# Alternatives to HashiCorp Vault

HashiCorp Vault is a platform for secrets management, encryption as a service, dynamic secrets, and PKI, with fine-grained access control and audit logging; self-hosted or HCP Vault cloud.

HashiCorp Vault ranks #2 of 7 in Secrets management, with an Alt Score of 93. It is licensed under BUSL-1.1, open source with paid hosting and available on the web. 13 of 13 checklist rows are verified against a public source.

Source: https://altcatalog.com/alternatives/hashicorp-vault/
Category: Secrets management

## Where HashiCorp Vault stands out

- **PKI / certificate management** — 3 of 7 apps with a verified answer have this

## Overview

- **Who it's for**: HashiCorp Vault is for platform, security, and DevOps teams that need to centrally store, control access to, and audit secrets (API keys, passwords, certificates, database credentials) across applications, infrastructure, and Kubernetes clusters, from individual developers running it locally to large enterprises deploying it at scale.
- **What you get**: Vault provides encrypted secret storage, on-demand dynamic secrets and credential rotation for systems like AWS and SQL databases, a PKI engine for X.509 certificate issuance, fine-grained path-based access policies, detailed audit logging, a CLI and full HTTP API with official client libraries, and native Kubernetes integrations (Vault Agent Injector, CSI provider, Vault Secrets Operator); it is offered as a free self-hosted binary, paid self-managed Vault Enterprise, or fully managed HCP Vault Dedicated in the cloud.
- **How it works**: Teams deploy a Vault server (self-hosted or via HCP Vault Dedicated), configure secrets engines and authentication methods, and define policies that grant or deny access to specific secret paths; applications and users then authenticate to Vault and read, generate, or rotate secrets on demand via the CLI, API, or Kubernetes integrations, with every request logged through Vault's audit devices.

## Profile

- **License**: BUSL-1.1 (verified 2026-07-17)
- **Pricing model**: OSS + paid hosting (verified 2026-07-17)
- **Starts at**: ?
- **Platforms**: Web
- **Status**: acquired (verified 2026-07-17)

## Ranked alternatives

| # | App | Alt Score | Licence | Platforms |
|---|-----|-----------|---------|-----------|
| 1 | [Infisical](https://altcatalog.com/alternatives/infisical.md) | 100 | MIT | Web |
| 2 | [CyberArk Conjur](https://altcatalog.com/alternatives/cyberark-conjur.md) | 89 | LGPL-3.0 | Web |
| 3 | [Akeyless](https://altcatalog.com/alternatives/akeyless.md) | 86 | Proprietary | ? |
| 4 | [Doppler](https://altcatalog.com/alternatives/doppler.md) | 79 | Proprietary | Web |
| 5 | [Bitwarden Secrets Manager](https://altcatalog.com/alternatives/bitwarden-secrets-manager.md) | 76 | AGPL-3.0 (server core); some parts under Bitwarden License v1.0 & the Bitwarden SDK License | Web |
| 6 | [1Password Secrets Automation](https://altcatalog.com/alternatives/1password-secrets.md) | 68 | Proprietary (platform); Go/JS/Python SDKs & CLI shell-plugins are MIT | Web |

Alt Score = Verified coverage (90%) + Visibility (10%). See https://altcatalog.com/how-alt-score-works/

## Feature comparison

Legend: Yes / No / Partial / ? (not verified).

