Cheaper than a security breach.
Pick a product and choose a plan that fits.
All paid plans include a free trial, no credit card required.
Free
For individuals and personal projects.
$00
forever
Get started with:
- 5 identities, unlimited projects
- 100+ integrations
- Agent Proxy
- Secret Sharing
- Secret References and Imports
- Secret Overrides
- 2FA
- Unlimited Projects (separate from 5 identities)
Pro
For growing teams looking to boost their security.
Billed annuallySave 13%
$20$23$2200
/identity/month
Everything in Free, plus:
- Unlimited identities
- Access Controls
- Secret Rotation
- SAML SSO
- 30-day Audit log retention
- Secret Versioning
- Point-in-time Recovery
AdvancedMost popular
For scaling teams with complex security needs.
Billed annuallySave 13%
$40$46$4400
/identity/month
Everything in Pro, plus:
- Dynamic Secrets
- Honey Tokens
- SOC 2 Type II
- Higher Rate Limits
- Custom Roles
- SSO & MFA enforcement
- 90-day Audit log retention
- Temporary Access
Enterprise
For large organizations that need SCIM, custom SLAs, and dedicated support.
Custom
billed annually
Everything in Advanced, plus:
- Approval Workflows & Access Requests
- LDAP
- SCIM
- Custom Audit log retention and rate limits
- User Groups
- 99.99% SLA
- KMIP
- External KMS & HSM Support
- Audit Log Streaming (SIEM)
- Sub-organizations
- Self-hosting or Dedicated Infrastructure
Trusted by the best teams in the world

Compare features of secrets management
IdentitiesThe number of user and machine identities (apps, CI pipelines, services) that can authenticate and hold permissions in your organization.
5 identities
Unlimited
Unlimited
Unlimited
Machine identitiesNon-human identities, like apps, CI pipelines, and services, that authenticate to Infisical to pull secrets programmatically.
ProjectsIsolated workspaces that each hold their own secrets, environments, and access rules.
Unlimited
Unlimited
Unlimited
Unlimited
EnvironmentsDistinct deployment contexts, like dev, staging, and production, where you can store separate versions of the same secrets.
3
6/project
12/project
Unlimited
Secret SyncsNative syncs that automatically push secrets from Infisical to platforms like GitHub, Vercel, AWS, and Kubernetes.
10
25
50
Unlimited
Third-party integrationsConnectors for third-party services like GitHub Actions, CircleCI, GitLab CI/CD, and AWS Secrets Manager.
Infrastructure integrationsNative support for infrastructure tooling such as Docker, Kubernetes, and Terraform.
Enterprise integrations (e.g. Oracle)Prebuilt syncs for enterprise systems such as Oracle Cloud, built for larger and more complex infrastructure.
–
–
–
Honey tokensFake credentials planted alongside real secrets that trigger an alert the moment an attacker tries to use them.
–
3
10
Unlimited
Secret referencing & overridesReference one secret's value from another, and override values per environment without duplicating the underlying secret.
Secret sharingShare a secret via a link that expires after a set time or number of views, instead of pasting it in chat or email.
Secret foldersOrganize secrets into nested folders within an environment, mirroring how your codebase or services are structured.
Infisical AgentA lightweight daemon that fetches secrets and keeps local files or templates continuously in sync on your machines.
WebhooksNotify external systems automatically when secrets change, so downstream services can react or redeploy.
Custom environmentsDefine your own environments beyond the defaults (dev, staging, prod) to match your deployment topology.
–
Secret versioningEvery change to a secret is saved, so you can see what changed, when, and by whom.
–
Point-in-time recoveryRoll back a folder's secrets and configuration to any previous snapshot, scoped to that folder only.
–
Secret rotationAutomatically regenerate credentials like database passwords or API keys on a schedule, reducing exposure from long-lived secrets.
–
Public DBs only
Dynamic secretsGenerate short-lived, unique credentials on demand for each identity, which automatically expire or revoke after use.
–
–
GatewaysLightweight relays deployed in your network that let Infisical securely reach private databases and internal services without inbound access.
–
–
Insights dashboardA summary view of secret access activity across your projects: volume, locations, and auth methods over time.
–
Two-factor authenticationRequire a second verification step, like an authenticator app code, in addition to a password at login.
