws-secrets-manager"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/google-secret-manager.json",
        "name": "Google Cloud Secret Manager",
        "score": 76.5,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "google-secret-manager"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/azure-key-vault.json",
        "name": "Azure Key Vault",
        "score": 74.7,
        "shared": [
          "secrets.store",
          "secrets.machine-identity",
          "secrets.audit",
          "secrets.rotate"
        ],
        "slug": "azure-key-vault"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/akeyless.json",
        "name": "Akeyless (SecretlessAI and MCP server)",
        "score": 73.6,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "akeyless"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/doppler.json",
        "name": "Doppler",
        "score": 71.4,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "doppler"
      }
    ],
    "tool": {
      "slug": "pulumi-esc",
      "name": "Pulumi ESC",
      "vendor": "Pulumi Corporation",
      "vendorUrl": "https://www.pulumi.com",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Pulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs.",
      "url": "https://www.anchorterminal.com/tools/pulumi-esc",
      "markdownUrl": "https://www.anchorterminal.com/tools/pulumi-esc.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pulumi-esc.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pulumi-esc.json",
      "repo": "https://github.com/pulumi/esc-sdk",
      "license": "Proprietary service under Pulumi's Terms \u0026 Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.pulumi.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@pulumi/esc-sdk"
        },
        {
          "registry": "pypi",
          "name": "pulumi-esc-sdk"
        },
        {
          "registry": "go",
          "name": "github.com/pulumi/esc-sdk/sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Every request sends `Authorization: token \u003ctoken\u003e` to https://api.pulumi.com. A personal token comes from the console and carries all of the user's permissions. Organisation tokens (Essentials and above) and team tokens (Pro and above) are machine tokens that take a role, and custom roles with environment scopes need Pro. A workload on a registered OIDC issuer (GitHub Actions, GitLab CI, EKS, GKE and others) exchanges its ID token for a short-lived Pulumi token with `pulumi login --oidc-token` or POST /api/oauth/token. Under an agent with no credentials the CLI creates an ephemeral account by itself.",
      "pricing": "freemium",
      "pricingNotes": "Free edition with 25 secrets and 10,000 API calls a month for one user, no card. Essentials is $40 a month, Pro $400 and Enterprise $2,000, each including that many credits, with a managed secret at $0.50, $0.75 or $1.00 a month and API calls at $0.10 per 10,000. An agent can start with no contract through the free edition or an agent account (https://www.pulumi.com/pricing/, checked 2026-10-08).",
      "priceSummary": "$0.01 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the ESC docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 20661,
        "pypiWeekly": 53903,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.pulumi.com/docs/esc/",
      "llmsTxt": "https://www.pulumi.com/llms.txt",
      "openapi": "https://api.pulumi.com/api/openapi/pulumi-spec.json",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "freemium",
        "free-tier",
        "no-card",
        "openapi",
        "llms-txt",
        "oidc",
        "cli",
        "typescript",
        "python",
        "go",
        "dotnet",
        "status-page",
        "soc2",
        "enterprise"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.1,
        "grade": "BB",
        "agentReady": true,
        "rank": 120,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 82,
          "payments": 55,
          "reliability": 60,
          "schema": 82,
          "security": 79,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 60,
            "points": 12,
            "reason": "Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 82,
            "points": 13.33,
            "reason": "OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 75,
            "points": 12.19,
            "reason": "`pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and `pulumi api --paginate` follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and `pulumi api` writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and `--dry-run` validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 79,
            "points": 13.83,
            "reason": "OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in `pulumi env run`. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 55,
            "points": 6.88,
            "reason": "No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 82,
            "points": 7.18,
            "reason": "Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 65,
            "points": 5.69,
            "note": "editorial 48, provenance 82",
            "reason": "The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "`pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and `pulumi api --paginate` follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and `pulumi api` writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and `--dry-run` validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15).",
            "maintenance": "Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10).",
            "payments": "No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20).",
            "reliability": "Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10).",
            "schema": "OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15).",
            "security": "OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in `pulumi env run`. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20).",
            "transparency": "The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20)."
