# Alternatives to CyberArk Conjur

Conjur is CyberArk open-source secrets management solution for securing machine identities and secrets in DevOps pipelines and cloud-native applications.

CyberArk Conjur ranks #3 of 7 in Secrets management, with an Alt Score of 89. It is licensed under LGPL-3.0, open source with paid hosting from Free and available on the web. 12 of 13 checklist rows are verified against a public source.

Source: https://altcatalog.com/alternatives/cyberark-conjur/
Category: Secrets management

## Where CyberArk Conjur stands out

- **Open source** — 3 of 7 apps with a verified answer have this

## Overview

- **Who it's for**: CyberArk Conjur is built for DevOps, platform, and security teams who need to remove hard-coded credentials from applications, scripts, containers, and CI/CD pipelines across cloud-native and hybrid infrastructure.
- **What you get**: A free, open-source (LGPL-3.0) secrets management server with a policy-as-code RBAC model, automatic secret rotation, a REST API, CLI, and client libraries, plus native integrations for Kubernetes/OpenShift, Jenkins, Ansible, and other DevOps tooling; a commercial self-hosted or SaaS edition (now branded Secrets Manager under CyberArk/Idira, following Palo Alto Networks' February 2026 acquisition of CyberArk) adds dynamic secrets and enterprise support.
- **How it works**: Secrets and access rules are declared as YAML policy files loaded into the Conjur server, which authenticates workloads (via API key, Kubernetes service account, JWT, or client certificate) and grants secret access based on role-based permissions; a rotation engine periodically regenerates credentials on both Conjur and the target system, and sidecar/init-container Secrets Providers sync those secrets into platforms like Kubernetes Secrets.

## Profile

- **License**: LGPL-3.0 (verified 2026-07-17)
- **Pricing model**: OSS + paid hosting (verified 2026-07-17)
- **Starts at**: Free (verified 2026-07-17)
- **Platforms**: Web
- **Status**: acquired (verified 2026-07-17)

## Ranked alternatives

| # | App | Alt Score | Licence | Platforms |
|---|-----|-----------|---------|-----------|
| 1 | [Infisical](https://altcatalog.com/alternatives/infisical.md) | 100 | MIT | Web |
| 2 | [HashiCorp Vault](https://altcatalog.com/alternatives/hashicorp-vault.md) | 93 | BUSL-1.1 | Web |
| 3 | [Akeyless](https://altcatalog.com/alternatives/akeyless.md) | 86 | Proprietary | ? |
| 4 | [Doppler](https://altcatalog.com/alternatives/doppler.md) | 79 | Proprietary | Web |
| 5 | [Bitwarden Secrets Manager](https://altcatalog.com/alternatives/bitwarden-secrets-manager.md) | 76 | AGPL-3.0 (server core); some parts under Bitwarden License v1.0 & the Bitwarden SDK License | Web |
| 6 | [1Password Secrets Automation](https://altcatalog.com/alternatives/1password-secrets.md) | 68 | Proprietary (platform); Go/JS/Python SDKs & CLI shell-plugins are MIT | Web |

Alt Score = Verified coverage (90%) + Visibility (10%). See https://altcatalog.com/how-alt-score-works/

## Feature comparison

Legend: Yes / No / Partial / ? (not verified).