Access controlsRole-based permissions that determine which users and machine identities can view or modify specific secrets and resources.
–
SSO (SAML)Let users log in through your identity provider, such as Okta or Azure AD, using the SAML protocol.
–
SSO / MFA enforcementRequire every member of your organization to authenticate through SSO or MFA, with no password-only fallback.
–
–
Custom rolesDefine your own permission sets beyond the built-in Admin and Member roles to match your team's exact access needs.
–
–
Additional privilegesGrant a user extra permissions on top of their role without creating a whole new custom role.
–
Multi-role assignmentAssign more than one role to a single user, combining their permissions.
–
–
Temporary accessGrant time-limited permissions that automatically expire, useful for short-term tasks like debugging production.
–
–
Approval workflows & access requestsRequire designated approvers to sign off before a user's request for expanded or temporary access is granted.
–
–
–
SCIMAutomatically provision and deprovision users in Infisical from your identity provider, like Okta or Azure AD.
–
–
–
LDAPLet members log in to Infisical using existing directory credentials from services like Active Directory.
–
–
–
User groupsAssign roles and permissions to a group so they apply automatically to every member, instead of one by one.
–
–
–
SOC 2 Type IIAn independent audit confirming Infisical's security, availability, and confidentiality controls are designed and operate effectively over time.
–
–
Audit log retentionHow long a searchable history of actions, such as secret access, permission changes, and logins, is kept.
–
30 days
90 days
Custom
Audit log streamingForward batches of audit log events to your SIEM, storage bucket, or observability stack.
–
–
–
Smart security alertsAutomatic notifications when Infisical detects suspicious activity, like logins from new locations or unusual access patterns.
IP allowlistingRestrict access to your organization to a defined set of trusted IP addresses or ranges.
–
Rate limitsAPI and request throughput limits. Advanced raises the standard limit; Enterprise sets a custom limit for high-volume automation.
Normal
Normal
Higher
Custom
Sub-organizationsCreate isolated child organizations, each with its own projects and members, under one shared root organization and billing.
–
–
–
KMIPLet external clients and hardware manage encryption keys through Infisical using the standard KMIP protocol.
–
–
–
KMS & HSM supportCentrally manage encryption and signing keys, optionally backed by a hardware security module for the root key.
–
–
–
Pay by cardPay for your subscription with a credit or debit card.
Annual billingPay yearly instead of monthly, typically at a discount.
Invoice billingPay via invoice on custom terms instead of an automatically charged credit card each month.
–
–
–
Custom MSANegotiate your own master service agreement terms instead of accepting the standard terms of service.
–
–
–
Agent Proxy (static secrets)Let AI agents use fixed credentials, like API keys, without ever exposing the actual values to the agent.
Agent Proxy (dynamic secrets)Broker AI agents' access to short-lived, auto-expiring credentials so a compromised agent can't leak long-term secrets.
–
–
Coming soon
Coming soon
Active developersThe number of developers whose commits and repositories are monitored for leaked secrets.
Up to 25
–
–
Unlimited
Scanning projectsThe number of projects you can connect for secret scanning.
Up to 1
–
–
Unlimited
Repository sizeThe maximum size of a repository that can be scanned for exposed secrets.
Up to 1 GB
–
–
Up to 100 GB
CLI scanningScan repositories and files for hardcoded secrets directly from the command line.
–
–
Pre-commit checksCatch secrets before they're committed by scanning changes during a git pre-commit hook.
–
–
Remediation trackingTrack the status of each detected secret through triage, rotation, and resolution.
–
–
Continuous monitoringContinuously watch connected repositories and alert the moment a new secret is exposed.
–
–
Custom detectorsDefine your own detection rules to catch organization-specific secret formats and tokens.
–
–
–
GitHub Enterprise ServerScan repositories hosted on a self-managed GitHub Enterprise Server instance.
–
–
–
Ticketing, docs, messaging & container registryExtend scanning beyond source code to ticketing systems, documentation, messaging, and container registries.
–
–
–
Alerting (Email, Slack, Discord, MS Teams, PagerDuty, Splunk)Route secret-leak alerts to Email, Slack, Discord, Microsoft Teams, PagerDuty, or Splunk.
