Skip to content
By developers

HashiCorp Vault vs AWS, Doppler, Infisical, Azure (2026)

Six secrets management options compared for 2026: dynamic secrets, deployment model, licensing and current published pricing, verified September 2026.

The short answer: if you run multi-cloud infrastructure and need true dynamic secrets, pick HashiCorp Vault (now an IBM product). If you live on AWS, use AWS Secrets Manager. On Azure, use Azure Key Vault. If your real blocker is that developers keep falling back to .env files, pick Doppler. If you need self-hosting with an OSI-approved license, pick Infisical, or OpenBao if you want a governed Vault fork.

The problem underneath all five choices is the same. Application credentials leak because storing them properly is slower than storing them badly. The Verizon Data Breach Investigations Report has repeatedly documented secrets exposed in public Git repositories tied to web application infrastructure, and millions of credentials leak from GitHub every year. Every one of those incidents started with an API key, a database password, or a cloud credential put somewhere it did not belong.

Secrets management is not a complex discipline. Application credentials, API keys, database passwords, TLS certificates, and encryption keys belong in a dedicated store, injected at runtime, rotated automatically, and audited fully. The complexity is making that easy enough that developers follow it instead of working around it.

This guide covers the five tools that matter most in 2026, with honest assessments of where each fits and where each falls short. If you have already decided Vault is not for you and want the replacement shortlist specifically, read the companion guide to alternatives to HashiCorp Vault. This page is the head-to-head comparison; that one is the migration shortlist.


How We Evaluated

Last verified: September 2026.

For this refresh we checked each vendor's own published pricing page, product documentation, and release notes, plus regulator-grade primary sources for ownership changes. The sources were the vendors' own pricing pages for Doppler, Infisical, AWS Secrets Manager, and Azure Key Vault. Capability and lifecycle claims came from HashiCorp's Vault pricing page and release notes, and from the OpenBao release announcements published through the Open Source Security Foundation. Ownership changes came from the acquisition press releases issued by IBM, Palo Alto Networks, and Delinea.

Four things decided the rankings. First, deployment model, because self-hosted versus SaaS is the constraint that eliminates tools fastest in regulated environments. Second, dynamic secrets, because short-lived credentials are the only control that limits the blast radius of a leak you did not detect. Third, licensing, because the Business Source License now triggers legal review at a growing number of companies. Fourth, developer experience, because a tool that developers route around produces no security value at all.

No hands-on lab testing is claimed here. Capability claims trace to vendor documentation, and pricing figures were read from the vendors' own published pages in September 2026. Secrets pricing changes often, so confirm current numbers before procurement.


The Real Problem: Developer Workarounds

Secrets management tools only work when developers use them. The most sophisticated vault deployment in the world produces no security value if engineers working at 11pm before a deadline paste the production database URL into a .env file and commit it to the repo.

That behavioral reality is why developer experience has become a dominant evaluation criterion. The question is not just "does this tool store secrets securely?" but "will developers actually use this tool, or will they work around it?"

The tools that win in practice share a characteristic: they inject secrets into applications without requiring developers to change how they write code. The workflow stays npm start or python app.py; the secrets tool intercepts that command, injects credentials as environment variables or files, and gets out of the way. Tools that require a new SDK, application code changes, or direct vault interaction see adoption drop sharply outside dedicated platform engineering teams.

Static versus dynamic secrets is the other axis that matters operationally. Static secrets are long-lived credentials stored in a vault and retrieved by applications. If the vault is breached, or a developer inadvertently logs a secret, a static credential can be exploited until someone rotates it manually. Dynamic secrets are generated on demand, expire quickly, and are revoked automatically. The blast radius of a dynamic credential exposure is limited to its short lifespan. The scale of exposure already in the wild makes this urgent: billions of leaked credentials are already circulating from years of accumulated breaches, and every unrotated static secret adds to that pool.