| Secrets management checklist | HashiCorp Vault | Infisical | CyberArk Conjur | Akeyless | Doppler | Bitwarden Secrets Manager |
|---|---|---|---|---|---|---|
| Pricing model | OSS + paid hosting | OSS + paid hosting | OSS + paid hosting | Freemium | Freemium | Freemium |
| Starts at | ? | $18/month per identity | Free | Free | $21/mo per user (Team plan) | $6/mo per user (Teams plan) |
| License | BUSL-1.1 | MIT | LGPL-3.0 | Proprietary | Proprietary | AGPL-3.0 (server core); some parts under Bitwarden License v1.0 & the Bitwarden SDK License |
| Platforms | Web | Web | Web | ? | Web | Web |
| Open source | Partial | Yes | Yes | No | No | Yes |
| Self-hostable | Yes | Yes | Yes | Partial | Yes | Yes |
| Managed / SaaS option | Yes | Yes | Yes | Yes | Yes | Yes |
| Dynamic secrets | Yes | Yes | Yes | Yes | Yes | No |
| Secret rotation | Yes | Yes | Yes | Yes | Yes | Partial |
| Secret scanning / leak detection | Partial | Yes | ? | Partial | No | ? |
| Kubernetes integration | Yes | Yes | Yes | Yes | Yes | Yes |
| CI/CD integrations | Yes | Yes | Yes | Yes | Yes | Yes |
| CLI | Yes | Yes | Yes | Yes | Yes | Yes |
| Audit logs | Yes | Yes | Yes | Yes | Yes | Yes |
| RBAC / fine-grained access | Yes | Yes | Yes | Yes | Yes | Yes |
| PKI / certificate management | Yes | Yes | Partial | Yes | No | No |
| SDKs & API | Yes | Yes | Yes | Yes | Yes | Yes |

## Sources

Sources for HashiCorp Vault. Each alternative is sourced on its own page.

- **License**: BUSL-1.1 — <https://raw.githubusercontent.com/hashicorp/vault/main/LICENSE> (verified 2026-07-17)
  - Note: Vault relicensed from MPL-2.0 to the Business Source License (BUSL-1.1) in Aug 2023, effective for Vault 1.15.0+. The LICENSE file names 'International Business Machines Corporation (IBM)' as Licensor
  - Quote: “Notice

Business Source License 1.1”
- **Pricing model**: OSS + paid hosting — <https://developer.hashicorp.com/hcp/docs/vault/get-started/deployment-considerations/tiers-and-features> (verified 2026-07-17)
  - Note: Vault ships as a free, source-available (BUSL-1.1, not OSI OSS) self-hosted binary/Community Edition, plus paid Vault Enterprise (self-managed) and paid HCP Vault Dedicated (managed cloud, hourly pay-
  - Quote: “HCP Vault Dedicated currently has trial, pay-as-you-go and contract based pricing options.”
- **Platforms**: Web — <https://developer.hashicorp.com/vault/install> (verified 2026-07-17)
  - Note: os":"darwin"},{"label":"Ubuntu/Debian"" — HCP Vault Dedicated/HCP Vault Secrets are accessed via the web-based HCP Portal ("Web"). Vault itself is also self-hosted software: the official install page offers binaries/packages for macOS (darwin
- **Status**: acquired — <https://raw.githubusercontent.com/hashicorp/vault/main/LICENSE> (verified 2026-07-17)
  - Note: HashiCorp (and Vault) is now owned by IBM, per the current LICENSE naming IBM as Licensor and copyright holder. Vault remains actively developed as a standalone product: GitHub releases show v2.0.0 (2
  - Quote: “Licensor:             International Business Machines Corporation (IBM)
Licensed Work:        Vault Version 1.15.0 or later. The Licensed Work is (c) 2024
                      IBM Corp.”
- **Open source**: Partial — <https://raw.githubusercontent.com/hashicorp/vault/main/LICENSE> (verified 2026-07-17)
  - Note: Vault's current LICENSE is BUSL-1.1, a source-available license that is NOT OSI-approved open source (it restricts competitive hosted/embedded offerings until a 4-year Change Date, after which it conv
  - Quote: “Notice