–
–
–
Community supportHelp from the Infisical community and team through public channels like Slack and GitHub.
Email supportDirect support from the Infisical team over email.
–
Priority supportFaster response times and a direct escalation path for support tickets, ahead of standard queue handling.
–
–
Slack Connect channelA shared Slack Connect channel with the Infisical team for direct, ongoing support.
–
–
–
Microsoft Teams shared channelA shared Microsoft Teams channel with the Infisical team for direct, ongoing support.
–
–
–
Dedicated SE & onboardingA named solutions engineer who helps design your rollout and onboard your team.
–
–
–
99.99% SLAA contractual guarantee of at most about 52 minutes of downtime per year, with service credits if unmet.
–
–
–
Self-hosting (add-on)Run Infisical on your own infrastructure instead of Infisical Cloud, while retaining enterprise features and support.
–
$25/id/mo
$50/id/mo
$90-100/id/mo
FreeGet started
IdentitiesThe number of user and machine identities (apps, CI pipelines, services) that can authenticate and hold permissions in your organization.5 identities
Machine identitiesNon-human identities, like apps, CI pipelines, and services, that authenticate to Infisical to pull secrets programmatically.
ProjectsIsolated workspaces that each hold their own secrets, environments, and access rules.Unlimited
EnvironmentsDistinct deployment contexts, like dev, staging, and production, where you can store separate versions of the same secrets.3
Secret SyncsNative syncs that automatically push secrets from Infisical to platforms like GitHub, Vercel, AWS, and Kubernetes.10
Third-party integrationsConnectors for third-party services like GitHub Actions, CircleCI, GitLab CI/CD, and AWS Secrets Manager.
Infrastructure integrationsNative support for infrastructure tooling such as Docker, Kubernetes, and Terraform.
Enterprise integrations (e.g. Oracle)Prebuilt syncs for enterprise systems such as Oracle Cloud, built for larger and more complex infrastructure.–
Honey tokensFake credentials planted alongside real secrets that trigger an alert the moment an attacker tries to use them.–
Secret referencing & overridesReference one secret's value from another, and override values per environment without duplicating the underlying secret.
Secret sharingShare a secret via a link that expires after a set time or number of views, instead of pasting it in chat or email.
Secret foldersOrganize secrets into nested folders within an environment, mirroring how your codebase or services are structured.
Infisical AgentA lightweight daemon that fetches secrets and keeps local files or templates continuously in sync on your machines.
WebhooksNotify external systems automatically when secrets change, so downstream services can react or redeploy.
Custom environmentsDefine your own environments beyond the defaults (dev, staging, prod) to match your deployment topology.–
Secret versioningEvery change to a secret is saved, so you can see what changed, when, and by whom.–
Point-in-time recoveryRoll back a folder's secrets and configuration to any previous snapshot, scoped to that folder only.–
Secret rotationAutomatically regenerate credentials like database passwords or API keys on a schedule, reducing exposure from long-lived secrets.–
Dynamic secretsGenerate short-lived, unique credentials on demand for each identity, which automatically expire or revoke after use.–
GatewaysLightweight relays deployed in your network that let Infisical securely reach private databases and internal services without inbound access.–
Insights dashboardA summary view of secret access activity across your projects: volume, locations, and auth methods over time.–
Two-factor authenticationRequire a second verification step, like an authenticator app code, in addition to a password at login.
Access controlsRole-based permissions that determine which users and machine identities can view or modify specific secrets and resources.–
SSO (SAML)Let users log in through your identity provider, such as Okta or Azure AD, using the SAML protocol.–
SSO / MFA enforcementRequire every member of your organization to authenticate through SSO or MFA, with no password-only fallback.–
Custom rolesDefine your own permission sets beyond the built-in Admin and Member roles to match your team's exact access needs.–
Additional privilegesGrant a user extra permissions on top of their role without creating a whole new custom role.–
Multi-role assignmentAssign more than one role to a single user, combining their permissions.–
Temporary accessGrant time-limited permissions that automatically expire, useful for short-term tasks like debugging production.–
Approval workflows & access requestsRequire designated approvers to sign off before a user's request for expanded or temporary access is granted.–
SCIMAutomatically provision and deprovision users in Infisical from your identity provider, like Okta or Azure AD.–
LDAPLet members log in to Infisical using existing directory credentials from services like Active Directory.–
User groupsAssign roles and permissions to a group so they apply automatically to every member, instead of one by one.–
SOC 2 Type IIAn independent audit confirming Infisical's security, availability, and confidentiality controls are designed and operate effectively over time.–
Audit log retentionHow long a searchable history of actions, such as secret access, permission changes, and logins, is kept.–
Audit log streamingForward batches of audit log events to your SIEM, storage bucket, or observability stack.–
Smart security alertsAutomatic notifications when Infisical detects suspicious activity, like logins from new locations or unusual access patterns.