Quick Comparison: Top 5 Secrets Management Tools 2026

Tool Best For Deployment Dynamic Secrets Published Pricing (Sept 2026) Open Source
HashiCorp Vault (IBM) Multi-cloud enterprise, regulated industries Self-hosted or HCP Vault Dedicated Yes, native, 20+ backends Community edition free; Enterprise and HCP quoted by sales No, Business Source License
AWS Secrets Manager AWS-native workloads AWS managed No, scheduled rotation only $0.40 per secret per month plus $0.05 per 10,000 API calls No
Doppler Developer adoption, fast-moving teams SaaS only Enterprise tier only Developer free for 3 users, then $8 per user; Team $21 per user per month No
Infisical Self-hosting with a permissive license Self-hosted or cloud Yes, Advanced tier and above Free for 5 identities; Pro $20, Advanced $40 per identity per month (annual) Yes, MIT community edition
Azure Key Vault Azure and Entra ID shops, HSM key custody Azure managed No, rotation and managed identity instead Per 10,000 operations, plus per-key monthly fees for HSM keys No
OpenBao (honorable mention) Teams that need Vault semantics under a true open source license Self-hosted Yes, inherited from the Vault fork Free Yes, MPL 2.0

1. HashiCorp Vault (an IBM product)

Best for: multi-cloud enterprises, regulated industries, and platform engineering teams that need dynamic secrets across several clouds.

Vault is the industry benchmark for secrets management in environments with multi-cloud infrastructure and strict security requirements. IBM closed the $6.4 billion HashiCorp acquisition on February 27, 2025. Any comparison that still describes HashiCorp as an independent vendor is out of date. Vault has been the reference implementation since 2015, and the architecture it established (identity-based access, dynamic credential generation, full audit logging) remains the standard others are measured against.

What changed under IBM: Vault jumped from 1.21 straight to 2.0 in April 2026 to align with IBM versioning. Vault Enterprise now follows the IBM Support Cycle-2 model, which gives each major release at least two years of standard support with extended support sold separately, replacing HashiCorp's older long-term support approach. The 2.0 release added Workload Identity Federation for secret syncing without static credentials and SCIM 2.0 provisioning for Vault's own user and group management. Enterprise licensing can now be fulfilled through IBM Passport Advantage. If you signed a HashiCorp contract before the deal, review renewal terms carefully; the commercial motion is IBM's now.

The license reality: In August 2023 HashiCorp changed Vault's license from Mozilla Public License to the Business Source License. BSL is not open source by the Open Source Initiative definition. Internal use remains free, but commercial production deployments are subject to licensing terms, and some legal teams now require review before approving BSL software. No public source confirms that IBM has reversed this, so treat Vault as BSL-licensed until IBM says otherwise.

The OpenBao alternative: OpenBao is a Vault fork under Linux Foundation and OpenSSF governance, licensed MPL 2.0 with no commercial restrictions. It reached v2.5.0 in February 2026 and v2.6 in August 2026, adding per-namespace sealing and a workflow engine for cross-plugin communication. For teams that want Vault's model without BSL exposure, OpenBao is now a serious option rather than a curiosity.

Dynamic secrets, the core differentiator: When an application needs a database credential, it asks Vault. Vault creates a new database user with specific permissions, returns credentials with a time to live (typically 1 to 24 hours), and revokes them automatically when the lease expires. No long-lived database password exists. If the application is compromised and the credential is exfiltrated, it is useless within hours. Applied across database access, cloud provider credentials, and TLS certificates, this is the architecture regulated financial institutions and healthcare organizations deploy.

Secrets engines: Vault's functionality is pluggable. The database engine supports MySQL, PostgreSQL, MongoDB, Oracle, Cassandra, and many more. The PKI engine manages TLS certificate issuance and rotation. Cloud engines generate short-lived IAM credentials for AWS, Azure, and GCP. The transit engine provides encryption as a service: applications send plaintext and receive ciphertext, keys never leave Vault's barrier, and key versioning supports rotation without re-encrypting existing data. That breadth makes Vault general cryptographic infrastructure, not just a credential store.

Authentication methods: Kubernetes service accounts, AWS IAM roles, Azure managed identities, LDAP, OIDC, and TLS certificates. Applications authenticate with their existing platform identity rather than a static password. For how the same identity-first thinking applies at the application layer, see the guide to API authorization patterns.

