Infisical
Open-source secrets management — centralize API keys, certs, SSH keys across environments with identity-based access, rotation, and secure delivery to GitHub, AWS, Kubernetes.
About Infisical
Infisical is open-source secrets management. It centralises API keys, certificates and SSH keys across environments, with identity-based access control, rotation, and secure delivery into GitHub, AWS and Kubernetes. The problem it solves is the .env file problem: credentials copied between laptops, CI settings and chat threads, with nobody able to say who can read what, or when a key was last changed.
We track it rather than run it. We list it as the option for the point where a project outgrows .env files and platform environment variables — several environments, more than a couple of people, and an audit question nobody can answer.
HashiCorp Vault is the incumbent and the most capable, with the operational weight to match — pick it when you need dynamic credentials and deep policy control and have someone to run it. AWS Secrets Manager or Google Secret Manager when you are entirely inside one cloud, where another vendor buys little. Doppler is the closest hosted comparison and worth evaluating side by side. 1Password Secrets Automation if the team already lives there. Infisical fits when you want open source and the option to self-host without Vault's overhead. One caveat, plainly: self-hosting a secrets store means owning its availability, and when it is down, deploys stop.
Try Infisical yourself.
Open the site in a new tab. No signup required from us.
Frequently asked questions
- What is Infisical?
- Open-source secrets management — centralize API keys, certs, SSH keys across environments with identity-based access, rotation, and secure delivery to GitHub, AWS, Kubernetes. Infisical is open-source secrets management. It centralises API keys, certificates and SSH keys across environments, with identity-based access control, rotation, and secure delivery into GitHub, AWS and Kubernetes. The problem it solves is the .env file problem: credentials copied between laptops, CI settings and chat threads, with nobody able to say who can read what, or when a key was last changed.
- What category does Infisical fall into?
- Infisical is a Infrastructure tool. Replace Works tracks it in the Tool Lab, our public catalogue of the AI tools we evaluate and ship with.
- Does Replace Works use Infisical?
- Infisical is listed in our Tool Lab as a tool we have evaluated and recommend, but it is not currently in our day-to-day rotation.