# Pulumi ESC > Pulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs. - Canonical: https://www.anchorterminal.com/tools/pulumi-esc - Markdown: https://www.anchorterminal.com/tools/pulumi-esc.md (~7,800 tokens) - Slim: https://www.anchorterminal.com/tools/pulumi-esc.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/pulumi-esc.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade BB · 71.1/100 · rank #120 of 722 · #7 in Secrets & credential vaults · agent-ready · confidence medium** ## Assessment An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation. ## Facts | Field | Value | | --- | --- | | Vendor | Pulumi Corporation (https://www.pulumi.com) | | Kind | HTTP API | | Category | Secrets & credential vaults (https://www.anchorterminal.com/categories/secrets) | | Transport | HTTP | | Endpoint | `https://api.pulumi.com` | | Auth | OAuth or key · Self-serve. Every request sends `Authorization: token ` to https://api.pulumi.com. A personal token comes from the console and carries all of the user's permissions. Organisation tokens (Essentials and above) and team tokens (Pro and above) are machine tokens that take a role, and custom roles with environment scopes need Pro. A workload on a registered OIDC issuer (GitHub Actions, GitLab CI, EKS, GKE and others) exchanges its ID token for a short-lived Pulumi token with `pulumi login --oidc-token` or POST /api/oauth/token. Under an agent with no credentials the CLI creates an ephemeral account by itself. | | Pricing | Freemium ($0.01 / 1k req) · Free edition with 25 secrets and 10,000 API calls a month for one user, no card. Essentials is $40 a month, Pro $400 and Enterprise $2,000, each including that many credits, with a managed secret at $0.50, $0.75 or $1.00 a month and API calls at $0.10 per 10,000. An agent can start with no contract through the free edition or an agent account (https://www.pulumi.com/pricing/, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the ESC docs, the OpenAPI document or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Pulumi's Terms & Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0 | | Packages | npm: `@pulumi/esc-sdk`; pypi: `pulumi-esc-sdk`; go: `github.com/pulumi/esc-sdk/sdk` | | Source | https://github.com/pulumi/esc-sdk | | Docs | https://www.pulumi.com/docs/esc/ | | llms.txt | https://www.pulumi.com/llms.txt | | Last release | 2026-10-07 | | npm downloads / week | 20,661 | | PyPI downloads / week | 53,903 | | Surface graded | Managed Pulumi Cloud at https://api.pulumi.com, reached through `pulumi env`, the REST API and the ESC SDKs | | Free edition | 1 user, 25 secrets, 10,000 API calls a month, no card. Personal tokens only | | Paid editions | Essentials $40 a month, Pro $400, Enterprise $2,000, each including the same number of credits at $1 a credit | | Unit prices | Managed secret $0.50 a month on Essentials, $0.75 on Pro, $1.00 on Enterprise. API calls $0.10 per 10,000. Plaintext config free | | Agent accounts | The CLI creates an ephemeral individual account when run under an agent with no credentials. Write access for 72 hours, claim within 30 days | | Credentials | Personal, organisation (Essentials up) and team (Pro up) tokens with expiry up to two years, and OIDC token exchange with a 25-hour default maximum | | Dynamic credentials | Login providers for AWS, Azure, Google Cloud, GitHub, Snowflake, Vault, Doppler and Infisical | | External stores | AWS Secrets Manager and Parameter Store, Azure Key Vault, Google Secret Manager, HashiCorp Vault, 1Password, Doppler and Infisical | | Rotation | Rotators for AWS IAM, Azure app secrets, MySQL, Postgres, Snowflake users and passwords, run by `pulumi env rotate` or on a schedule, keeping two valid secrets | | Audit | environment-open, environment-read-open and environment-decrypted events with user, time and source IP. Pro and Enterprise | | Approvals | Update approvals and open approvals by ruleset. Pro and Enterprise | | SDKs | TypeScript @pulumi/esc-sdk, Python pulumi-esc-sdk, Go github.com/pulumi/esc-sdk/sdk and .NET Pulumi.Esc.Sdk, all 0.14.0 (15 June 2026), Apache-2.0 | | MCP server | The Pulumi MCP server at https://mcp.ai.pulumi.com/mcp lists no ESC tools in its docs | | Self-hosting | Enterprise edition only, through sales | | Status | status.pulumi.com on Atlassian Statuspage, with an ESC component | | Capabilities | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | | Tags | hosted, closed-source, freemium, free-tier, no-card, openapi, llms-txt, oidc, cli, typescript, python, go, dotnet, status-page, soc2, enterprise | | JSON | https://www.anchorterminal.com/api/v1/tools/pulumi-esc.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 60 | 12.