Deployment and pricing: Production self-hosted Vault typically uses integrated Raft storage or Consul for high availability, with auto-unseal configured through a cloud KMS so nodes do not need manual unsealing after restart. HCP Vault Secrets, the SaaS-only product, was sunsetted in mid-2025, and the HCP Vault Dedicated Starter tier was discontinued around the same time (InfoQ, April 2026). As of September 2026 HashiCorp's own Vault pricing page lists Vault as custom pricing through sales rather than publishing an entry-level hourly rate, so budget by quote and not by the per-hour figures that older comparisons still cite.

Honest weakness: Vault's operational complexity is real. Self-hosted deployment means cluster and high-availability configuration, seal and unseal key management, HCL policy authoring, an authentication method per workload type, and ongoing upgrade and monitoring work. Organizations that deploy self-hosted Vault without dedicated platform engineering expertise consistently report it as their highest-maintenance security infrastructure. The depth that suits complex environments is the same depth that makes it wrong for teams without the resources to run it well.


2. AWS Secrets Manager

Best for: organizations running substantially all workloads on AWS.

AWS Secrets Manager is the path of least resistance for AWS-first organizations. It integrates natively with AWS services: automatic credential rotation for RDS, Redshift, and DocumentDB using Lambda rotation functions, IAM policies for access control, KMS for encryption, and CloudTrail for audit logging. For teams already inside the AWS toolchain, that native integration removes the configuration overhead that makes other secrets managers hard to adopt.

How it works: Secrets are key-value pairs encrypted with KMS keys. Applications retrieve them through the AWS SDK or the Secrets Manager API. IAM policies define which compute resources (EC2 instances, Lambda functions, ECS tasks, EKS pods) can read which secrets. Cross-account sharing through resource policies allows centralized secrets management across AWS Organizations while keeping least-privilege boundaries. CloudFormation and Terraform support means secret lifecycle can live in infrastructure as code.

Automatic rotation: Rotation schedules cycle credentials using Lambda functions. For RDS (MySQL, PostgreSQL, Oracle, SQL Server, MariaDB), Redshift, and DocumentDB, AWS ships pre-built rotation functions that use a two-user strategy: the new credential is created and verified before the old one is invalidated, so there is no application downtime. Custom Lambda rotation functions extend this to any secret type, at development cost proportional to the target service's complexity. This is not Vault's dynamic secrets model, but scheduled rotation of static credentials is a large improvement over credentials that are never rotated.

Cross-service integration: RDS, Aurora, Redshift, DocumentDB, and ElastiCache have native retrieval integrations. ECS and EKS inject secrets as environment variables or mounted files with no application code change. Lambda retrieves secrets through the built-in extension, caching them in memory to reduce API call costs. Secrets can also be replicated across regions for disaster recovery, with the primary managed in one region and read replicas maintained automatically elsewhere.

Pricing: $0.40 per secret per month plus $0.05 per 10,000 API calls, unchanged as of September 2026. A deployment with 500 secrets and moderate retrieval costs roughly $200 per month in storage charges before API calls. That is not expensive in absolute terms, but it scales linearly with secret count, so model it before a migration that multiplies your secret inventory.

Honest weakness: Strong vendor lock-in. The integration architecture assumes AWS compute reading AWS-managed secrets through AWS IAM. Multi-cloud teams, on-premises workloads, and non-AWS CI/CD pipelines need extra configuration that often erases the simplicity advantage. The rotation model also differs from dynamic secrets in a way that matters to auditors. Rotating a static credential still leaves a window where the old credential is valid. A failed rotation can leave applications unable to retrieve the new value until someone intervenes.


3. Doppler

Best for: startup and growth-stage teams whose real barrier is developer adoption, not compliance.

Doppler optimizes for a different thing than Vault or the cloud-native services. Vault optimizes for security depth, AWS and Azure optimize for native integration, and Doppler optimizes for developers actually using it. The premise is that a tool developers adopt voluntarily beats an architecturally superior tool they route around.

The developer experience: Install the CLI, authenticate, run doppler run -- npm start, and the application receives its secrets as environment variables. No SDK changes, no policy authoring, no Kubernetes webhook configuration. The web dashboard shows secrets across projects and environments with change history, access logs, and team permissions, without exposing values to unauthorized users.

