Roundups

Top 7 Secrets Management Tools and Platforms in 2026

Vault is now IBM's. CyberArk is now Palo Alto's. We compare the seven leading secrets management platforms on deployment model, dynamic secrets support and what they actually cost.

Illustration of a vast vault of glowing glass vials representing centralized secrets management

TL;DR

  • HashiCorp Vault remains the reference implementation for dynamic, short-lived secrets — but it is now an IBM product (acquisition closed February 27, 2025) and its open-source core sits under the restrictive BUSL-1.1 license.
  • CyberArk closed its acquisition by Palo Alto Networks on February 11, 2026. The product names have not changed yet. Factor roadmap uncertainty into any multi-year contract.
  • AWS Secrets Manager is the only tool here with fully transparent per-unit pricing: $0.40 per secret per month plus $0.05 per 10,000 API calls (AWS pricing page, observed September 2025).
  • The biggest shift in the category is machine identity. Infisical, Doppler and Akeyless have all shipped AI-agent credential features in the past year, and per-identity pricing now matters more than per-seat.

Secrets management is the practice of storing, rotating and distributing credentials — database passwords, API keys, certificates, encryption keys — outside your source code, with audit logs and access policies attached. The leading tools in 2026 are HashiCorp Vault, CyberArk Secrets Manager, Infisical, Akeyless, AWS Secrets Manager, Azure Key Vault and Doppler. Which one fits depends on three things: whether you need self-hosting, whether you run in more than one cloud, and how many machine identities you have to credential.

How we picked these

Ranked by how much of a multi-environment secrets problem each product can own on its own, weighted by maturity and publicly verifiable adoption. Specifically:

  • Environment coverage — multi-cloud, on-prem, Kubernetes, CI/CD, or locked to one provider.
  • Dynamic secrets — can it mint short-lived credentials on demand, or only store and rotate static ones?
  • Deployment flexibility — SaaS, self-hosted, open source, or a single option.
  • Pricing transparency — published per-unit rates beat "contact sales".
  • Verifiable adoption — named customers or disclosed scale from the vendor or a reputable source.

We did not rank on feature-checklist totals. A product that does one layer well and prices it clearly beats a broad suite you cannot evaluate without a sales call.

Quick comparison

Company Best for Deployment Pricing model
HashiCorp Vault Dynamic secrets at enterprise scale SaaS, self-managed, BUSL-1.1 source Tiered; no public per-unit rates
CyberArk Secrets Manager Enterprises standardizing on one identity platform SaaS, self-hosted, open-source Conjur Quote only
Infisical Open-source self-hosting with a paid upgrade path Self-hosted (free) or SaaS Per identity, from $20/month
Akeyless Replacing a self-hosted vault with SaaS SaaS only Quote only
AWS Secrets Manager AWS-native workloads AWS managed service $0.40/secret/month + API calls
Azure Key Vault HSM-backed key custody on Azure Azure managed service Consumption-based, two tiers
Doppler Small teams wanting predictable seat pricing SaaS or on-prem $21/user/month (Team)

1. HashiCorp Vault

HashiCorp Vault product interface showing secrets management dashboard
Image: HashiCorp Vault

HashiCorp Vault is the product most other tools in this list are measured against. Its distinguishing capability is dynamic secrets: rather than storing a long-lived database password, Vault brokers a credential that is generated on request and revoked on a TTL. It also offers encryption as a service, so applications can encrypt data without handling keys directly. The architecture is pluggable — auth methods and secrets engines are modular, which is why Vault ended up integrated with nearly every CI/CD and orchestration tool.

IBM completed its acquisition of HashiCorp on February 27, 2025. The site is now branded "HashiCorp, an IBM Company" and support routes through IBM.

Best for: Platform teams that need short-lived credentials across mixed on-prem and cloud estates.

Pros

  • Dynamic secrets with automatic revocation, backed by the largest library of pluggable secrets engines in the category.
  • Vendor-named customers include Walgreens, Lufthansa, GSK, Deutsche Bank and BNP Paribas.
  • Integrates with the rest of the HashiCorp stack (Terraform, Consul, Boundary) under one identity model.

Cons

  • The open-source core moved to BUSL-1.1 in August 2023, which bars use in a competing commercial service.
  • No self-serve per-unit pricing is published post-acquisition — evaluation now runs through IBM sales.
  • Self-managed Vault carries real operational burden: unseal procedures, HA topology and storage backends are yours to run.

2. CyberArk Secrets Manager

CyberArk approaches secrets from the privileged-access side, and it shows. Secrets Manager is built around non-human identity governance across multi-cloud, CI/CD and container environments. Its most practical feature is Secrets Hub, which layers CyberArk policy and audit on top of secrets that stay in AWS Secrets Manager or Azure Key Vault — so developers keep using native cloud tooling while security gets one governance plane. The open-source Conjur edition gives teams a free entry point.

Palo Alto Networks completed its acquisition of CyberArk on February 11, 2026, in a deal valued around $25 billion in equity. Product branding is unchanged as of this writing.