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 82 | 13.3 | | Agent ergonomics | 13% | 16.2 | 75 | 12.2 | | Security & auth | 14% | 17.5 | 79 | 13.8 | | Payments & pricing | 10% | 12.5 | 55 | 6.9 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 82 | 7.2 | | Transparency & trust (editorial 48, provenance 82) | 7% | 8.8 | 65 | 5.7 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **71.1 → BB** | ### Why each score - Reliability 60: Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. Statuspage at status.pulumi.com with an ESC component and incidents back to October 2023 (20). Between 10 July and 8 October 2026 the API or ESC had a 42-minute major incident on inbound OIDC on 6 October and a minor one on team token operations on 23 July, and a six-hour Neo outage on 11 September did not list ESC (20 of 30). No API rate limit with numbers was found. The free edition's 10,000 API calls a month is a quota (0 of 15). The OpenAPI document declares 429 with Retry-After on listing environments only, and updates return 409 when the environment changed since it was read. No backoff guidance was found (6 of 15). The pricing page lists an uptime commitment from Essentials up with no figure, and the terms promise commercially reasonable efforts (4 of 10). ESC is generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 82: OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). llms.txt at www.pulumi.com, every docs page served as Markdown by a .md suffix or an Accept header, and a JSON docs index (10). Each ESC operation has a paragraph saying what it does and which call follows, such as OpenEnvironment then ReadOpenEnvironment (16 of 20). Path and query parameters are typed, but the environment itself is a YAML body and durations are free strings (10 of 15). SDK pages carry worked examples. Error responses in the document are a status and a one-line description with no shared error schema (8 of 15). The API version travels in the Accept header (application/vnd.pulumi+8), and there is a dated changelog with RSS plus CLI and SDK changelogs (13 of 15). - Agent ergonomics 75: `pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20 of 25). List calls page with continuationToken and a count, and `pulumi api --paginate` follows the cursors. Filtering is limited to tags and organisation (15 of 20). The CLI maps failures to ten documented exit codes and `pulumi api` writes a one-line JSON error envelope with a stable code. Raw API errors are less structured (14 of 20). Updates are conditional on the environment's ETag and return 409 on a conflict, and check endpoints and `--dry-run` validate without writing. No idempotency keys (12 of 20). SDKs for TypeScript, Python, Go and .NET with a default client that needs only PULUMI_ACCESS_TOKEN, all still 0.x (14 of 15). - Security & auth 79: OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on claims. Organisation and team tokens take a role and an expiry of up to two years, and an organisation can enforce a maximum. Tokens travel in the Authorization header only. Personal tokens, the only kind on the free edition, carry all of the user's permissions (27 of 30). Separate environment:read, open and write scopes, open and update approvals, deletion protection, and secret filtering in `pulumi env run`. Custom roles and approvals are Pro and Enterprise (18 of 20). Secrets aren't untrusted content (10 of 15). Audit logs record environment-open, environment-read-open and environment-decrypted with user, time and source IP, on Pro and Enterprise only (12 of 15). SOC 2 Type II stated, a security whitepaper updated July 2026 and security@pulumi.com with a PGP key. No security.txt (404) and no bug bounty found (12 of 20). - Payments & pricing 55: No x402, MPP or L402 (0). Per-unit prices are public. A managed secret is $0.50 a month on Essentials, $0.75 on Pro and $1.00 on Enterprise, and API calls are $0.10 per 10,000 (20). The free edition includes 25 secrets and 10,000 API calls a month, and the pricing page says no credit card is required (20). The Pulumi CLI creates an ephemeral Pulumi Cloud account, ESC included, when it runs under an agent with no credentials. It has write access for 72 hours and a person must claim it within 30 days (15 of 20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 82: Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). Four CLI releases between 25 September and 7 October alone (20). Public changelog with RSS, community Slack and GitHub issues, with paid support on every edition. We couldn't read the issue tracker, so this is scored on the closed-service line (12 of 25). Official SDKs for four languages at 0.14.0, released 15 June 2026 (12 of 15). The SDK repository runs lint and tests in