Skip to main content
Infisical Secrets Management centralizes secrets such as API keys, database credentials, and application configuration. Teams eliminate hardcoded secrets, scope access by environment and path, and deliver secrets to applications and infrastructure through the CLI, SDKs, agents, Kubernetes, and CI/CD.

Get started

Store a secret and deliver it to a running application:

Quickstart

Add your secrets and deliver them to your stack in under 10 minutes.

Local development

Run your app on your own machine and pull secrets from Infisical.

Manage secrets

Work with secrets once they’re in a project:

Organization

Projects, folders, and referencing one secret from another.

Versioning

Secret history, and rolling a secret or an environment back to an earlier state.

Access control

Validation rules, approval workflows, access requests, and folder-level roles.

Monitoring

Insights into a project, plus webhooks and event subscriptions for its changes.

Integrations

Deliver secrets from your project to applications, infrastructure, and third-party stores:

Overview

What separates the three kinds of integration, and how to pick one.

Search integrations

Every framework, platform, and sync destination in one searchable list.

Secret rotation

Replace a long-lived credential on a schedule:

Overview

Replace a credential on a schedule, with no gap where the old one stops working.

Search providers

Databases, cloud IAM, SaaS API keys, and local machine accounts.

Dynamic secrets

Issue a credential per request and expire it after use:

Overview

Generate a credential when someone asks for one, and revoke it when its lease ends.

Search services

Databases, cloud IAM, message queues, directories, and Kubernetes.

Honey tokens

Plant decoy credentials and watch for anyone using them:

Overview

Plant a decoy credential that alerts you the moment someone uses it.

AWS

Set up AWS honey tokens and read the alerts they raise.

Agent proxy

Broker credentials to AI agents:

Overview

Put a proxy in front of a service so your app never handles the credential.

Quickstart

Set up credentials, then run the proxy locally or as a standalone service.

Reference

Supported services, both proxy modes, and the activity log they write.