| Secrets management checklist | CyberArk Conjur | Infisical | HashiCorp Vault | Akeyless | Doppler | Bitwarden Secrets Manager |
|---|---|---|---|---|---|---|
| Pricing model | OSS + paid hosting | OSS + paid hosting | OSS + paid hosting | Freemium | Freemium | Freemium |
| Starts at | Free | $18/month per identity | ? | Free | $21/mo per user (Team plan) | $6/mo per user (Teams plan) |
| License | LGPL-3.0 | MIT | BUSL-1.1 | Proprietary | Proprietary | AGPL-3.0 (server core); some parts under Bitwarden License v1.0 & the Bitwarden SDK License |
| Platforms | Web | Web | Web | ? | Web | Web |
| Open source | Yes | Yes | Partial | No | No | Yes |
| Self-hostable | Yes | Yes | Yes | Partial | Yes | Yes |
| Managed / SaaS option | Yes | Yes | Yes | Yes | Yes | Yes |
| Dynamic secrets | Yes | Yes | Yes | Yes | Yes | No |
| Secret rotation | Yes | Yes | Yes | Yes | Yes | Partial |
| Secret scanning / leak detection | ? | Yes | Partial | Partial | No | ? |
| Kubernetes integration | Yes | Yes | Yes | Yes | Yes | Yes |
| CI/CD integrations | Yes | Yes | Yes | Yes | Yes | Yes |
| CLI | Yes | Yes | Yes | Yes | Yes | Yes |
| Audit logs | Yes | Yes | Yes | Yes | Yes | Yes |
| RBAC / fine-grained access | Yes | Yes | Yes | Yes | Yes | Yes |
| PKI / certificate management | Partial | Yes | Yes | Yes | No | No |
| SDKs & API | Yes | Yes | Yes | Yes | Yes | Yes |

## Sources

Sources for CyberArk Conjur. Each alternative is sourced on its own page.