Best for: Large enterprises that already run CyberArk for privileged access.

Pros

  • The only vendor here spanning SaaS, self-hosted and a free open-source edition in a single product line.
  • Secrets Hub centralizes governance without forcing migration off native cloud secret stores.
  • CyberArk says it was named overall leader in the 2025 KuppingerCole Leadership Compass for enterprise secrets management.

Cons

  • No published pricing of any kind. Every engagement is a quote.
  • The Palo Alto acquisition closed recently enough that roadmap and packaging changes are a live risk.
  • The product line — SaaS, Self-Hosted, Conjur, Secrets Hub, Credential Providers — takes real effort to evaluate against single-SKU competitors.

3. Infisical

Infisical open-source secrets management platform
Image: Infisical

Infisical is the strongest open-source alternative to Vault right now, and it has expanded well beyond secrets. The platform now covers secrets management, certificate and PKI lifecycle, and privileged access in one codebase. For AI workloads it ships Agent Vault and Agent Proxy, which give agents scoped access to tools without exposing the underlying secret value — a meaningfully different model from handing an agent an API key.

Infisical raised a $16 million Series A led by Elad Gil in June 2025. Its repository carries roughly 27,000 GitHub stars, and named case-study customers include Hugging Face, Lucid, Writer and OpenRouter.

Best for: Teams that want to self-host for free now and buy support later.

Pros

  • Core code is MIT-licensed and self-hostable with no seat or secret cap.
  • Secrets, certificates and privileged access ship as one platform rather than three purchases.
  • Agent Proxy brokers tool access for AI agents without exposing raw credential values.

Cons

  • It is open-core, not open source: everything under the ee directory requires a paid license for production use.
  • Per-identity pricing ($20–23/identity/month Pro, $40–46 Advanced, as of October 2026) adds up fast when every service account counts as an identity.
  • The PKI and PAM modules are recent additions and less battle-tested than the secrets core.

4. Akeyless

Akeyless unified identity security platform architecture diagram
Image: Akeyless

Akeyless sells a pure-SaaS vault aimed squarely at teams tired of operating one. Its technical differentiator is Distributed Fragments Cryptography (DFC), a patented zero-knowledge design in which Akeyless never holds a complete encryption key — fragments are split so that no single party, including the vendor, can reconstruct it. The platform covers secrets, multi-cloud key management, certificate lifecycle and a modern PAM module.

The company states it has secured over 220 billion machine interactions. Named customers include Wix, Thales, Deutsche Bank, Hugo Boss and Cimpress, the last of which is quoted describing a migration off a self-hosted vault.

Best for: Organizations replacing self-managed Vault infrastructure with a managed service.

Pros

  • DFC zero-knowledge key handling is a genuine architectural difference from standard KMS and HSM custody models.
  • Covers secrets, KMS, certificates and PAM in one SaaS platform, removing cluster operations entirely.
  • Publicly named enterprise customers who have migrated from competing vaults.

Cons

  • SaaS only. There is no self-hosted or open-source edition, so you are fully dependent on Akeyless availability.
  • Pricing is not published — even the dedicated pricing page yields no rates without contact.
  • Its headline efficiency claims about reduced overhead and lower total cost are vendor-authored, with no independent audit cited.

5. AWS Secrets Manager

AWS Secrets Manager service overview graphic
Image: AWS Secrets Manager

AWS Secrets Manager handles the full lifecycle of database credentials, API keys and other secrets with fine-grained IAM policies attached. Its most useful feature is scheduled rotation without redeployment — a Lambda function rotates the credential and applications pick up the new value on next retrieval. Cross-region replication is built in for disaster recovery.

It is also the only product in this roundup with genuinely transparent pricing: $0.40 per secret per month, plus $0.05 per 10,000 API calls, as published on the AWS pricing page and observed in September 2025. AWS's own worked examples put a 1,500-secret organization at roughly $604.50/month and a 10,000-secret organization at about $4,060/month.

Best for: Workloads that live entirely inside AWS.

Pros

  • Fully published, dated, per-unit pricing with vendor worked examples at several scales.
  • Native IAM integration and automated rotation without touching application deployments.
  • Built-in cross-region replication for disaster recovery, no extra tooling.

Cons

  • AWS-only. There is no self-hosted option and no meaningful story for workloads in other clouds.
  • Per-call billing scales unpredictably — AWS's own example of five million ephemeral token requests per month comes to roughly $2,850.
  • No dynamic secrets engine comparable to Vault or Infisical. Rotation is scheduled, not credential-on-demand.

6. Azure Key Vault

Microsoft Azure Key Vault is primarily a key custody service that also stores secrets and certificates. Its defining characteristic is FIPS-validated HSM backing — the Premium tier stores keys in hardware security modules, and applications never get direct access to key material. Instead they call the vault to perform cryptographic operations. That distinction matters for regulated workloads where key extraction must be impossible, not merely logged.