CI and had a commit on 11 September 2026. The standalone esc repository was retired after v0.26.0 on 9 July 2026 (8 of 10). - Transparency & trust 65: The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). The privacy statement covers customers of the services and gives no retention periods and no date. No public data processing addendum was found (12 of 30). The standalone CLI's retirement came with a final release, a notice printed on every command and a migration guide. No general deprecation policy was found (10 of 20). The whitepaper says the managed service runs in more than one region and the status page names AWS us-west-2. No subprocessor list was found (6 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/pulumi-esc.md (JSON https://www.anchorterminal.com/fixes/pulumi-esc.json) ### What we couldn't check - The lead named an `esc` CLI. The standalone esc CLI was retired at v0.26.0 on 9 July 2026 and ESC now ships only as `pulumi env` in the Pulumi CLI. - No API rate limit with numbers was found in the docs we read or in the OpenAPI document. - The pricing page lists an uptime commitment from Essentials up. We found no document giving the figure. - No data processing addendum, subprocessor list or dated terms were found on www.pulumi.com. - unchecked: GitHub star counts and the issue trackers of pulumi/pulumi and pulumi/esc-sdk, because the GitHub API refused us for its rate limit. - unchecked: whether the Pulumi CLI sends telemetry and how to turn it off. - unchecked: the self-hosted edition, which is Enterprise only and sold through sales. The grade is for the managed service. ### Sources - ESC documentation: (seen 2026-10-08) - pricing, free edition and per-unit prices: (seen 2026-10-08) - OpenAPI document: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - REST API basics, authentication and headers: (seen 2026-10-08) - pulumi api guide, pagination and error envelope: (seen 2026-10-08) - CLI exit codes: (seen 2026-10-08) - agent accounts: (seen 2026-10-08) - access tokens: (seen 2026-10-08) - OIDC issuers: (seen 2026-10-08) - environment RBAC scopes: (seen 2026-10-08) - audit log events: (seen 2026-10-08) - ESC audit logs: (seen 2026-10-08) - approvals: (seen 2026-10-08) - rotators: (seen 2026-10-08) - migration from the standalone esc CLI: (seen 2026-10-08) - MCP server tools: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - security page: (seen 2026-10-08) - security whitepaper: (seen 2026-10-08) - terms: (seen 2026-10-08) - privacy statement: (seen 2026-10-08) - changelog: (seen 2026-10-08) - Pulumi CLI releases: (seen 2026-10-08) - standalone esc repository, README and changelog: (seen 2026-10-08) - SDK repository, changelog and CI: (seen 2026-10-08) - TypeScript SDK on npm: (seen 2026-10-08) - Python SDK on PyPI: (seen 2026-10-08) ## Who's behind it (provenance 82/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Pulumi Corporation | 20/20 | | Domain age | pulumi.com, registered 2017-02-13 (9 years) | 11/15 | | Endpoint on the vendor's domain | api.pulumi.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 1 clause that costs points | 6.3/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | status.pulumi.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Terms & Conditions govern use of the Pulumi Services and name Pulumi Corporation, 601 Union St., Suite 1415, Seattle, WA 98101, with Washington law and King County courts. We found no date on the page. The privacy statement covers customers who register to use the services and gives privacy@pulumi.com as contact. We found no date on the page. www.pulumi.com/.well-known/security.txt and www.pulumi.com/security.txt both return 404. The security page gives security@pulumi.com and a PGP key. status.pulumi.com is Atlassian Statuspage with an ESC component. Its incident feed goes back to October 2023. No data processing addendum or subprocessor list was found on www.pulumi.com. The addresses we tried returned 404 and the sitemap lists neither. RDAP for pulumi.com gives a registration date of 2017-02-13. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.pulumi.com/terms-and-conditions/), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects. - To know. Says the terms or the service can change without notice (costs points). "You acknowledge and agree that the form and nature of the Pulumi Services which Pulumi provides may change from time to time without prior notice to you, subject to the terms in Section 4.3." - To know. Says access can be ended without notice or for any reason. "9.4 You agree that Pulumi, in its sole discretion and for any or no reason, may terminate your account or any part thereof." - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of the State of Washington. