Infisical
Open-source platform for secrets, PKI certificates, and privileged access
29k stars 2.2k forks last commit first released
Actively maintained
Last commit 27 Aug 2026.

Infisical is an open-source security platform for centrally managing application secrets and configuration, internal and external PKI certificates, and privileged access workflows. It helps teams reduce credential sprawl by securely delivering, rotating, and auditing sensitive values across environments and infrastructure.
Key Features
- Secrets management across projects and environments with web UI, CLI, SDKs, and API
- Dynamic secrets and scheduled secret rotation for supported backends
- Secret syncs and delivery options for CI/CD, cloud platforms, and Kubernetes workloads
- Secret scanning and leak prevention tooling to catch exposed credentials
- Built-in PKI with private CA hierarchy, certificate issuance, renewal, and revocation
- ACME-based certificate enrollment and certificate lifecycle governance policies
- SSH certificate issuance for short-lived, centralized infrastructure access
- Key Management System (KMS) for encrypt/decrypt workflows and key governance
- Role-based access controls, approvals, temporary access, and audit logs
Use Cases
- Centralize and distribute application secrets to developers, CI pipelines, and runtime environments
- Run an internal CA and manage X.509 certificates for services, devices, and apps
- Replace long-lived infrastructure credentials with short-lived SSH certificates and dynamic secrets
Limitations and Considerations
- Some premium/enterprise functionality is separated into an enterprise directory and may require a commercial license
Infisical is well-suited for organizations that need a modern developer experience for secrets and PKI while maintaining strong governance through access controls and auditing. It can serve as a unified layer for managing credentials and certificates across diverse stacks and deployment environments.
Categories:
Tags:
Tech Stack:
Similar to Infisical

Passbolt
Open-source password and secret manager for teams
Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.
OpenBao
Open source secrets management for keys, certificates, and tokens
OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access control.

TeamPass
Collaborative on-prem password management with RBAC and encryption.
On-prem password manager enabling secure sharing and fine-grained access control over credentials.

Squidex
Open-source headless CMS with API-first content management
Squidex is an open-source headless CMS and content hub with REST and GraphQL APIs, workflows, versioning, and integrations for delivering content to any app or site.
ZITADEL
API-first identity and access management platform for applications
ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

Rundeck
Runbook automation and job orchestration for operations teams
Open-source runbook automation platform to schedule jobs, orchestrate workflows, and provide controlled self-service operations via web UI and API.