Pricing is consumption-based across a Standard and a Premium (HSM-backed) tier, published on Azure's pricing page rather than as a flat subscription. Key Vault is integrated with Microsoft Sentinel and Defender for cloud-wide monitoring.

Best for: Azure-native teams with regulatory requirements for HSM-held keys.

Pros

  • HSM-backed key custody without buying or operating hardware security modules.
  • Deep native integration with Microsoft Sentinel, Defender and the rest of the Azure security stack.
  • Available across Microsoft's broad regional footprint, which matters for data-residency rules.

Cons

  • Azure-only, with the same lock-in problem as its AWS counterpart.
  • Pricing is calculator-gated rather than stated plainly on the product page, which slows budgeting.
  • No dynamic or short-lived credential engine. This is static key, secret and certificate custody.

7. Doppler

Doppler secrets management dashboard showing environment configuration
Image: Doppler

Doppler is the most developer-friendly option here and the easiest to price. It syncs secrets across environments and integrations from a single control plane, with Dynamic Secrets that issue fresh credentials per deploy and auto-revoke them. It has leaned hard into AI workloads with a native MCP server that lets agents request secrets under scoped OIDC service-account identities — and, notably, it does not charge per agent.

Pricing as of October 2026: free for three developers, then $8/month per additional user on the Developer plan, or $21/user/month on Team. The company states it secures more than 76,000 organizations and serves over 75 billion secret reads monthly.

Best for: Small and mid-size teams that want flat, predictable per-seat costs.

Pros

  • Seat-based pricing that does not scale with the number of AI agents or service accounts.
  • Published per-user rates on every tier below Enterprise — rare in this category.
  • Offers an on-premises deployment option despite being SaaS-first.

Cons

  • Proprietary. There is no open-source edition and no free self-hosted tier.
  • Enterprise features including external key management, dynamic secrets and log forwarding sit behind a custom-priced tier.
  • Team-plan add-ons such as custom roles and user groups cost $9/seat/month each, which stacks quickly.

How to choose

If you run multi-cloud or hybrid and need short-lived credentials: HashiCorp Vault, accepting the operational burden and the BUSL licensing constraint. Akeyless if you want the same outcome without running the cluster.

If you are entirely on AWS or entirely on Azure: use the native service. AWS Secrets Manager and Azure Key Vault are cheaper, better integrated and require no new vendor. Revisit only when a second cloud appears.

If budget is the constraint: Infisical self-hosted. The MIT core has no cap, and you can buy the enterprise license later without migrating.

If you already own CyberArk: CyberArk Secrets Manager, and use Secrets Hub so developers keep their native cloud workflows.

If you are a team of five to fifty: Doppler. The pricing is knowable in advance, which is worth more than feature breadth at that size.

Secrets management is one layer, not a security program. It sits alongside the cloud security platforms that watch runtime posture, and most credential leaks are caught there rather than in the vault.

If you are credentialing AI agents: compare per-identity economics carefully. Infisical charges per identity; Doppler charges per human seat. At a hundred agents those two models produce very different invoices.

Frequently Asked Questions

What is secrets management?

Secrets management is the practice of storing credentials — API keys, database passwords, certificates, encryption keys — in a dedicated encrypted system rather than in code, config files or environment variables. The system controls who can read each secret, logs every access, and rotates credentials on a schedule or on demand.

Which secrets management tool is best for multiple environments?

HashiCorp Vault and CyberArk Secrets Manager handle multi-environment estates best, because both run self-hosted and in SaaS and broker credentials across clouds. Akeyless achieves similar coverage as pure SaaS. Cloud-native options like AWS Secrets Manager do not extend beyond their own provider.

How do you automate secrets management in DevOps?

Inject secrets at runtime rather than at build time. Authenticate the workload — via Kubernetes service account, OIDC token or IAM role — then have it fetch credentials from the vault on startup. Use dynamic secrets with short TTLs so a leaked credential expires on its own.

Why is proper secret management important?

Hardcoded credentials leak through repositories, logs, container images and CI output, and a static credential stays valid until someone notices. Centralized management gives you one place to revoke, a full audit trail of who accessed what, and automatic rotation that limits how long any exposure remains useful.

Is AWS Secrets Manager enough on its own?

For single-cloud AWS workloads, usually yes — rotation, IAM integration and replication cover most needs at $0.40 per secret per month. You outgrow it when you add a second cloud, need on-premises coverage, or need credentials minted on demand rather than rotated on a schedule.

Editor's note — sources: Product, pricing and documentation pages for each vendor, observed September–October 2026: HashiCorp Vault, AWS Secrets Manager pricing, CyberArk Secrets Management, Azure Key Vault, Doppler pricing, Infisical pricing, Akeyless. Acquisition details from IBM and Palo Alto Networks announcements and investor communications. Infisical Series A reporting, June 2025. Pricing and feature claims are accurate as of October 2026 and change frequently — confirm with the vendor before purchase. Where a vendor publishes no pricing, we have said so rather than estimating.

Get Edgewisely in your inbox

Business stories that matter, free. Enter your email — no password, no account to set up.
jamie@example.com
Subscribe