IP allowlistingRestrict access to your organization to a defined set of trusted IP addresses or ranges.–
Rate limitsAPI and request throughput limits. Advanced raises the standard limit; Enterprise sets a custom limit for high-volume automation.Normal
Sub-organizationsCreate isolated child organizations, each with its own projects and members, under one shared root organization and billing.–
KMIPLet external clients and hardware manage encryption keys through Infisical using the standard KMIP protocol.–
KMS & HSM supportCentrally manage encryption and signing keys, optionally backed by a hardware security module for the root key.–
Pay by cardPay for your subscription with a credit or debit card.
Annual billingPay yearly instead of monthly, typically at a discount.
Invoice billingPay via invoice on custom terms instead of an automatically charged credit card each month.–
Custom MSANegotiate your own master service agreement terms instead of accepting the standard terms of service.–
Agent Proxy (static secrets)Let AI agents use fixed credentials, like API keys, without ever exposing the actual values to the agent.
Agent Proxy (dynamic secrets)Broker AI agents' access to short-lived, auto-expiring credentials so a compromised agent can't leak long-term secrets.–
Active developersThe number of developers whose commits and repositories are monitored for leaked secrets.Up to 25
Scanning projectsThe number of projects you can connect for secret scanning.Up to 1
Repository sizeThe maximum size of a repository that can be scanned for exposed secrets.Up to 1 GB
CLI scanningScan repositories and files for hardcoded secrets directly from the command line.
Pre-commit checksCatch secrets before they're committed by scanning changes during a git pre-commit hook.
Remediation trackingTrack the status of each detected secret through triage, rotation, and resolution.
Continuous monitoringContinuously watch connected repositories and alert the moment a new secret is exposed.
Custom detectorsDefine your own detection rules to catch organization-specific secret formats and tokens.–
GitHub Enterprise ServerScan repositories hosted on a self-managed GitHub Enterprise Server instance.–
Ticketing, docs, messaging & container registryExtend scanning beyond source code to ticketing systems, documentation, messaging, and container registries.–
Alerting (Email, Slack, Discord, MS Teams, PagerDuty, Splunk)Route secret-leak alerts to Email, Slack, Discord, Microsoft Teams, PagerDuty, or Splunk.–
Community supportHelp from the Infisical community and team through public channels like Slack and GitHub.
Email supportDirect support from the Infisical team over email.–
Priority supportFaster response times and a direct escalation path for support tickets, ahead of standard queue handling.–
Slack Connect channelA shared Slack Connect channel with the Infisical team for direct, ongoing support.–
Microsoft Teams shared channelA shared Microsoft Teams channel with the Infisical team for direct, ongoing support.–
Dedicated SE & onboardingA named solutions engineer who helps design your rollout and onboard your team.–
99.99% SLAA contractual guarantee of at most about 52 minutes of downtime per year, with service credits if unmet.–
Self-hosting (add-on)Run Infisical on your own infrastructure instead of Infisical Cloud, while retaining enterprise features and support.–
Certificate Management pricing
Free
The basics for individuals and startups.
$00
/mo
- Core internal CA management
- Core certificate management
- ACME-compatible external CA integration
- API & ACME enrollment methods
- Certificate dashboard
- Up to 10 SANs
- No wildcard SANs
- Up to 2 internal CAs
- Up to 2 basic external CA integrations
Enterprise
Flexible pricing that scales with your organization.