Universal sync: Doppler's main architectural capability is syncing secrets to downstream targets: AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, Kubernetes secrets, Vercel, Netlify, Fly.io, Railway, GitHub Actions, CircleCI, GitLab CI, and dozens more. That positions Doppler as a management layer above cloud-native stores rather than a replacement for them. One place to define secrets, one place to manage access, synchronized to whatever environments need them. When a production value changes, Doppler can restart connected services or fire webhooks so deployments do not run on stale configuration.

Project and environment organization: Secrets are organized into projects and environments with inheritance, so production can inherit a base config and override only what differs. Branch configs let a developer override specific values for feature work without touching shared environments.

Doppler Share and Secret Ops: Doppler Share sends an individual secret over a secure one-time link, which replaces the Slack-message habit. Secret Ops watches public repositories and alerts when monitored secrets appear in the open.

Pricing as of September 2026: the published plans are Developer, Team, and Enterprise. Developer is free for 3 users, then $8 per additional user per month, capped at 25 users, 10 projects, and 4 environments. Team is $21 per user per month and raises those caps to 500 users, 250 projects, and 15 environments. Enterprise is custom priced. Doppler prices per human seat and does not charge for AI agents and other non-human identities, which matters if your agent fleet is growing faster than your headcount. Note that these numbers are materially higher than the figures circulating in older comparisons, including earlier versions of this page.

Honest weakness: Doppler is cloud-only, with no self-hosted deployment. For data sovereignty requirements that prohibit cloud-hosted secrets, or regulated environments that require secrets never leave on-premises infrastructure, it is not viable. Dynamic secrets are listed only on the Enterprise plan, so teams on Developer or Team tiers are managing long-lived static credentials. Doppler is also closed source, which matters where software supply chain transparency is a requirement.


4. Infisical

Best for: organizations that need self-hosted secrets management with a permissive license and a modern interface.

Infisical is the open-source platform that emerged as the developer-experience-focused alternative to Vault, pairing a Doppler-style UI with genuine self-hosting. It has become the most credible open-source option for teams that need modern secrets management without Vault's operational demands or Doppler's cloud-only constraint.

Why Infisical instead of Vault: the comparison matters most for organizations that need self-hosted deployment but find Vault's policy engine and HCL configuration too demanding. Infisical provides a web UI, a CLI that follows the same injection pattern (infisical run -- your-command), and SDKs for Python, JavaScript, Go, Java, and Ruby. Self-hosting runs on Docker, Kubernetes, or bare metal, and needs PostgreSQL and Redis. Documentation is written for a capable DevOps engineer rather than a HashiCorp specialist.

Security architecture: Infisical encrypts secrets client-side before they leave the browser or client application, so the server stores ciphertext and decryption requires client-held keys. A complete server compromise does not expose plaintext. The platform keeps full version history for every secret with rollback and point-in-time recovery, and logs every access, modification, and rotation with user identity, timestamp, and source IP. Those audit capabilities cover the documentation requirements of most compliance frameworks, including SOC 2 Type 2, without additional tooling.

Dynamic secrets are no longer a gap: this is the biggest change since the last version of this guide. Infisical's published pricing now lists dynamic secrets, gateways, full secret rotation, and custom roles on the Advanced tier, not as roadmap items. Static rotation for PostgreSQL, MySQL, and other database providers remains available too. Infisical has also expanded beyond secrets into certificate management (internal CA, ACME-compatible external CA integration) and a separate privileged access product with access requests, approval workflows, SSH certificate authentication, and session recording.

CI/CD and Kubernetes: native integrations with GitHub Actions, GitLab CI, CircleCI, Jenkins, and ArgoCD cover most pipeline patterns. The Kubernetes operator syncs secrets into Kubernetes secret objects, and the agent sidecar injects them as files or environment variables with no application code change.

Pricing as of September 2026: the free tier covers 5 identities, unlimited projects, 3 environments, and 10 secret syncs. Pro is $20 per identity per month billed annually ($23 monthly) and adds SAML SSO, secret versioning, and point-in-time recovery. Advanced is $40 per identity per month billed annually ($46 monthly) and adds dynamic secrets. Enterprise is custom and adds LDAP, SCIM, user groups, approval workflows, and external KMS or HSM. Infisical bills per identity rather than per human seat, which is a meaningful cost difference from Doppler when machine identities outnumber people. The self-hosted community edition remains free under MIT.

