# Alternatives to Akeyless

Akeyless is a SaaS platform for secrets management, dynamic secrets, encryption, and machine identity, built on a distributed fragments cryptography model.

Akeyless ranks #4 of 7 in Secrets management, with an Alt Score of 86. It is proprietary and freemium from Free. 13 of 13 checklist rows are verified against a public source.

Source: https://altcatalog.com/alternatives/akeyless/
Category: Secrets management

## Where Akeyless stands out

- **PKI / certificate management** — 3 of 7 apps with a verified answer have this

## Overview

- **Who it's for**: DevOps, platform, and security teams that need to manage secrets, encryption keys, and certificates for machines, AI agents, and humans across multi-cloud and hybrid environments, without operating their own vault infrastructure.
- **What you get**: A SaaS secrets management and machine-identity platform offering static, dynamic, and rotated secrets, encryption/KMS, PKI and SSH certificate lifecycle management, RBAC, and audit logging, all reachable through a web console, CLI, REST API, and SDKs (Go, Python, Java, JavaScript, C#, Ruby). A free tier is available with limited quotas; broader usage requires a custom-quoted Enterprise plan.
- **How it works**: Applications and users authenticate to the Akeyless SaaS control plane (built on Distributed Fragments Cryptography for zero-knowledge key management) directly or through a customer-deployed Gateway component that brokers requests from internal workloads to Akeyless services, enabling secrets and certificates to be issued, rotated, or retrieved on demand via CLI, API, or native integrations with Kubernetes, CI/CD tools, and cloud providers.

## Profile

- **License**: Proprietary (verified 2026-07-17)
- **Pricing model**: Freemium (verified 2026-07-17)
- **Starts at**: Free (verified 2026-07-17)
- **Platforms**: ?
- **Status**: active (verified 2026-07-17)

## Ranked alternatives

| # | App | Alt Score | Licence | Platforms |
|---|-----|-----------|---------|-----------|
| 1 | [Infisical](https://altcatalog.com/alternatives/infisical.md) | 100 | MIT | Web |
| 2 | [HashiCorp Vault](https://altcatalog.com/alternatives/hashicorp-vault.md) | 93 | BUSL-1.1 | Web |
| 3 | [CyberArk Conjur](https://altcatalog.com/alternatives/cyberark-conjur.md) | 89 | LGPL-3.0 | Web |
| 4 | [Doppler](https://altcatalog.com/alternatives/doppler.md) | 79 | Proprietary | Web |
| 5 | [Bitwarden Secrets Manager](https://altcatalog.com/alternatives/bitwarden-secrets-manager.md) | 76 | AGPL-3.0 (server core); some parts under Bitwarden License v1.0 & the Bitwarden SDK License | Web |
| 6 | [1Password Secrets Automation](https://altcatalog.com/alternatives/1password-secrets.md) | 68 | Proprietary (platform); Go/JS/Python SDKs & CLI shell-plugins are MIT | Web |

Alt Score = Verified coverage (90%) + Visibility (10%). See https://altcatalog.com/how-alt-score-works/

## Feature comparison

Legend: Yes / No / Partial / ? (not verified).

| Secrets management checklist | Akeyless | Infisical | HashiCorp Vault | CyberArk Conjur | Doppler | Bitwarden Secrets Manager |
|---|---|---|---|---|---|---|
| Pricing model | Freemium | OSS + paid hosting | OSS + paid hosting | OSS + paid hosting | Freemium | Freemium |
| Starts at | Free | $18/month per identity | ? | Free | $21/mo per user (Team plan) | $6/mo per user (Teams plan) |
| License | Proprietary | MIT | BUSL-1.1 | LGPL-3.0 | Proprietary | AGPL-3.0 (server core); some parts under Bitwarden License v1.0 & the Bitwarden SDK License |
| Platforms | ? | Web | Web | Web | Web | Web |
| Open source | No | Yes | Partial | Yes | No | Yes |
| Self-hostable | Partial | Yes | Yes | Yes | Yes | Yes |
| Managed / SaaS option | Yes | Yes | Yes | Yes | Yes | Yes |
| Dynamic secrets | Yes | Yes | Yes | Yes | Yes | No |
| Secret rotation | Yes | Yes | Yes | Yes | Yes | Partial |
| Secret scanning / leak detection | Partial | Yes | Partial | ? | No | ? |
| Kubernetes integration | Yes | Yes | Yes | Yes | Yes | Yes |
| CI/CD integrations | Yes | Yes | Yes | Yes | Yes | Yes |
| CLI | Yes | Yes | Yes | Yes | Yes | Yes |
| Audit logs | Yes | Yes | Yes | Yes | Yes | Yes |
| RBAC / fine-grained access | Yes | Yes | Yes | Yes | Yes | Yes |
| PKI / certificate management | Yes | Yes | Yes | Partial | No | No |
| SDKs & API | Yes | Yes | Yes | Yes | Yes | Yes |

## Sources

Sources for Akeyless. Each alternative is sourced on its own page.