- **License**: LGPL-3.0 — <https://raw.githubusercontent.com/cyberark/conjur/master/LICENSE.md> (verified 2026-07-17)
  - Note: Conjur OSS server code (this repo) is licensed under LGPL-3.0. README.md confirms: "The Conjur server (as in, the code within this repository) is licensed under the Free Software Foundation's GNU LGPL
  - Quote: “GNU Lesser General Public License ... Version 3, 29 June 2007”
- **Pricing model**: OSS + paid hosting — <https://www.cyberark.com/products/secrets-manager-self-hosted/> (verified 2026-07-17)
  - Note: Conjur Open Source (this GitHub project, conjur.org) is free/LGPL-3.0. The commercial successor products - Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Secrets Manager, SaaS (formerly
  - Quote: “Conjur Secrets Manager Enterprise is now Secrets Manager, Self-Hosted.”
- **Starts at**: Free — <https://www.cyberark.com/products/secrets-manager-self-hosted/> (verified 2026-07-17)
  - Note: Conjur Open Source is free to self-host. No public pricing is disclosed for the paid Secrets Manager Self-Hosted/SaaS tiers; the CyberArk product page only offers "Request a Demo", i.e. contact-sales.
  - Quote: “Request a Demo”
- **Platforms**: Web — <https://docs.cyberark.com/secrets-manager-saas/latest/en/content/conjurcloud/cl_conjurcloudoverview.htm> (verified 2026-07-17)
  - Note: Conjur is a server/API product: self-hosted via Docker containers (README: "Conjur is designed to run in a Docker container(s)") plus a SaaS offering. Accessed via REST API/CLI/web console rather than
  - Quote: “Secrets Manager - SaaS is a SaaS-based cloud-agnostic solution for secrets management.”
- **Status**: acquired — <https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era> (verified 2026-07-17)
  - Note: Acquisition completed Feb 11, 2026. CyberArk's product line was rebranded to "Idira" in May 2026 (docs.cyberark.com now shows "Idira Docs" branding and Conjur Cloud is renamed Secrets Manager SaaS). T
  - Quote: “Palo Alto Networks (NASDAQ: PANW), the global cybersecurity leader, today announced the completion of its acquisition of CyberArk, establishing Identity Security as a core pillar of its platformizatio”
- **Open source**: Yes — <https://raw.githubusercontent.com/cyberark/conjur/master/README.md> (verified 2026-07-17)
  - Quote: “The Conjur server (as in, the code within this repository) is licensed under the Free Software Foundation's GNU LGPL v3.0.”
- **Self-hostable**: Yes — <https://raw.githubusercontent.com/cyberark/conjur/master/README.md> (verified 2026-07-17)
  - Quote: “Conjur is designed to run in a Docker container(s), using PostgreSQL as the backing data store.”
- **Managed / SaaS option**: Yes — <https://docs.cyberark.com/secrets-manager-saas/latest/en/content/conjurcloud/cl_conjurcloudoverview.htm> (verified 2026-07-17)
  - Note: This SaaS product was formerly branded "Conjur Cloud"; the docs page itself notes: "Conjur Cloud Secrets Manager is now Idira Secrets Manager, SaaS."
  - Quote: “Secrets Manager - SaaS is a SaaS-based cloud-agnostic solution for secrets management.”
- **Dynamic secrets**: Yes — <https://docs.cyberark.com/secrets-manager-sh/latest/en/content/operations/dynamic-secrets-aws.htm> (verified 2026-07-17)
  - Note: Dynamic secrets (e.g. AWS secrets engine) are documented for Secrets Manager Self-Hosted and Secrets Manager SaaS (paid tiers). This page returns 404 under the conjur-open-source docs path, so it appe
  - Quote: “The AWS secrets engine generates AWS access credentials dynamically based on IAM policies. These secrets are generated just in time (JIT), on demand and are short-lived, which follows the principle of”
- **Secret rotation**: Yes — <https://docs.cyberark.com/conjur-open-source/latest/en/content/operations/services/rotation-secrets.html> (verified 2026-07-17)
  - Quote: “The Conjur rotation feature meets this requirement by automatically generating and rotating the secrets used to access an underlying system.”
- **Kubernetes integration**: Yes — <https://docs.cyberark.com/conjur-open-source/latest/en/content/integrations/k8s-ocp/cjr-k8s-secrets-provider-ic.htm> (verified 2026-07-17)
  - Quote: “This topic describes how to set up Secrets Provider for Kubernetes as an init container or sidecar, cyberark-secrets-provider-for-k8s, to populate Kubernetes Secrets with secrets stored in Conjur.”
- **CI/CD integrations**: Yes — <https://docs.cyberark.com/conjur-open-source/latest/en/content/integrations/jenkins.htm> (verified 2026-07-17)
  - Note: Conjur OSS also ships an Ansible integration (docs.cyberark.com/conjur-open-source/.../integrations/ansible.html) and its GitHub README lists CI/CD tools (Ansible, Jenkins, Puppet, Terraform) among th
  - Quote: “The Conjur Secrets plugin enables Jenkins to authenticate to Conjur and retrieve secrets for use in Jenkins pipeline code or Freestyle projects.”
- **CLI**: Yes — <https://docs.cyberark.com/conjur-open-source/latest/en/content/developer/cli/cli-setup.htm> (verified 2026-07-17)
  - Quote: “The Secrets Manager CLI implements the Conjur REST API, providing an alternate interface for managing Conjur resources, including roles, privileges, policy, and secrets.”
- **Audit logs**: Yes — <https://raw.githubusercontent.com/cyberark/conjur/master/CHANGELOG.md> (verified 2026-07-17)
  - Note: Audit logging is core to the OSS server itself (app/models/audit.rb and app/models/audit/ in the cyberark/conjur repo); the CHANGELOG documents ongoing additions of audit events across API endpoints.
  - Quote: “Password changes (`PUT /authn/:account/password`) now produce audit events with message ID `password`.”
- **RBAC / fine-grained access**: Yes — <https://docs.cyberark.com/conjur-open-source/latest/en/content/operations/policy/policy-basic-concepts.htm> (verified 2026-07-17)
  - Quote: “Conjur implements role-based access control (RBAC) to provide role management and permission checking.”
- **PKI / certificate management**: Partial — <https://raw.githubusercontent.com/cyberark/conjur/master/CERTIFICATE_AUTH.md> (verified 2026-07-17)
  - Note: Conjur supports certificate-based authentication (creating/using a root CA to authenticate workloads) and can store/rotate TLS certificates as secrets, but full PKI certificate-authority issuance inte
  - Quote: “This guide describes how to create, configure, and use a Certificate Authenticator in Conjur Secrets Manager, including secret retrieval.”
- **SDKs & API**: Yes — <https://docs.cyberark.com/conjur-open-source/latest/en/content/developer/lp_api_opensource.htm> (verified 2026-07-17)
  - Quote: “We provide the following API libraries to help integrate Conjur into your development environments.”

---
Ranked by verified data, never by who paid. https://altcatalog.com/trust/