          },
          "sources": [
            {
              "what": "ESC documentation",
              "url": "https://www.pulumi.com/docs/esc/",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing, free edition and per-unit prices",
              "url": "https://www.pulumi.com/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI document",
              "url": "https://api.pulumi.com/api/openapi/pulumi-spec.json",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://www.pulumi.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "REST API basics, authentication and headers",
              "url": "https://www.pulumi.com/docs/reference/cloud-rest-api/api-basics/",
              "seen": "2026-10-08"
            },
            {
              "what": "pulumi api guide, pagination and error envelope",
              "url": "https://www.pulumi.com/docs/iac/cli/api/",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI exit codes",
              "url": "https://www.pulumi.com/docs/iac/cli/exit-codes/",
              "seen": "2026-10-08"
            },
            {
              "what": "agent accounts",
              "url": "https://www.pulumi.com/docs/administration/concepts/agent-accounts/",
              "seen": "2026-10-08"
            },
            {
              "what": "access tokens",
              "url": "https://www.pulumi.com/docs/administration/concepts/access-tokens/",
              "seen": "2026-10-08"
            },
            {
              "what": "OIDC issuers",
              "url": "https://www.pulumi.com/docs/administration/concepts/oidc-issuers/",
              "seen": "2026-10-08"
            },
            {
              "what": "environment RBAC scopes",
              "url": "https://www.pulumi.com/docs/administration/reference/rbac-scopes/environments/",
              "seen": "2026-10-08"
            },
            {
              "what": "audit log events",
              "url": "https://www.pulumi.com/docs/administration/reference/audit-log-events/",
              "seen": "2026-10-08"
            },
            {
              "what": "ESC audit logs",
              "url": "https://www.pulumi.com/docs/esc/administration/audit-logs/",
              "seen": "2026-10-08"
            },
            {
              "what": "approvals",
              "url": "https://www.pulumi.com/docs/esc/concepts/approvals/",
              "seen": "2026-10-08"
            },
            {
              "what": "rotators",
              "url": "https://www.pulumi.com/docs/esc/concepts/rotators/",
              "seen": "2026-10-08"
            },
            {
              "what": "migration from the standalone esc CLI",
              "url": "https://www.pulumi.com/docs/esc/guides/migrate-from-esc-cli/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server tools",
              "url": "https://www.pulumi.com/docs/ai/mcp-server/",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents",
              "url": "https://status.pulumi.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.pulumi.com/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "security whitepaper",
              "url": "https://www.pulumi.com/security/pulumi-cloud-security-whitepaper/",
              "seen": "2026-10-08"
            },
            {
              "what": "terms",
              "url": "https://www.pulumi.com/terms-and-conditions/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy statement",
              "url": "https://www.pulumi.com/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://www.pulumi.com/releases/changelog/",
              "seen": "2026-10-08"
            },
            {
              "what": "Pulumi CLI releases",
              "url": "https://github.com/pulumi/pulumi/releases",
              "seen": "2026-10-08"
            },
            {
              "what": "standalone esc repository, README and changelog",
              "url": "https://github.com/pulumi/esc",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK repository, changelog and CI",
              "url": "https://github.com/pulumi/esc-sdk",
              "seen": "2026-10-08"
            },
            {
              "what": "TypeScript SDK on npm",
              "url": "https://registry.npmjs.org/@pulumi/esc-sdk/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "Python SDK on PyPI",
              "url": "https://pypi.org/pypi/pulumi-esc-sdk/json",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "The lead named an `esc` CLI. The standalone esc CLI was retired at v0.26.0 on 9 July 2026 and ESC now ships only as `pulumi env` in the Pulumi CLI.",
            "No API rate limit with numbers was found in the docs we read or in the OpenAPI document.",
            "The pricing page lists an uptime commitment from Essentials up. We found no document giving the figure.",
            "No data processing addendum, subprocessor list or dated terms were found on www.pulumi.com.",
            "unchecked: GitHub star counts and the issue trackers of pulumi/pulumi and pulumi/esc-sdk, because the GitHub API refused us for its rate limit.",
            "unchecked: whether the Pulumi CLI sends telemetry and how to turn it off.",
            "unchecked: the self-hosted edition, which is Enterprise only and sold through sales. The grade is for the managed service."
          ]
        },
        "negative": 0,
        "verdict": "An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.",
        "bestFor": "Teams already on Pulumi, or anyone who wants one place that composes static secrets, other vaults and short-lived cloud credentials, and agents that need to start with no signup.",
        "strengths": [
          "The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it",
          "Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page",
          "OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default",
          "Separate read, open and write scopes per environment, with open approvals and update approvals on Pro and Enterprise",
          "Prices published per unit, $0.50 a secret a month on Essentials and $0.10 per 10,000 API calls, with a free edition and no card"
        ],
        "weaknesses": [
          "Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise",
          "No API rate limit with numbers was found in the reviewed documentation",
          "No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date",
          "The official Pulumi MCP server lists no ESC tools, and the standalone esc CLI was retired at v0.26.0 on 9 July 2026",
          "A 42-minute major incident on 6 October 2026 affected inbound OIDC on the API and ESC, with no detail published",
          "The free edition has personal tokens only, which carry all of the user's permissions"
        ],
        "agentNotes": [
          "Use `pulumi env`, not `esc`. The standalone CLI stopped at v0.26.0 and gets no security fixes",
          "Read one value with `pulumi env open \u003corg\u003e/\u003cproject\u003e/\u003cenv\u003e \u003cproperty path\u003e` so the whole environment doesn't enter context",