Licensing advantage: the community edition is MIT licensed, which is genuinely open source, unlike Vault's BSL. For legal teams that scrutinize licensing, that is a decisive difference.

Honest weakness: Infisical is younger and less mature than Vault. The integration ecosystem, while growing quickly, is smaller. First-time deployers will find less community documentation and fewer experienced practitioners than the decade-old Vault ecosystem offers. Per-identity billing can also get expensive fast in a machine-heavy environment, which is exactly the environment the product targets, so model it against your actual identity count.


5. Azure Key Vault

Best for: Azure and Entra ID organizations, especially where HSM key custody is a compliance requirement.

Azure Key Vault fills the role for Azure workloads that Secrets Manager fills for AWS: tight identity integration through Entra ID, scheduled rotation, certificate management, and Hardware Security Module backing for cryptographic keys.

Three object types in one service: keys (cryptographic keys for encryption and signing), secrets (passwords, connection strings, API keys), and certificates (X.509 certificates with lifecycle management). Consolidating all three simplifies infrastructure for the many organizations that need all three.

Managed HSM: Azure Key Vault Managed HSM provides dedicated single-tenant FIPS 140-2 Level 3 validated hardware security modules. Keys never leave the HSM boundary in plaintext. Standard and Premium vault tiers offer software-protected and HSM-protected keys respectively. Where proving cryptographic key custody is a compliance requirement, hardware attestation is something software-based key storage cannot provide.

Entra ID integration: Access is controlled through Entra ID RBAC or Key Vault access policies. Azure workloads (VMs, App Service, Functions, AKS pods) authenticate using managed identities instead of credentials stored in application code, which solves the bootstrapping problem for Azure-hosted workloads. Key Vault references in App Service and Azure Functions let applications consume secrets through configuration syntax that resolves at runtime, with no code change. The broader identity vendor landscape keeps shifting through acquisitions and rebrands; the State of CIAM 2026 analysis tracks the ones worth watching.

Certificate management: Key Vault integrates with DigiCert and GlobalSign directly, and with other certificate authorities through manual import, to automate TLS certificate issuance, tracking, and renewal. For organizations managing many certificates across services, that automation prevents the expiration incidents that keep appearing in post-mortems.

Soft delete and purge protection: Deleted secrets are retained for a configurable 7 to 90 days before permanent deletion, and purge protection blocks permanent deletion even by administrators during that window. This is an underappreciated control against accidental or malicious secret deletion.

Pricing: Microsoft charges per 10,000 operations for secret and certificate operations, with additional monthly per-key fees for HSM-protected keys (billed only if the key was used in the prior 30 days) and hourly pool fees for Managed HSM. Certificate renewals carry higher fees than ordinary operations, and rates vary by region, so check the Azure Key Vault pricing page for your region rather than trusting a single global figure. For most applications operational cost is modest; high-throughput services should model API call volume.

Honest weakness: the same lock-in as AWS, specific to Azure. Key Vault does not generate dynamic database credentials, though Azure Database for PostgreSQL and MySQL support managed identity access as an alternative to credential-based authentication. Its access policy model is also less expressive than Vault's policy language for complex authorization scenarios. Local development, where Azure managed identities do not exist, needs extra configuration through service principals or Azure CLI credential providers.


Where Secrets Management Meets Privileged Access

The boundary between secrets management and privileged access management is dissolving, and 2026 consolidation is the reason. Three moves matter when you are drawing up a shortlist.

CyberArk is now part of Palo Alto Networks. The roughly $25 billion deal closed on February 11, 2026. CyberArk Conjur has been a common Vault competitor in enterprise secrets deals, and its roadmap now sits inside a platform strategy rather than a standalone identity company. If your shortlist includes Conjur, ask about product commitments in writing.

Delinea acquired StrongDM, completing on March 5, 2026, combining enterprise PAM with just-in-time runtime authorization. Delinea remains independent, which is now a differentiator in a market where the two largest identity security assets have been absorbed into platform vendors.

Infisical shipped a privileged access product alongside its secrets manager, approaching the same convergence from the open-source side.