- **License**: Proprietary — <https://www.akeyless.io/end-user-license-agreement-2025/> (verified 2026-07-17)
  - Note: SaaS platform licensed under a commercial EULA, not open source.
  - Quote: “Akeyless hereby grants you a non-exclusive, non-transferable (except as otherwise permitted herein) right to access and use the Service during the Term, solely in accordance with this Agreement, Docum”
- **Pricing model**: Freemium — <https://www.akeyless.io/pricing/> (verified 2026-07-17)
  - Note: Plan Limits table shows a FREE tier alongside a custom-quoted ENTERPRISE tier.
  - Quote: “Start free or customize an enterprise solution tailored to your needs.”
- **Starts at**: Free — <https://www.akeyless.io/pricing/> (verified 2026-07-17)
  - Note: Paid tier is labeled ENTERPRISE and priced only via 'Talk to an expert' (custom quote); no public paid starting price is disclosed on the pricing page.
  - Quote: “Start Free”
- **Status**: active — <https://www.akeyless.io/pricing/> (verified 2026-07-17)
  - Note: Site sitemap shows page updates as recent as 2026-07-16 and docs actively cover in-development early-access features, indicating active development.
  - Quote: “© 2026 AKEYLESS. All rights reserved”
- **Open source**: No — <https://www.akeyless.io/end-user-license-agreement-2025/> (verified 2026-07-17)
  - Note: Proprietary closed-source SaaS platform.
  - Quote: “Akeyless or its licensors retain all ownership and intellectual property rights to the Akeyless Proprietary, and derivative works thereof”
- **Self-hostable**: Partial — <https://docs.akeyless.io/docs/gateway-overview.md> (verified 2026-07-17)
  - Note: Only the Gateway data-path component can be deployed in the customer's own infrastructure (Docker, Kubernetes, serverless); the core control plane/vault remains Akeyless-hosted SaaS, so the full platf
  - Quote: “Akeyless Gateway is a customer-hosted runtime component that sits between internal workloads and the Akeyless SaaS.”
- **Managed / SaaS option**: Yes — <https://www.akeyless.io/pricing/> (verified 2026-07-17)
  - Note: Akeyless is SaaS-first.
  - Quote: “Pure SaaS delivers the simplicity and scalability of a fully cloud-managed solution for rapid deployment and minimal operational overhead.”
- **Dynamic secrets**: Yes — <https://docs.akeyless.io/docs/how-to-create-dynamic-secret.md> (verified 2026-07-17)
  - Quote: “Dynamic Secrets are secrets that are generated every time they are accessed, using permissions you've defined in advance.”
- **Secret rotation**: Yes — <https://docs.akeyless.io/docs/rotated-secrets.md> (verified 2026-07-17)
  - Quote: “You can define a rotated secret to automatically update the password at defined intervals, or manually trigger a password update with the CLI or from the Akeyless Console.”
- **Secret scanning / leak detection**: Partial — <https://docs.akeyless.io/docs/identity-and-secrets-intelligence.md> (verified 2026-07-17)
  - Note: Cloud secret-exposure scanning exists but is early access and currently limited to GCP/AWS cloud environments, not general source-code/repo secret scanning.
  - Quote: “Identity and Secrets Intelligence is currently in early access. ... Current early-access scanner coverage includes: GCP Scanner support ... AWS Scanner support for cloud identities”
- **Kubernetes integration**: Yes — <https://docs.akeyless.io/docs/gateway-deploy-kubernetes-helm.md> (verified 2026-07-17)
  - Note: Also has External Secrets Operator support, Kubernetes Secrets Store CSI Driver, Cert Manager, and a Kubernetes Secrets Injector (see docs.akeyless.io llms.txt integrations list).
  - Quote: “Kubernetes with Helm Deployment”
- **CI/CD integrations**: Yes — <https://docs.akeyless.io/docs/github-action.md> (verified 2026-07-17)
  - Note: Also has Jenkins, GitLab, CircleCI, Azure DevOps, and TeamCity plugins per docs.akeyless.io integrations.
  - Quote: “The Akeyless GitHub Actions plugin enables workflow automation for GitHub-hosted repositories.”
- **CLI**: Yes — <https://docs.akeyless.io/docs/cli.md> (verified 2026-07-17)
  - Quote: “The Akeyless CLI has pre-compiled binary versions for Linux, macOS, and Windows that can be installed locally.”
- **Audit logs**: Yes — <https://docs.akeyless.io/docs/audit-logs.md> (verified 2026-07-17)
  - Quote: “Akeyless Audit Logs take note of just about every change/action within the Akeyless system, providing a complete track record of your Akeyless system operations.”
- **RBAC / fine-grained access**: Yes — <https://docs.akeyless.io/docs/rbac.md> (verified 2026-07-17)
  - Quote: “Akeyless Role-Based Access Control (RBAC) follows the least privilege principle to limit access rights for machines/human users to the bare minimum of permissions they need to perform their work.”
- **PKI / certificate management**: Yes — <https://docs.akeyless.io/docs/certificate-lifecycle-management.md> (verified 2026-07-17)
  - Quote: “Akeyless Certificate Lifecycle Management (CLM) solution provides a seamless way to create, provision, monitor, renew, and revoke digital certificates.”
- **SDKs & API**: Yes — <https://docs.akeyless.io/docs/sdks.md> (verified 2026-07-17)
  - Quote: “We currently support the following SDKs: C# .NET Core SDK, Go SDK, Java SDK, JavaScript SDK, Python SDK, Ruby SDK”

---
Ranked by verified data, never by who paid. https://altcatalog.com/trust/