# Pulumi ESC (slim) > Pulumi ESC is the secrets and configuration service in Pulumi Cloud. Environments hold static secrets, pull from other vaults and issue short-lived cloud credentials over OIDC, read through the Pulumi CLI, a REST API and four SDKs. - Full: https://www.anchorterminal.com/tools/pulumi-esc.md (~7,800 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/pulumi-esc.json · canonical https://www.anchorterminal.com/tools/pulumi-esc - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 71.1/100 · rank #120 of 722 · #7 in Secrets & credential vaults · agent-ready · confidence medium** Assessment: An agent can start without a signup, because the Pulumi CLI creates a free ephemeral account that includes ESC, and the REST API has a public OpenAPI document. Audit logs, custom roles and approvals need the Pro edition at $400 a month, and no API rate limit was found in the reviewed documentation. ## Facts - Kind: HTTP API · vendor: Pulumi Corporation · category: Secrets & credential vaults · legal entity: Pulumi Corporation · provenance 82/100 - Endpoint: `https://api.pulumi.com` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Pulumi's Terms & Conditions. The Pulumi CLI, the ESC evaluator and the ESC SDKs are Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Surface graded: Managed Pulumi Cloud at https://api.pulumi.com, reached through `pulumi env`, the REST API and the ESC SDKs - Free edition: 1 user, 25 secrets, 10,000 API calls a month, no card. Personal tokens only - Paid editions: Essentials $40 a month, Pro $400, Enterprise $2,000, each including the same number of credits at $1 a credit - Unit prices: Managed secret $0.50 a month on Essentials, $0.75 on Pro, $1.00 on Enterprise. API calls $0.10 per 10,000. Plaintext config free - Agent accounts: The CLI creates an ephemeral individual account when run under an agent with no credentials. Write access for 72 hours, claim within 30 days - Credentials: Personal, organisation (Essentials up) and team (Pro up) tokens with expiry up to two years, and OIDC token exchange with a 25-hour default maximum - Dynamic credentials: Login providers for AWS, Azure, Google Cloud, GitHub, Snowflake, Vault, Doppler and Infisical - External stores: AWS Secrets Manager and Parameter Store, Azure Key Vault, Google Secret Manager, HashiCorp Vault, 1Password, Doppler and Infisical - Rotation: Rotators for AWS IAM, Azure app secrets, MySQL, Postgres, Snowflake users and passwords, run by `pulumi env rotate` or on a schedule, keeping two valid secrets - Audit: environment-open, environment-read-open and environment-decrypted events with user, time and source IP. Pro and Enterprise - Approvals: Update approvals and open approvals by ruleset. Pro and Enterprise - SDKs: TypeScript @pulumi/esc-sdk, Python pulumi-esc-sdk, Go github.com/pulumi/esc-sdk/sdk and .NET Pulumi.Esc.Sdk, all 0.14.0 (15 June 2026), Apache-2.0 - MCP server: The Pulumi MCP server at https://mcp.ai.pulumi.com/mcp lists no ESC tools in its docs - Self-hosting: Enterprise edition only, through sales - Status: status.pulumi.com on Atlassian Statuspage, with an ESC component - Prices: ESC API calls $0.01 per 1,000 requests; Essentials edition $40 per month (plan); Pro edition $400 per month (plan); Enterprise edition $2000 per month (plan) - Scores: Reliability 60, Performance pending, Schema & documentation 82, Agent ergonomics 75, Security & auth 79, Payments & pricing 55, Task success pending, Maintenance & community 82, Transparency & trust 65 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service, the Pulumi Cloud API that the CLI and SDKs call. · Schema & documentation, OpenAPI 3.0.3 at api.pulumi.com/api/openapi/pulumi-spec.json, 479 paths, of which 94 paths and 127 operations are ESC (25). · Agent ergonomics, `pulumi env open` takes a property path, so one value can be read instead of the whole environment, in JSON, YAML, dotenv or shell form (20… · Security & auth, OIDC issuers exchange a workload's ID token for a Pulumi token that lasts 25 hours at most by default, under allow and deny policies on clai… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Pulumi CLI v3.268.0, which carries `pulumi env`, was released on 7 October 2026, a day before this check (30). · Transparency & trust, The CLI, the ESC evaluator and the SDKs are Apache-2.0, and Pulumi Cloud is closed under clear terms (20 of 30). - Sources: 28, open questions: 7, both in the full twin - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit - JSON: https://www.anchorterminal.com/api/v1/tools/pulumi-esc.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/pulumi-esc.svg` or a link to https://www.anchorterminal.com/tools/pulumi-esc from a page on pulumi.com or one of its subdomains, or the README of github.com/pulumi/esc-sdk, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use `pulumi env`, not `esc`. The standalone CLI stopped at v0.26.0 and gets no security fixes 2. Read one value with `pulumi env open // ` so the whole environment doesn't enter context 3. Run tools with `pulumi env run -- `, which filters secret values from the command's output unless -i is set 4. Set PULUMI_ACCESS_TOKEN for the SDKs. From 0.14.0 they no longer read the CLI login on disk 5. Send `Authorization: token ` and `Accept: application/vnd.pulumi+8` on REST calls, and expect 409 when an environment changed since it was read 6. Relay the claim link an agent account prints. The account goes read-only after 72 hours and locks after 30 days unclaimed ## Connect ```bash curl -fsSL https://get.pulumi.com | sh ``` ```bash curl -H "Authorization: token $PULUMI_ACCESS_TOKEN" \ -H "Accept: application/vnd.pulumi+8" \ https://api.pulumi.com/api/user ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/pulumi-esc ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 83.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/infisical.min.md | | AWS Secrets Manager | BB | 77.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.5 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Azure Key Vault | BB | 74.7 | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate | https://www.anchorterminal.com/tools/azure-key-vault.min.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/akeyless.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)