Custom
billed annually
All of Free, plus:
- Externally-signed intermediate CA
- Wildcard SANs
- Basic CRL support
- Certificate inventory
- Certificate alerting
- Certificate syncs (AWS, Azure KV, Chef)
- Server-side auto-renewal
- Enterprise external CA integrations (e.g. Microsoft AD CS)
- Enterprise enrollment methods (EST)
- Integrations with PagerDuty, Slack & Jira
- SSO & SCIM provisioning
- Audit logs, 90-day retention
Core internal CA managementRun your own private certificate authorities inside Infisical and issue certificates from them.
Core certificate managementIssue, renew, revoke, and monitor certificates across their full lifecycle.
Internal CAsThe number of private CA hierarchies Infisical hosts for you.
Up to 2
Unlimited
ACME-compatible external CA integrationIntegrate any ACME-compatible external CA to issue and renew certificates automatically.
Basic external CA integrationsConnect private CAs you already run elsewhere, like AWS Private CA or Azure ADCS.
Up to 2
Unlimited
Externally-signed intermediate CARun an intermediate CA in Infisical that's signed by a root CA you keep outside Infisical.
–
Enterprise external CA integrations (Microsoft AD CS)Integrate enterprise CAs such as Microsoft Active Directory Certificate Services.
–
Active SANsThe number of Subject Alternative Names (additional hostnames) a single certificate can cover at once.
Up to 10
Unlimited
Wildcard SANsCover a domain and all its subdomains with a single wildcard entry (e.g. *.example.com).
–
API & ACMERequest and renew certificates programmatically via Infisical's API or the standard ACME protocol.
Enterprise enrollment methods (EST)Enroll certificates onto network devices and endpoints using the EST protocol.
–
Certificate dashboardA central view of every certificate, its status, and its expiry across your PKI.
Certificate inventoryA searchable inventory of all issued certificates and their metadata.
–
Certificate alertingGet notified ahead of certificate expiry so you can renew before anything breaks.
–
Server-side auto-renewalInfisical renews certificates automatically before they expire, with no manual intervention.
–
Certificate syncs (AWS, Azure KV, Chef)Automatically push issued certificates to destinations like AWS, Azure Key Vault, and Chef.
–
Basic CRL supportPublish and maintain Certificate Revocation Lists so clients can check whether a certificate is still valid.
–
SSO & SCIM provisioningLog in via your identity provider and automatically provision or deprovision users through SCIM.
–
Integrations with PagerDuty, Slack & JiraRoute certificate alerts and events into PagerDuty, Slack, and Jira.
–
Audit log retentionHow long a searchable history of certificate issuance, revocation, and access events is kept.
–
90 days
FreeGet started
Core internal CA managementRun your own private certificate authorities inside Infisical and issue certificates from them.
Core certificate managementIssue, renew, revoke, and monitor certificates across their full lifecycle.
Internal CAsThe number of private CA hierarchies Infisical hosts for you.Up to 2
ACME-compatible external CA integrationIntegrate any ACME-compatible external CA to issue and renew certificates automatically.
Basic external CA integrationsConnect private CAs you already run elsewhere, like AWS Private CA or Azure ADCS.Up to 2
Externally-signed intermediate CARun an intermediate CA in Infisical that's signed by a root CA you keep outside Infisical.–
Enterprise external CA integrations (Microsoft AD CS)Integrate enterprise CAs such as Microsoft Active Directory Certificate Services.–
Active SANsThe number of Subject Alternative Names (additional hostnames) a single certificate can cover at once.Up to 10
Wildcard SANsCover a domain and all its subdomains with a single wildcard entry (e.g. *.example.com).–
API & ACMERequest and renew certificates programmatically via Infisical's API or the standard ACME protocol.
Enterprise enrollment methods (EST)Enroll certificates onto network devices and endpoints using the EST protocol.–
Certificate dashboardA central view of every certificate, its status, and its expiry across your PKI.
Certificate inventoryA searchable inventory of all issued certificates and their metadata.–
Certificate alertingGet notified ahead of certificate expiry so you can renew before anything breaks.–
Server-side auto-renewalInfisical renews certificates automatically before they expire, with no manual intervention.–
Certificate syncs (AWS, Azure KV, Chef)Automatically push issued certificates to destinations like AWS, Azure Key Vault, and Chef.–
Basic CRL supportPublish and maintain Certificate Revocation Lists so clients can check whether a certificate is still valid.–
SSO & SCIM provisioningLog in via your identity provider and automatically provision or deprovision users through SCIM.–
Integrations with PagerDuty, Slack & JiraRoute certificate alerts and events into PagerDuty, Slack, and Jira.–
Audit log retentionHow long a searchable history of certificate issuance, revocation, and access events is kept.–
Privileged Access pricing
ProMost popular
For teams that need access control and session auditing.