          "Run tools with `pulumi env run \u003cenv\u003e -- \u003ccmd\u003e`, which filters secret values from the command's output unless -i is set",
          "Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk",
          "Send `Authorization: token \u003ctoken\u003e` and `Accept: application/vnd.pulumi+8` on REST calls, and expect 409 when an environment changed since it was read",
          "Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.1
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 82,
          "payments": 55,
          "reliability": 60,
          "schema": 82,
          "security": 79,
          "transparency": 48
        },
        "provenanceScore": 82
      },
      "connect": {
        "install": "curl -fsSL https://get.pulumi.com | sh",
        "http": "curl -H \"Authorization: token $PULUMI_ACCESS_TOKEN\" \\\n     -H \"Accept: application/vnd.pulumi+8\" \\\n     https://api.pulumi.com/api/user"
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/pulumi-esc"
      },
      "notable": [
        "Agent accounts give an AI agent a free ephemeral Pulumi Cloud account with ESC and no signup. Write access lasts 72 hours and a person has 30 days to claim it (https://www.pulumi.com/docs/administration/concepts/agent-accounts/)",
        "The standalone esc CLI was retired with v0.26.0 on 9 July 2026. Every command is now `pulumi env` in the Pulumi CLI (https://www.pulumi.com/docs/esc/guides/migrate-from-esc-cli/)",
        "`pulumi api` calls any REST endpoint with the CLI's credentials, lists the OpenAPI operations as JSON and writes errors as a one-line JSON envelope (https://www.pulumi.com/docs/iac/cli/api/)",
        "Rotated secrets keep two valid credentials at a time, so instances that haven't picked up the new one keep working (https://www.pulumi.com/docs/esc/concepts/rotators/)",
        "Audit logs record every environment open, read and decrypt with user, time and source IP, on Pro and Enterprise (https://www.pulumi.com/docs/esc/administration/audit-logs/)",
        "A major incident on 6 October 2026 affected inbound OIDC on the API and ESC for 42 minutes (https://status.pulumi.com)"
      ],
      "area": "agent-runtime",
      "details": [
        {
          "label": "Surface graded",
          "value": "Managed Pulumi Cloud at https://api.pulumi.com, reached through `pulumi env`, the REST API and the ESC SDKs"
        },
        {
          "label": "Free edition",
          "value": "1 user, 25 secrets, 10,000 API calls a month, no card. Personal tokens only"
        },
        {
          "label": "Paid editions",
          "value": "Essentials $40 a month, Pro $400, Enterprise $2,000, each including the same number of credits at $1 a credit"
        },
        {
          "label": "Unit prices",
          "value": "Managed secret $0.50 a month on Essentials, $0.75 on Pro, $1.00 on Enterprise. API calls $0.10 per 10,000. Plaintext config free"
        },
        {
          "label": "Agent accounts",
          "value": "The CLI creates an ephemeral individual account when run under an agent with no credentials. Write access for 72 hours, claim within 30 days"
        },
        {
          "label": "Credentials",
          "value": "Personal, organisation (Essentials up) and team (Pro up) tokens with expiry up to two years, and OIDC token exchange with a 25-hour default maximum"
        },
        {
          "label": "Dynamic credentials",
          "value": "Login providers for AWS, Azure, Google Cloud, GitHub, Snowflake, Vault, Doppler and Infisical"
        },
        {
          "label": "External stores",
          "value": "AWS Secrets Manager and Parameter Store, Azure Key Vault, Google Secret Manager, HashiCorp Vault, 1Password, Doppler and Infisical"
        },
        {
          "label": "Rotation",
          "value": "Rotators for AWS IAM, Azure app secrets, MySQL, Postgres, Snowflake users and passwords, run by `pulumi env rotate` or on a schedule, keeping two valid secrets"
        },
        {
          "label": "Audit",
          "value": "environment-open, environment-read-open and environment-decrypted events with user, time and source IP. Pro and Enterprise"
        },
        {
          "label": "Approvals",
          "value": "Update approvals and open approvals by ruleset. Pro and Enterprise"
        },
        {
          "label": "SDKs",
          "value": "TypeScript @pulumi/esc-sdk, Python pulumi-esc-sdk, Go github.com/pulumi/esc-sdk/sdk and .NET Pulumi.Esc.Sdk, all 0.14.0 (15 June 2026), Apache-2.0"
        },
        {
          "label": "MCP server",
          "value": "The Pulumi MCP server at https://mcp.ai.pulumi.com/mcp lists no ESC tools in its docs"
        },
        {
          "label": "Self-hosting",
          "value": "Enterprise edition only, through sales"
        },
        {
          "label": "Status",
          "value": "status.pulumi.com on Atlassian Statuspage, with an ESC component"
        }
      ],
      "unitPrices": [
        {
          "item": "ESC API calls",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "$0.10 per 10,000. First 10,000 a month free on the free edition"
        },
        {
          "item": "Essentials edition",
          "unit": "month",
          "usd": 40,
          "note": "Includes 40 credits. A managed secret is $0.50 a month"
        },
        {
          "item": "Pro edition",
          "unit": "month",
          "usd": 400,
          "note": "Includes 400 credits. A managed secret is $0.75 a month"
        },
        {
          "item": "Enterprise edition",
          "unit": "month",
          "usd": 2000,
          "note": "Includes 2,000 credits. A managed secret is $1.00 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Pulumi Corporation",
        "domain": "pulumi.com",
        "domainRegistered": "2017-02-13",
        "endpointOnVendorDomain": true,
        "terms": "https://www.pulumi.com/terms-and-conditions/",
        "privacy": "https://www.pulumi.com/privacy/",
        "statusPage": "https://status.pulumi.com",
        "changelog": "https://www.pulumi.com/releases/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms \u0026 Conditions govern use of the Pulumi Services and name Pulumi Corporation, 601 Union St., Suite 1415, Seattle, WA 98101, with Washington law and King County courts. We found no date on the page.",
          "The privacy statement covers customers who register to use the services and gives privacy@pulumi.com as contact. We found no date on the page.",
          "www.pulumi.com/.well-known/security.txt and www.pulumi.com/security.txt both return 404. The security page gives security@pulumi.com and a PGP key.",
          "status.pulumi.com is Atlassian Statuspage with an ESC component. Its incident feed goes back to October 2023.",
          "No data processing addendum or subprocessor list was found on www.pulumi.com. The addresses we tried returned 404 and the sitemap lists neither.",
          "RDAP for pulumi.com gives a registration date of 2017-02-13."