Practically, this means the buying question is changing. It used to be "which tool stores our application secrets?" It is becoming "how do we grant every identity, human and machine, short-lived access at the moment of action?" Non-human identities now outnumber humans in most cloud estates and they need privileged access too. If your evaluation spans both, read the privileged access management comparison alongside this page, and the Delinea alternatives guide if Delinea is your incumbent. The secrets management category on the identity map tracks the vendor set as it moves.


The Dynamic Secrets Transition

The shift from static secrets to dynamic, short-lived credentials is the most significant architectural change in this market. Git-leaked secrets almost universally involve long-lived static credentials. A database password committed to a repository in 2022 and never rotated is still a valid attack vector today.

The gap between "we should rotate credentials regularly" and "we actually rotate credentials regularly" is where most secrets breaches originate. Dynamic secrets close it by making rotation automatic and continuous rather than manual and periodic.

Where the five tools stand as of September 2026:

Full dynamic secrets: HashiCorp Vault (most mature implementation, 20+ backends), OpenBao (inherits the same engines), and Infisical on the Advanced tier and above.

Rotation-based, not true dynamic: AWS Secrets Manager and Azure Key Vault. Credentials are static but rotated on a schedule. Better than no rotation, weaker than true dynamic.

Enterprise tier only: Doppler. Strong developer experience for static credentials, with dynamic secrets available only at the top plan.

For regulated industries where auditors ask how you ensure compromised credentials cannot be used after a certain period, dynamic secrets give a clear answer that scheduled rotation cannot fully match.

The connection to broader authentication architecture, including how zero-trust principles apply to workload identity, is covered in the passkeys at scale enterprise deployment playbook. For the distinction between workforce identity, customer identity, and identity as a service, see IAM vs CIAM.


Practical Decision Framework

Multi-cloud enterprise with compliance requirements and platform engineering capacity: HashiCorp Vault. It is the only option here with dynamic secrets across AWS, Azure, GCP, and on-premises databases from one platform. Budget for dedicated platform engineering or buy HCP Vault Dedicated to shift the operational burden, and get the quote before you commit.

AWS-native startup managing database credentials: AWS Secrets Manager. Automatic RDS rotation with no infrastructure to run, predictable cost, and IAM integration that reuses existing access control. Revisit only when multi-cloud requirements appear.

Azure-centric enterprise that needs HSM-backed key custody: Azure Key Vault with the Premium tier or Managed HSM. Entra ID managed identities remove the credential bootstrapping problem that complicates other deployment models.

Development team replacing .env files and hardcoded secrets: Doppler. Fastest time to value, and the developer experience drives voluntary adoption. Check the seat math at $21 per user per month before rolling out to a large engineering organization.

Self-hosting required and Vault complexity is too high: Infisical. MIT community edition, client-side encryption, modern UI, and dynamic secrets on the Advanced tier. Model per-identity billing against your machine identity count.

Self-hosting required and BSL is disqualifying: OpenBao. Vault semantics, Linux Foundation governance, MPL 2.0, no commercial restrictions. You take on the same operational burden as self-hosted Vault plus a smaller commercial support ecosystem.


Frequently Asked Questions

What is the difference between secrets management and password management?

Password managers such as 1Password and Bitwarden store human-accessible credentials: website logins, service accounts, and shared team passwords. Secrets managers store machine credentials: API keys, database passwords, TLS certificates, and encryption keys that applications retrieve programmatically. Password managers optimize for human workflows (UI, mobile apps, autofill); secrets managers optimize for machine workflows (API access, runtime injection, automatic rotation). Most enterprises need both. For the human side, see the 2026 password manager comparison and the credential management guide.

Should I use a secrets manager or just encrypt environment variables?

A dedicated secrets manager gives you audit logging, access control, automatic rotation, and centralized management that encrypted environment variables cannot. Environment variables stored in CI/CD platforms or container orchestrators are usually readable by anyone with deployment access, have no rotation mechanism, and leave no audit trail. The setup investment pays off as soon as you have more than a handful of secrets or more than one person with deploy rights.

What does "secrets sprawl" mean and why is it a problem?