Business Source License 1.1”
- **Self-hostable**: Yes — <https://developer.hashicorp.com/vault/install> (verified 2026-07-17)
  - Note: os":"darwin"},{"label":"Ubuntu/Debian"" — Official install page provides Vault binaries/packages for macOS, Windows, Linux (Ubuntu/Debian, CentOS/RHEL, Fedora, Amazon Linux), and FreeBSD for self-hosted deployment.
- **Managed / SaaS option**: Yes — <https://developer.hashicorp.com/hcp/docs/vault/what-is-hcp-vault> (verified 2026-07-17)
  - Note: HCP Vault Dedicated is HashiCorp's fully managed cloud offering (HashiCorp Cloud Platform).
  - Quote: “HCP Vault Dedicated is a hosted version of Vault Enterprise operated by Hashicorp on your behalf.”
- **Dynamic secrets**: Yes — <https://raw.githubusercontent.com/hashicorp/vault/main/README.md> (verified 2026-07-17)
  - Note: Dynamic secrets are Vault's signature feature.
  - Quote: “Dynamic Secrets: Vault can generate secrets on-demand for some
  systems, such as AWS or SQL databases.”
- **Secret rotation**: Yes — <https://developer.hashicorp.com/vault/docs/secrets/databases> (verified 2026-07-17)
  - Note: Automatic rotation applies to static roles (e.g. database credentials); dynamic secrets are generated on-demand and revoked at lease expiry rather than 'rotated' in place.
  - Quote: “With static roles, Vault stores and automatically rotates passwords for the associated database user based on a configurable period of time or rotation schedule.”
- **Secret scanning / leak detection**: Partial — <https://hashicorp.com/en/products/vault/hcp-vault-radar> (verified 2026-07-17)
  - Note: Core Vault (the secrets engine/vault itself) does not scan external repos for leaked secrets. Repo/code secret scanning and leak detection is provided by a separate, related HashiCorp product, HCP Vau
  - Quote: “Discover, prioritize, and remediate unmanaged and leaked secrets across your development ecosystem.”
- **Kubernetes integration**: Yes — <https://developer.hashicorp.com/vault/docs/platform/k8s> (verified 2026-07-17)
  - Note: Multiple official Kubernetes integrations: Vault Secrets Operator, Vault CSI provider, and Vault Agent Injector.
  - Quote: “Vault provides the following integrations to seamlessly consume secrets in your Kubernetes workloads without modifying your existing application code: Vault Secrets Operator ... CSI driver ... Vault A”
- **CI/CD integrations**: Yes — <https://developer.hashicorp.com/vault/integrations> (verified 2026-07-17)
  - Note: ,"description":"Dynamically provision secrets for Buildkite CI/CD pipelines." — The official integrations directory also lists Jenkins (CloudBees CI) and JetBrains TeamCity secrets engines/plugins for CI/CD credential retrieval.
  - Quote: “Buildkite Secrets Engine”
- **CLI**: Yes — <https://developer.hashicorp.com/vault/docs/commands> (verified 2026-07-17)
  - Note: Dedicated 'Vault CLI usage: Technical reference for the Vault CLI' documentation section covering the full vault command-line tool.
  - Quote: “Vault CLI usage”
- **Audit logs**: Yes — <https://developer.hashicorp.com/vault/docs/audit> (verified 2026-07-17)
  - Note: Audit devices provide a detailed, tamper-evident log of all requests and responses.
  - Quote: “Audit devices are mountable devices that log requests and responses in Vault.”
- **RBAC / fine-grained access**: Yes — <https://developer.hashicorp.com/vault/docs/concepts/policies> (verified 2026-07-17)
  - Note: Policies are deny-by-default and path-based, giving fine-grained access control.
  - Quote: “Policies provide a declarative way to grant or forbid access to certain paths and operations in Vault.”
- **PKI / certificate management**: Yes — <https://developer.hashicorp.com/vault/docs/secrets/pki> (verified 2026-07-17)
  - Note: The PKI secrets engine issues and manages X.509 certificates, including short-lived dynamic certs.
  - Quote: “Dynamically generate X.509 certificates with the PKI secrets engine plugin.”
- **SDKs & API**: Yes — <https://developer.hashicorp.com/vault/api-docs> (verified 2026-07-17)
  - Note: A full HTTP API is documented, plus an official/community client libraries page (https://developer.hashicorp.com/vault/api-docs/libraries: 'List of official and community contributed libraries for int
  - Quote: “Vault has an HTTP API that can be used to control every aspect of Vault.”

---
Ranked by verified data, never by who paid. https://altcatalog.com/trust/