        ],
        "score": 82,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Pulumi Corporation",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "pulumi.com, registered 2017-02-13 (9 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.pulumi.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 6.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.pulumi.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.pulumi.com/terms-and-conditions/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 4245,
            "points": 6.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "15.6 The Terms, and your relationship with Pulumi under the Terms, shall be governed by the laws of the State of Washington without regard to its conflict of laws provisions.",
                "says": "The law of the State of Washington"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…YOU EXPRESSLY UNDERSTAND AND AGREE THAT PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE.",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "4.3 If any charge owed by you is 30 days or more overdue, Pulumi may, without limiting its other rights and remedies, suspend your access to Pulumi Services until such amounts are paid in full, provided we have given you 10 or more days' prior notice that your account is overdue."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If we change the Terms in any substantive way, we will give you at least seven (7) days’ notice before the changes take effect, during which period of time you may reject the changes by terminating your account.",
                "says": "Gives seven days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "1.3 You may not use the Pulumi Services if you are a person barred from receiving the Pulumi Services under the laws of the United States or other countries, including the country in which you are resident or from which you use the Pulumi Services."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "You acknowledge and agree that the form and nature of the Pulumi Services which Pulumi provides may change from time to time without prior notice to you, subject to the terms in Section 4.3.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "9.4 You agree that Pulumi, in its sole discretion and for any or no reason, may terminate your account or any part thereof."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Pulumi may use the customer's trade names, trademarks and logos in marketing materials and customer lists at its sole discretion.",
                "quote": "8.4 You agree that Pulumi, in its sole discretion, may use your trade names, trademarks, service marks, logos, domain names and other distinctive brand features in presentations, marketing materials, customer lists, financial reports and Web site listings"
              },
              {
                "date": "2026-10-08",
                "text": "The agreement renews automatically for periods equal to the initial term unless either party asks to end it at least 30 days before the term ends.",
                "quote": "shall be automatically renewed for additional periods of the same duration as the Initial Service Term (collectively, the “Term”), unless either party requests termination at least thirty (30) days prior to the end of the then-current term."
              },
              {
                "date": "2026-10-08",
                "text": "The liability clause says Pulumi is not liable to the customer for direct damages as well as indirect, incidental, special, consequential or exemplary ones.",
                "quote": "PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.pulumi.com/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 5514,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "Please read this Privacy Statement carefully to learn how we collect, use, share and otherwise process information relating to individuals (\"Personal Data\"), and your rights and choices regarding our processing of your Personal Data."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We may retain your Personal Data for a period of time consistent with the original purpose of collection (see \"Purposes for which we process Personal Data and on what legal basis\" section above)."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may also collect information about you from other sources, including third parties from whom we have purchased Personal Data, and combine this information with Personal Data provided by you."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "…through which our customers may create their own websites and applications running on our platforms, sell or offer their own products and services, send electronic communications to other individuals, and collect and analyze Personal Data from individuals."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "…is necessary for our legitimate interests to advertise our websites or, where necessary, to the extent you have provided your prior separate consent (please also view \"Your rights relating to your Personal Data\" below to learn how you can control how your Personal Data is processed by Pulumi for marketing purposes);"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have questions or complaints regarding Pulumi's Privacy Statement or associated practices, please contact us at privacy@pulumi.com.",
                "says": "privacy@pulumi.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "In this event, we will ensure that such recipient offers an adequate level of protection, for instance by entering into standard contractual clauses for the transfer of data as approved by the European Commission (Art.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "With third–party social networks, advertising networks and websites, which usually act as separate controllers, so that Pulumi can market and advertise on third party platforms and websites;"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The statement says it does not apply to the cloud products and services through which customers create and run their own websites and applications.",
                "quote": "This Privacy Statement does not apply to the extent we offer our customers various cloud products and services through which our customers may create their own websites and applications running on our platforms"
