- Secret Stores: Secure, versioned storage scoped by project, environment, and path.
- Access Control: Fine-grained, identity-aware permissions for users and machines
- Secret Delivery: Access secrets via CLI, SDKs (Go, Node.js, Python, etc.), HTTP API, agents, Kubernetes Operator, External Secrets Operator (ESO), and more.
- Lifecycle Automation: Automate secret rotation, generate dynamic secrets, and enforce approval-based workflows.
- Secrets Syncs: Push secrets to external services like GitHub, GitLab, AWS Secrets Manager, Vercel, and more.