Skip to main content
Infisical is the open source, all-in-one platform for secrets, certificates, and privileged access management. It provides modern security workflows — including secrets rotation, dynamic credentials, access approvals, and privileged access management — all within one platform designed for developers, infrastructure, and security teams. Start managing secrets securely with Infisical Cloud or learn how to host Infisical yourself.
Visual learner? Watch a guided overview of the Infisical platform to build the right mental model before diving into the rest of the documentation.

Why use Infisical?

Managing secrets, credentials, and infrastructure access is a critical concern for engineering teams. As infrastructure scales and environments become more complex, secrets start to sprawl — across codebases, CI/CD pipelines, configuration files, and cloud services. This makes them difficult to track, rotate, and secure. Without proper management, secret sprawl turns into risk: hardcoded credentials, unrotated keys, fragmented access controls that attackers can exploit amongst other things. Infisical addresses this challenge by providing an all-in-one platform and workflows to:
  • Securely store and manage application secrets from development to production.
  • Scan code and pipelines for exposed credentials.
  • Automate X.509 certificate issuance and renewal.
  • Govern privileged access to infrastructure with policy-driven sessions.
  • Encrypt and decrypt sensitive data with centralized key control.
  • Audit every access, credential use, and change.
Infisical is designed to integrate cleanly into your stack—improving security without adding complexity.

What can you do with Infisical?

Infisical consists of five integrated products, each addressing a specific aspect of infrastructure security. The cards below link to an introduction to each product and the tasks it can be used for.

Manage secrets

Store, deliver, and rotate credentials used by applications, and broker access to services for AI agents.

Detect leaked secrets

Scan source code and developer systems to identify credentials that have been exposed.

Manage certificates

Issue and automatically renew TLS, mTLS, and device certificates from internal or external certificate authorities.

Manage cryptographic keys

Perform encryption, decryption, and signing operations using keys stored within Infisical.

Manage privileged access

Give users and AI agents session-based access to databases and servers without providing them with the underlying credentials.

How the platform fits together

All five products share the same underlying platform. This platform includes organizations, projects, identities, deployment configuration, and integrations with external services.

Account structure

How organizations, projects, and members are structured within Infisical.

Identity and access

How users and machine identities authenticate, and how roles determine their permissions.

External integrations

Stored credentials that allow Infisical to authenticate with third-party services on your behalf.

Private network access

How Infisical reaches systems that aren’t directly accessible from its own network.

Cloud vs. self-host

Choose between running Infisical on Infisical Cloud or on your own infrastructure.

Architecture and security

How Infisical is built, how permissions are evaluated, and how data is encrypted.

Contributing

How to propose a change to Infisical, run the platform locally, and open a pull request.