Secrets sprawl is the accumulation of application credentials across disconnected locations: .env files in repositories, CI/CD environment variables, container orchestration configs, developer laptops, Slack messages, shared documents, and inconsistently used vaults. When a secret exists in many places with no central tracking, rotating a compromised credential means finding and updating every copy. That makes rotation impractical and audit impossible, which is why credential-leak breaches often persist for a long time before detection. A centralized manager fixes it by making the vault the only legitimate source.

How do applications retrieve secrets without storing credentials for the vault itself?

This is the bootstrapping problem, and the answer is platform identity. Cloud provider managed identities (AWS IAM roles for EC2 and Lambda, Azure managed identities, GCP service accounts) authenticate to the secrets manager with no static credential. In Kubernetes, pod service account tokens do the same. For local development, developer CLI authentication issues short-lived tokens at login. The principle is that the identity used to reach the vault should be dynamic and platform-managed, never a static password.

What happens if my secrets management platform goes down?

Applications should cache secrets locally with a configurable TTL so a brief outage does not cause an incident. Self-hosted Vault, OpenBao, and Infisical need high-availability configuration (multiple nodes, shared or replicated storage) before production. SaaS options such as Doppler, AWS Secrets Manager, and Azure Key Vault provide managed availability with published SLAs. Whatever the platform, never hard-code a fallback secret in application code; that reintroduces exactly the risk the vault was meant to remove.

How often should secrets be rotated?

For dynamic secrets, rotation is continuous and automatic, typically on a 1 to 24 hour TTL. For static secrets on a schedule, 90 days is the common maximum for high-value credentials, tightening to 30 days for anything with direct external access. For long-standing API keys, annual rotation is the floor, quarterly where the provider supports automation. The practical answer is "as often as your tooling makes automatic" rather than "as often as your policy specifies." Automated rotation every 24 hours beats a manual 90-day policy that slips.

What should we do about secrets already committed to Git repositories?

Assume they are compromised and rotate immediately. GitHub secret scanning alerts on known credential patterns in public repositories, with similar scanning available for private ones. GitGuardian, TruffleHog, and GitHub Advanced Security scan full commit history for secrets patterns. Rotation is necessary even for secrets committed years ago to private repositories, because private-to-public migrations, leaked repository access tokens, and employee departures create exposure windows that are hard to reconstruct later. The Ghost CMS SQL injection incident shows what happens when exposed credentials meet unpatched infrastructure.

Is Infisical production-ready for enterprise use?

Yes, with caveats. Infisical ships SSO, SCIM, audit logs, IP allowlisting, approval workflows, and external KMS or HSM support on its upper tiers, and dynamic secrets are now generally available rather than a roadmap promise. It is younger than Vault, so the integration ecosystem is smaller and the community knowledge base is thinner. For organizations prioritizing open source, self-hosting, and developer experience, it is a reasonable primary choice. For the deepest dynamic secrets coverage or HSM-backed key custody, Vault or the cloud-native services still lead.


Final Take

The market has matured to the point where there is no excuse for .env files in production. Every engineering team has a viable option at its size and budget.

Small teams with no compliance requirements and limited DevOps capacity should start with Doppler. The five-minute setup and injection model produces immediate improvement over .env files with no operational overhead.

Teams on AWS or Azure should start with the native managed service. Integrated rotation, IAM-based access control, and zero infrastructure to run make Secrets Manager and Key Vault the obvious starting points for single-cloud organizations.

Organizations with multi-cloud infrastructure, compliance requirements, or a genuine need for dynamic secrets should invest in Vault, with HCP Vault Dedicated if they want to avoid cluster management. Get the IBM-era quote and the support commitments in writing before signing.

Teams that want self-hosted deployment with a modern developer experience should evaluate Infisical, and teams for whom the Business Source License is disqualifying should evaluate OpenBao.

The one approach with no defender is leaving credentials in .env files, CI/CD environment variables, or application code. For the broader DevSecOps picture, including how secrets management connects to code scanning and IaC security, see the open source security tools guide and the DevOps tech stack guide.


Published March 2026, last verified September 2026. IBM completed its acquisition of HashiCorp on February 27, 2025, and Vault moved to IBM release and support cycles with version 2.0 in April 2026. Doppler and Infisical both repriced since the previous version of this guide. Verify current licensing and pricing with each vendor before making procurement decisions.

Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:

Get the newsletter

New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.

Tell us what you read most (optional)