              },
              {
                "date": "2026-10-08",
                "text": "Pulumi collects business contact details and web behaviour data from third party data providers for targeted advertising and profiling.",
                "quote": "‘intent data’ which is web user behavior data, IP addresses, social handles, LinkedIn URL and custom profiles from third party data providers for the purposes of targeted advertising, delivering relevant email content, event promotion and profiling;"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/pulumi-esc.json",
      "live": {
        "slug": "pulumi-esc",
        "probe": {
          "target": "https://api.pulumi.com",
          "method": "get",
          "lastAt": "2026-10-08T20:09:56.39392546Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 218,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 158,
          "p95ms24h": 272,
          "samples24h": 30,
          "samples30d": 30,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 30,
              "ok": 30
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.pulumi.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T20:01:18.989791514Z"
        },
        "pages": [
          {
            "url": "https://www.pulumi.com/releases/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:52.955269848Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ddd6467eba9b"
          },
          {
            "url": "https://www.pulumi.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:48.804855492Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ba84dc7bc768"
          },
          {
            "url": "https://www.pulumi.com/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:51.056197289Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "96eac852b529"
          },
          {
            "url": "https://www.pulumi.com/terms-and-conditions/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:55.102680068Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "660bfdce2184"
          }
        ],
        "updatedAt": "2026-10-08T20:09:56.39392546Z"
      }
    },
    "verify": {
      "accepts": "a page on pulumi.com or one of its subdomains, or the README of github.com/pulumi/esc-sdk",
      "badgeUrl": "https://www.anchorterminal.com/badges/pulumi-esc.svg",
      "body": {
        "slug": "pulumi-esc",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/pulumi-esc",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/pulumi-esc\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/pulumi-esc.svg\" alt=\"Pulumi ESC on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Pulumi ESC on Anchor Terminal](https://www.anchorterminal.com/badges/pulumi-esc.svg)](https://www.anchorterminal.com/tools/pulumi-esc)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/pulumi-esc\"\u003ePulumi ESC on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/pulumi-esc",
    "json": "https://www.anchorterminal.com/tools/pulumi-esc.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/pulumi-esc.md",
    "slim": "https://www.anchorterminal.com/tools/pulumi-esc.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 71.1/100 · rank #120 of 722 · #7 in Secrets \u0026 credential vaults · agent-ready · confidence medium**\n\n\n## Assessment\n\nAn agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Pulumi Corporation (https://www.pulumi.com) |\n| Kind | HTTP API |\n| Category | Secrets \u0026 credential vaults (https://www.anchorterminal.com/categories/secrets) |\n| Transport | HTTP |\n| Endpoint | `https://api.pulumi.com` |\n| Auth | OAuth or key · Self-serve. Every request sends `Authorization: token \u003ctoken\u003e` to https://api.pulumi.com. A personal token comes from the console and carries all of the user's permissions. Organisation tokens (Essentials and above) and team tokens (Pro and above) are machine tokens that take a role, and custom roles with environment scopes need Pro. A workload on a registered OIDC issuer (GitHub Actions, GitLab CI, EKS, GKE and others) exchanges its ID token for a short-lived Pulumi token with `pulumi login --oidc-token` or POST /api/oauth/token. Under an agent with no credentials the CLI creates an ephemeral account by itself. |\n| Pricing | Freemium ($0.01 / 1k req) · Free edition with 25 secrets and 10,000 API calls a month for one user, no card. Essentials is $40 a month, Pro $400 and Enterprise $2,000, each including that many credits, with a managed secret at $0.50, $0.75 or $1.00 a month and API calls at $0.10 per 10,000. An agent can start with no contract through the free edition or an agent account (https://www.pulumi.com/pricing/, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the ESC docs, the OpenAPI document or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Pulumi's Terms \u0026 Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0 |\n| Packages | npm: `@pulumi/esc-sdk`; pypi: `pulumi-esc-sdk`; go: `github.com/pulumi/esc-sdk/sdk` |\n| Source | https://github.com/pulumi/esc-sdk |\n| Docs | https://www.pulumi.com/docs/esc/ |\n| llms.txt | https://www.pulumi.com/llms.txt |\n| Last release | 2026-10-07 |\n| npm downloads / week | 20,661 |\n| PyPI downloads / week | 53,903 |\n| Surface graded | Managed Pulumi Cloud at https://api.pulumi.com, reached through `pulumi env`, the REST API and the ESC SDKs |\n| Free edition | 1 user, 25 secrets, 10,000 API calls a month, no card. Personal tokens only |\n| Paid editions | Essentials $40 a month, Pro $400, Enterprise $2,000, each including the same number of credits at $1 a credit |\n| Unit prices | Managed secret $0.50 a month on Essentials, $0.75 on Pro, $1.00 on Enterprise. API calls $0.10 per 10,000. Plaintext config free |\n| Agent accounts | The CLI creates an ephemeral individual account when run under an agent with no credentials. Write access for 72 hours, claim within 30 days |\n| Credentials | Personal, organisation (Essentials up) and team (Pro up) tokens with expiry up to two years, and OIDC token exchange with a 25-hour default maximum |\n| Dynamic credentials | Login providers for AWS, Azure, Google Cloud, GitHub, Snowflake, Vault, Doppler and Infisical |\n| External stores | AWS Secrets