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Says how changes to the terms are announced. Gives seven days of notice before a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Pulumi may use the customer's trade names, trademarks and logos in marketing materials and customer lists at its sole discretion. "8.4 You agree that Pulumi, in its sole discretion, may use your trade names, trademarks, service marks, logos, domain names and other distinctive brand features in presentations, marketing materials, customer lists, financial reports and Web site listings" - Also in the text (2026-10-08). The agreement renews automatically for periods equal to the initial term unless either party asks to end it at least 30 days before the term ends. "shall be automatically renewed for additional periods of the same duration as the Initial Service Term (collectively, the “Term”), unless either party requests termination at least thirty (30) days prior to the end of the then-current term." - Also in the text (2026-10-08). The liability clause says Pulumi is not liable to the customer for direct damages as well as indirect, incidental, special, consequential or exemplary ones. "PULUMI, ITS SUBSIDIARIES AND AFFILIATES, AND ITS LICENSORS SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL CONSEQUENTIAL OR EXEMPLARY DAMAGES WHICH MAY BE INCURRED BY YOU, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, WHETHER OR NOT FORESEEABLE." **Privacy policy** (https://www.pulumi.com/privacy/), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "With third–party social networks, advertising networks and websites, which usually act as separate controllers, so that Pulumi can market and advertise on third party platforms and websites;" - Not found in the text. Gives the date it was last updated. - Gives a privacy contact. privacy@pulumi.com. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). The statement says it does not apply to the cloud products and services through which customers create and run their own websites and applications. "This Privacy Statement does not apply to the extent we offer our customers various cloud products and services through which our customers may create their own websites and applications running on our platforms" - Also in the text (2026-10-08). Pulumi collects business contact details and web behaviour data from third party data providers for targeted advertising and profiling. "‘intent data’ which is web user behavior data, IP addresses, social handles, LinkedIn URL and custom profiles from third party data providers for the purposes of targeted advertising, delivering relevant email content, event promotion and profiling;" ## Live (updated 2026-10-08 20:09 UTC) - Right now: up, HTTP 404, 218 ms, checked 2026-10-08 20:09 UTC (get on `https://api.pulumi.com`) - Uptime 24h 100.0% (30 probes) · 30 days 100.0% (30 probes) · p50 158 ms · p95 272 ms - Vendor status page: none, All Systems Operational - Watching changelog - Watching pricing - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/pulumi-esc.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | ESC API calls | $0.01 | per 1,000 requests | $0.10 per 10,000. First 10,000 a month free on the free edition | | Essentials edition | $40 | per month (plan) | Includes 40 credits. A managed secret is $0.50 a month | | Pro edition | $400 | per month (plan) | Includes 400 credits. A managed secret is $0.75 a month | | Enterprise edition | $2000 | per month (plan) | Includes 2,000 credits. A managed secret is $1.00 a month | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - The Pulumi CLI creates a free ephemeral account for an agent with no signup, with write access for 72 hours and 30 days to claim it - Public OpenAPI 3.0.3 document with 127 ESC operations, an llms.txt and a Markdown copy of every docs page - OIDC issuers exchange a workload's ID token for a short-lived Pulumi token, 25 hours at most by default - Separate read, open and write scopes per environment, with open approvals and update approvals on Pro and Enterprise - Prices published per unit, $0.50 a secret a month on Essentials and $0.10 per 10,000 API calls, with a free edition and no card ## Weaknesses - Audit logs, custom roles, team tokens, approvals and customer-managed keys need Pro ($400 a month) or Enterprise - No API rate limit with numbers was found in the reviewed documentation - No public data processing addendum or subprocessor list was found, and the terms and privacy statement carry no date - The official Pulumi MCP server lists no ESC tools, and the standalone esc CLI was retired at v0.26.0 on 9 July 2026 - A 42-minute major incident on 6 October 2026 affected inbound OIDC on the API and ESC, with no detail published - The free edition has personal tokens only, which carry all of the user's permissions ## Before you call it (notes for agents) 1. Use `pulumi env`, not `esc`. The standalone CLI stopped at v0.26.0 and gets no security fixes 2. Read one value with `pulumi env open // ` so the whole environment doesn't enter context 3. Run tools with `pulumi env run -- `, which filters secret values from the command's output unless -i is set 4. Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk 5. Send `Authorization: token ` and `Accept: application/vnd.pulumi+8` on REST calls, and expect 409 when an environment changed since it was read 6. Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed ## Connect Install: ```bash curl -fsSL https://get.pulumi.com | sh ``` First request: ```bash curl -H "Authorization: token $PULUMI_ACCESS_TOKEN" \ -H "Accept: application/vnd.pulumi+8" \ https://api.pulumi.com/api/user ``` Through letme (picks today, calling later): https://letme.dev/pulumi-esc. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Infisical | A | 83.7 | 2 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/infisical.md | | AWS Secrets Manager | BB | 77.7 | 18 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/aws-secrets-manager.md | | Google Cloud Secret Manager | BB | 76.5 | 28 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/google-secret-manager.md | | Azure Key Vault | BB | 74.7 | 60 | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate | no | https://www.anchorterminal.com/tools/azure-key-vault.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.6 | 74 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/akeyless.md | | Doppler | BB | 71.4 | 110 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/doppler.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Agent accounts give an AI agent a free ephemeral Pulumi Cloud account with ESC and no signup. Write access lasts 72 hours and a person has 30 days to claim it (source: ) - The standalone esc CLI was retired with v0.26.0 on 9 July 2026. Every command is now `pulumi env` in the Pulumi CLI (source: ) - `pulumi api` calls any REST endpoint with the CLI's credentials, lists the OpenAPI operations as JSON and writes errors as a one-line JSON envelope (source: ) - Rotated secrets keep two valid credentials at a time, so instances that haven't picked up the new one keep working (source: ) - Audit logs record every environment open, read and decrypt with user, time and source IP, on Pro and Enterprise (source: ) - A major incident on 6 October 2026 affected inbound OIDC on the API and ESC for 42 minutes (source: ) ## Compare - [1Password service accounts, SDKs and Environments MCP vs Pulumi ESC](https://www.anchorterminal.com/compare/1password-vs-pulumi-esc.md): B 69.7 vs BB 71.1 - [Akeyless (SecretlessAI and MCP server) vs Pulumi ESC](https://www.anchorterminal.com/compare/akeyless-vs-pulumi-esc.md): BB 73.6 vs BB 71.1 - [AWS Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-pulumi-esc.md): BB 77.7 vs BB 71.1 - [Azure Key Vault vs Pulumi ESC](https://www.anchorterminal.com/compare/azure-key-vault-vs-pulumi-esc.md): BB 74.7 vs BB 71.1 - [Bitwarden Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-pulumi-esc.md): C 56.8 vs BB 71.1 - [Doppler vs Pulumi ESC](https://www.anchorterminal.com/compare/doppler-vs-pulumi-esc.md): BB 71.4 vs BB 71.1 - [Google Cloud Secret Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/google-secret-manager-vs-pulumi-esc.md): BB 76.5 vs BB 71.1 - [HashiCorp Vault + Vault MCP Server vs Pulumi ESC](https://www.anchorterminal.com/compare/hashicorp-vault-vs-pulumi-esc.md): B 64.2 vs BB 71.1 - [Infisical vs Pulumi ESC](https://www.anchorterminal.com/compare/infisical-vs-pulumi-esc.md): A 83.7 vs BB 71.1 - [Keeper Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.md): B 69.4 vs BB 71.1 - [Phase vs Pulumi ESC](https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md): B 68 vs BB 71.1 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on pulumi.com or one of its subdomains, or the README of github.com/pulumi/esc-sdk. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "pulumi-esc", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Pulumi ESC on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Pulumi ESC on Anchor Terminal](https://www.anchorterminal.com/badges/pulumi-esc.svg)](https://www.anchorterminal.com/tools/pulumi-esc) ``` Plain link: ```html Pulumi ESC on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Pulumi ESC is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/pulumi-esc-dark.png - Light: https://www.anchorterminal.com/assets/share/pulumi-esc-light.png