$2200
/user/month
- Access requests
- Approval workflows
- Credential rotation
- SSH certificate auth
- Command blocking
- Session-log masking
- CLI-based resource access
- Audit logs & session recording, 30-day retention
Enterprise
For large organizations managing complex infrastructure, including Windows and RDP.
Custom
billed annually
Everything in Pro, plus:
- Unlimited resources
- SCIM
- LDAP
- Privileged account discovery
- Enterprise resources (e.g. Windows servers, RDP)
- Custom log & session recording retention
- SIEM audit log streaming
ResourcesDatabases, servers, and other infrastructure targets that users can request time-limited, brokered access to.
Up to 50
Unlimited
Access requestsUsers request time-limited access to a resource instead of holding standing credentials.
Approval workflowsRequire a designated approver to sign off before a user's access request is granted.
CLI-based resource accessConnect to resources through Infisical's command-line tool, which injects credentials without exposing them.
SSH certificate authAuthenticate to servers with short-lived SSH certificates instead of long-lived static keys.
Privileged credential rotationAutomatically rotate the credentials behind privileged accounts on a schedule to limit exposure.
Command blockingAllow or block specific commands within a privileged session to prevent risky operations.
Automated privileged account discoveryAutomatically scan your infrastructure to find privileged accounts that should be brought under management.
–
Enterprise resources (Windows, RDP)Extend privileged access management to Windows servers and RDP sessions in addition to standard infrastructure.
–
Audit logsA record of who accessed which resource and when, plus session-level events like start, end, and credential fetch.
Session recordingSearchable logs of the commands and activity within a privileged session, for compliance review and incident investigation.
Session-log maskingAutomatically redact sensitive values, like secrets and tokens, from recorded session logs.
Log & session recording retentionHow long session recordings and audit logs are stored and available for review.
30 days
Custom
SIEM audit log streamingForward batches of privileged access audit events to your SIEM or observability stack.
–
SCIMAutomatically provision and deprovision users from your identity provider, like Okta or Azure AD.
–
LDAPConnect Infisical to an LDAP directory for authentication and group-based access.
–
ResourcesDatabases, servers, and other infrastructure targets that users can request time-limited, brokered access to.Up to 50
Access requestsUsers request time-limited access to a resource instead of holding standing credentials.
Approval workflowsRequire a designated approver to sign off before a user's access request is granted.
CLI-based resource accessConnect to resources through Infisical's command-line tool, which injects credentials without exposing them.
SSH certificate authAuthenticate to servers with short-lived SSH certificates instead of long-lived static keys.
Privileged credential rotationAutomatically rotate the credentials behind privileged accounts on a schedule to limit exposure.
Command blockingAllow or block specific commands within a privileged session to prevent risky operations.
Automated privileged account discoveryAutomatically scan your infrastructure to find privileged accounts that should be brought under management.–
Enterprise resources (Windows, RDP)Extend privileged access management to Windows servers and RDP sessions in addition to standard infrastructure.–
Audit logsA record of who accessed which resource and when, plus session-level events like start, end, and credential fetch.
Session recordingSearchable logs of the commands and activity within a privileged session, for compliance review and incident investigation.
Session-log maskingAutomatically redact sensitive values, like secrets and tokens, from recorded session logs.
Log & session recording retentionHow long session recordings and audit logs are stored and available for review.30 days
SIEM audit log streamingForward batches of privileged access audit events to your SIEM or observability stack.–
SCIMAutomatically provision and deprovision users from your identity provider, like Okta or Azure AD.–
LDAPConnect Infisical to an LDAP directory for authentication and group-based access.–
Frequently asked questions
Everything you need to know about plans, billing, and getting started.
Infisical is an identity security platform that helps engineers and their organizations manage secrets across any identities, secure AI agents, manage certificates and PKI, and provide privileged access.
Its products are available individually or in combination. Infisical's offerings serve the full span of organizations, from hobbyists and individual builders all the way to massive organizations.