Manager and Parameter Store, Azure Key Vault, Google Secret Manager, HashiCorp Vault, 1Password, Doppler and Infisical |\n| Rotation | Rotators for AWS IAM, Azure app secrets, MySQL, Postgres, Snowflake users and passwords, run by `pulumi env rotate` or on a schedule, keeping two valid secrets |\n| Audit | environment-open, environment-read-open and environment-decrypted events with user, time and source IP. Pro and Enterprise |\n| Approvals | Update approvals and open approvals by ruleset. Pro and Enterprise |\n| SDKs | TypeScript @pulumi/esc-sdk, Python pulumi-esc-sdk, Go github.com/pulumi/esc-sdk/sdk and .NET Pulumi.Esc.Sdk, all 0.14.0 (15 June 2026), Apache-2.0 |\n| MCP server | The Pulumi MCP server at https://mcp.ai.pulumi.com/mcp lists no ESC tools in its docs |\n| Self-hosting | Enterprise edition only, through sales |\n| Status | status.pulumi.com on Atlassian Statuspage, with an ESC component |\n| Capabilities | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit |\n| Tags | hosted, closed-source, freemium, free-tier, no-card, openapi, llms-txt, oidc, cli, typescript, python, go, dotnet, status-page, soc2, enterprise |\n| JSON | https://www.anchorterminal.com/api/v1/tools/pulumi-esc.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 60 | 12.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 82 | 13.3 |\n| Agent ergonomics | 13% | 16.2 | 75 | 12.2 |\n| Security \u0026 auth | 14% | 17.5 | 79 | 13.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 55 | 6.9 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 82 | 7.2 |\n| Transparency \u0026 trust (editorial 48, provenance 82) | 7% | 8.8 | 65 | 5.7 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **71.1 → BB** |\n\n### Why each score\n\n- Reliability 60: Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 82: OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15).\n- Agent ergonomics 75: `pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and `pulumi api --paginate` follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and `pulumi api` writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and `--dry-run` validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15).\n- Security \u0026 auth 79: OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in `pulumi env run`. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20).\n- Payments \u0026 pricing 55: No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 82: Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10).\n- Transparency \u0026 trust 65: The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/pulumi-esc.md (JSON https://www.anchorterminal.com/fixes/pulumi-esc.json)\n\n### What we couldn't check\n\n- The lead named an `esc` CLI. The standalone esc CLI was retired at v0.26.0 on 9 July 2026 and ESC now ships only as `pulumi env` in the Pulumi CLI.\n- No API rate limit with numbers was found in the docs we read or in the OpenAPI document.\n- The pricing page lists an uptime commitment from Essentials up. We found no document giving the figure.\n- No data processing addendum, subprocessor list or dated terms were found on www.pulumi.com.\n- unchecked: GitHub star counts and the issue trackers of pulumi/pulumi and pulumi/esc-sdk, because the GitHub API refused us for its rate limit.\n- unchecked: whether the Pulumi CLI sends telemetry and how to turn it off.\n- unchecked: the self-hosted edition, which is Enterprise only and sold through sales. The grade is for the managed service.\n\n### Sources\n\n- ESC documentation: \u003chttps://www.pulumi.com/docs/esc/\u003e (seen 2026-10-08)\n- pricing, free edition and per-unit prices: \u003chttps://www.pulumi.com/pricing/\u003e (seen 2026-10-08)\n- OpenAPI document: \u003chttps://api.pulumi.com/api/openapi/pulumi-spec.json\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://www.pulumi.com/llms.txt\u003e (seen 2026-10-08)\n- REST API basics, authentication and headers: \u003chttps://www.pulumi.com/docs/reference/cloud-rest-api/api-basics/\u003e (seen 2026-10-08)\n- pulumi api guide, pagination and error envelope: \u003chttps://www.pulumi.com/docs/iac/cli/api/\u003e (seen 2026-10-08)\n- CLI exit codes: \u003chttps://www.pulumi.com/docs/iac/cli/exit-codes/\u003e (seen 2026-10-08)\n- agent accounts: \u003chttps://www.pulumi.com/docs/administration/concepts/agent-accounts/\u003e (seen 2026-10-08)\n- access tokens: \u003chttps://www.pulumi.com/docs/administration/concepts/access-tokens/\u003e (seen 2026-10-08)\n- OIDC issuers: \u003chttps://www.pulumi.com/docs/administration/concepts/oidc-issuers/\u003e (seen 2026-10-08)\n- environment RBAC scopes: \u003chttps://www.pulumi.com/docs/administration/reference/rbac-scopes/environments/\u003e (seen 2026-10-08)\n- audit log events: \u003chttps://www.pulumi.com/docs/administration/reference/audit-log-events/\u003e (seen 2026-10-08)\n- ESC audit logs: \u003chttps://www.pulumi.com/docs/esc/administration/audit-logs/\u003e (seen 2026-10-08)\n- approvals: \u003chttps://www.pulumi.com/docs/esc/concepts/approvals/\u003e (seen 2026-10-08)\n- rotators: \u003chttps://www.pulumi.com/docs/esc/concepts/rotators/\u003e (seen 2026-10-08)\n- migration from the standalone esc CLI: \u003chttps://www.pulumi.com/docs/esc/guides/migrate-from-esc-cli/\u003e (seen 2026-10-08)\n- MCP server tools: \u003chttps://www.pulumi.com/docs/ai/mcp-server/\u003e (seen 2026-10-08)\n- status incidents: \u003chttps://status.pulumi.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.pulumi.com/security/\u003e (seen 2026-10-08)\n- security whitepaper: \u003chttps://www.pulumi.com/security/pulumi-cloud-security-whitepaper/\u003e (seen 2026-10-08)\n- terms: \u003chttps://www.pulumi.com/terms-and-conditions/\u003e (seen 2026-10-08)\n- privacy statement: \u003chttps://www.pulumi.com/privacy/\u003e (seen 2026-10-08)\n- changelog: \u003chttps://www.pulumi.com/releases/changelog/\u003e (seen 2026-10-08)\n- Pulumi CLI releases: \u003chttps://github.com/pulumi/pulumi/releases\u003e (seen 2026-10-08)\n- standalone esc repository, README and changelog: \u003chttps://github.com/pulumi/esc\u003e (seen 2026-10-08)\n- SDK repository, changelog and CI: \u003chttps://github.com/pulumi/esc-sdk\u003e (seen 2026-10-08)\n- TypeScript SDK on npm: \u003chttps://registry.npmjs.org/@pulumi/esc-sdk/latest\u003e (seen 2026-10-08)\n- Python SDK on PyPI: \u003chttps://pypi.org/pypi/pulumi-esc-sdk/json\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 82/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Pulumi Corporation | 20/20 |\n| Domain age | pulumi.com, registered 2017-02-13 (9 years) | 11/15 |\n| Endpoint on the vendor's domain | api.pulumi.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 1 clause that costs points | 6.3/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | status.pulumi.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Terms \u0026 Conditions govern use of the Pulumi Services and name Pulumi Corporation, 601 Union St., Suite 1415, Seattle, WA 98101, with Washington law and King County courts. We found no date on the page.\n\nThe privacy statement covers customers who register to use the services and gives privacy@pulumi.com as contact. We found no date on the page.\n\nwww.pulumi.com/.well-known/security.txt and www.pulumi.com/security.txt both return 404. The security page gives security@pulumi.com and a PGP key.\n\nstatus.pulumi.com is Atlassian Statuspage with an ESC component. Its incident feed goes back to October 2023.\n\nNo data processing addendum or subprocessor list was found on www.pulumi.com. The addresses we tried returned 404 and the sitemap lists neither.\n\nRDAP for pulumi.com gives a registration date of 2017-02-13.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.pulumi.com/terms-and-conditions/), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects.\n\n- To know. Says the terms or the service can change without notice (costs points). \"You acknowledge and agree that the form and nature of the Pulumi Services which Pulumi provides may change from time to time without prior notice to you, subject to the terms in Section 4.3.\"\n- To know. Says access can be ended without notice or for any reason. \"9.4 You agree that Pulumi, in its sole discretion and for any or no reason, may terminate your account or any part thereof.\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of Washington.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Gives seven days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Pulumi may use the customer's trade names, trademarks and logos in marketing materials and customer lists at its sole discretion. \"8.4 You agree that Pulumi, in its sole discretion, may use your trade names, trademarks, service marks, logos, domain names and other distinctive brand features in presentations, marketing materials, customer lists, financial reports and Web site listings\"\n- Also in the text (2026-10-08). The agreement renews automatically for periods equal to the initial term unless either party asks to end it at least 30 days before the term ends. \"shall be automatically renewed for additional periods of the same duration as the Initial Service Term (collectively, the “Term”), unless either party requests termination at least thirty (30) days prior to the end of the then-current term.\"\n- Also in the text (2026-10-08). The liability clause says Pulumi is not liable to the customer for direct damages as well as indirect, incidental, special, consequential or exemplary ones. \"PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE.\"\n\n**Privacy policy** (https://www.pulumi.com/privacy/), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"With third–party social networks, advertising networks and websites, which usually act as separate controllers, so that Pulumi can market and advertise on third party platforms and websites;\"\n- Not found in the text. Gives the date it was last updated.\n- Gives a privacy contact. privacy@pulumi.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). The statement says it does not apply to the cloud products and services through which customers create and run their own websites and applications. \"This Privacy Statement does not apply to the extent we offer our customers various cloud products and services through which our customers may create their own websites and applications running on our platforms\"\n- Also in the text (2026-10-08). Pulumi collects business contact details and web behaviour data from third party data providers for targeted advertising and profiling. \"‘intent data’ which is web user behavior data, IP addresses, social handles, LinkedIn URL and custom profiles from third party data providers for the purposes of targeted advertising, delivering relevant email content, event promotion and profiling;\"\n\n## Live (updated 2026-10-08 20:09 UTC)\n\n- Right now: up, HTTP 404, 218 ms, checked 2026-10-08 20:09 UTC (get on `https://api.pulumi.com`)\n- Uptime 24h 100.0% (30 probes) · 30 days 100.0% (30 probes) · p50 158 ms · p95 272 ms\n- Vendor status page: none, All Systems Operational\n- Watching changelog \u003chttps://www.pulumi.com/releases/changelog/\u003e\n- Watching pricing \u003chttps://www.pulumi.com/pricing/\u003e\n- Watching privacy \u003chttps://www.pulumi.com/privacy/\u003e\n- Watching terms \u003chttps://www.pulumi.com/terms-and-conditions/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/pulumi-esc.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| ESC API calls | $0.01 | per 1,000 requests | $0.10 per 10,000. First 10,000 a month free on the free edition |\n| Essentials edition | $40 | per month (plan) | Includes 40 credits. A managed secret is $0.50 a month |\n| Pro edition | $400 | per month (plan) | Includes 400 credits. A managed secret is $0.75 a month |\n| Enterprise edition | $2000 | per month (plan) | Includes 2,000 credits. A managed secret is $1.00 a month |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it\n- Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page\n- OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default\n- Separate read, open and write scopes per environment, with open approvals and update approvals on Pro and Enterprise\n- Prices published per unit, $0.50 a secret a month on Essentials and $0.10 per 10,000 API calls, with a free edition and no card\n\n## Weaknesses\n\n- Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise\n- No API rate limit with numbers was found in the reviewed documentation\n- No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date\n- The official Pulumi MCP server lists no ESC tools, and the standalone esc CLI was retired at v0.26.0 on 9 July 2026\n- A 42-minute major incident on 6 October 2026 affected inbound OIDC on the API and ESC, with no detail published\n- The free edition has personal tokens only, which carry all of the user's permissions\n\n## Before you call it (notes for agents)\n\n1. Use `pulumi env`, not `esc`. The standalone CLI stopped at v0.26.0 and gets no security fixes\n2. Read one value with `pulumi env open \u003corg\u003e/\u003cproject\u003e/\u003cenv\u003e \u003cproperty path\u003e` so the whole environment doesn't enter context\n3. Run tools with `pulumi env run \u003cenv\u003e -- \u003ccmd\u003e`, which filters secret values from the command's output unless -i is set\n4. Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk\n5. Send `Authorization: token \u003ctoken\u003e` and `Accept: application/vnd.pulumi+8` on REST calls, and expect 409 when an environment changed since it was read\n6. Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed\n\n## Connect\n\nInstall:\n\n```bash\ncurl -fsSL https://get.pulumi.com | sh\n```\n\nFirst request:\n\n```bash\ncurl -H \"Authorization: token $PULUMI_ACCESS_TOKEN\" \\\n     -H \"Accept: application/vnd.pulumi+8\" \\\n     https://api.pulumi.com/api/user\n```\n\nThrough letme (picks today, calling later): https://letme.dev/pulumi-esc. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Infisical | A | 83.7 | 2 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/infisical.md |\n| AWS Secrets Manager | BB | 77.7 | 18 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/aws-secrets-manager.md |\n| Google Cloud Secret Manager | BB | 76.5 | 28 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/google-secret-manager.md |\n| Azure Key Vault | BB | 74.7 | 60 | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate | no | https://www.anchorterminal.com/tools/azure-key-vault.md |\n| Akeyless (SecretlessAI and MCP server) | BB | 73.6 | 74 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/akeyless.md |\n| Doppler | BB | 71.4 | 110 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/doppler.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Agent accounts give an AI agent a free ephemeral Pulumi Cloud account with ESC and no signup. Write access lasts 72 hours and a person has 30 days to claim it (source: \u003chttps://www.pulumi.com/docs/administration/concepts/agent-accounts/\u003e)\n- The standalone esc CLI was retired with v0.26.0 on 9 July 2026. Every command is now `pulumi env` in the Pulumi CLI (source: \u003chttps://www.pulumi.com/docs/esc/guides/migrate-from-esc-cli/\u003e)\n- `pulumi api` calls any REST endpoint with the CLI's credentials, lists the OpenAPI operations as JSON and writes errors as a one-line JSON envelope (source: \u003chttps://www.pulumi.com/docs/iac/cli/api/\u003e)\n- Rotated secrets keep two valid credentials at a time, so instances that haven't picked up the new one keep working (source: \u003chttps://www.pulumi.com/docs/esc/concepts/rotators/\u003e)\n- Audit logs record every environment open, read and decrypt with user, time and source IP, on Pro and Enterprise (source: \u003chttps://www.pulumi.com/docs/esc/administration/audit-logs/\u003e)\n- A major incident on 6 October 2026 affected inbound OIDC on the API and ESC for 42 minutes (source: \u003chttps://status.pulumi.com\u003e)\n\n## Compare\n\n- [1Password service accounts, SDKs and Environments MCP vs Pulumi ESC](https://www.anchorterminal.com/compare/1password-vs-pulumi-esc.md): B 69.7 vs BB 71.1\n- [Akeyless (SecretlessAI and MCP server) vs Pulumi ESC](https://www.anchorterminal.com/compare/akeyless-vs-pulumi-esc.md): BB 73.6 vs BB 71.1\n- [AWS Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-pulumi-esc.md): BB 77.7 vs BB 71.1\n- [Azure Key Vault vs Pulumi ESC](https://www.anchorterminal.com/compare/azure-key-vault-vs-pulumi-esc.md): BB 74.7 vs BB 71.1\n- [Bitwarden Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-pulumi-esc.md): C 56.8 vs BB 71.1\n- [Doppler vs Pulumi ESC](https://www.anchorterminal.com/compare/doppler-vs-pulumi-esc.md): BB 71.4 vs BB 71.1\n- [Google Cloud Secret Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/google-secret-manager-vs-pulumi-esc.md): BB 76.5 vs BB 71.1\n- [HashiCorp Vault + Vault MCP Server vs Pulumi ESC](https://www.anchorterminal.com/compare/hashicorp-vault-vs-pulumi-esc.md): B 64.2 vs BB 71.1\n- [Infisical vs Pulumi ESC](https://www.anchorterminal.com/compare/infisical-vs-pulumi-esc.md): A 83.7 vs BB 71.1\n- [Keeper Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.md): B 69.4 vs BB 71.1\n- [Phase vs Pulumi ESC](https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md): B 68 vs BB 71.1\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on pulumi.com or one of its subdomains, or the README of github.com/pulumi/esc-sdk. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"pulumi-esc\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/pulumi-esc\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/pulumi-esc.svg\" alt=\"Pulumi ESC on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Pulumi ESC on Anchor Terminal](https://www.anchorterminal.com/badges/pulumi-esc.svg)](https://www.anchorterminal.com/tools/pulumi-esc)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/pulumi-esc\"\u003ePulumi ESC on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Pulumi ESC is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/pulumi-esc-dark.png\n- Light: https://www.anchorterminal.com/assets/share/pulumi-esc-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Secrets \u0026 credential vaults",
        "url": "https://www.anchorterminal.com/categories/secrets"
      },
      {
        "name": "Pulumi ESC",
        "url": ""
      }
    ],
    "description": "Pulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs.",
    "facts": [
      "rank #120 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Pulumi ESC",
    "image": "https://www.anchorterminal.com/assets/og/tools-pulumi-esc.png",
    "path": "/tools/pulumi-esc",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Pulumi ESC review for AI agents, grade BB (71.1/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/pulumi-esc"
  },
  "tokens": {
    "markdown": 7800,
    "slim": 1830
  },
  "version": 1
}
