Infisical

Infisical

Open-source platform for secrets, PKI certificates, and privileged access

24.5kstars
1.7kforks
Last commit: 20h ago
Repo age: 4y old
Infisical screenshot

Infisical is an open-source security platform for centrally managing application secrets and configuration, internal and external PKI certificates, and privileged access workflows. It helps teams reduce credential sprawl by securely delivering, rotating, and auditing sensitive values across environments and infrastructure.

Key Features

  • Secrets management across projects and environments with web UI, CLI, SDKs, and API
  • Dynamic secrets and scheduled secret rotation for supported backends
  • Secret syncs and delivery options for CI/CD, cloud platforms, and Kubernetes workloads
  • Secret scanning and leak prevention tooling to catch exposed credentials
  • Built-in PKI with private CA hierarchy, certificate issuance, renewal, and revocation
  • ACME-based certificate enrollment and certificate lifecycle governance policies
  • SSH certificate issuance for short-lived, centralized infrastructure access
  • Key Management System (KMS) for encrypt/decrypt workflows and key governance
  • Role-based access controls, approvals, temporary access, and audit logs

Use Cases

  • Centralize and distribute application secrets to developers, CI pipelines, and runtime environments
  • Run an internal CA and manage X.509 certificates for services, devices, and apps
  • Replace long-lived infrastructure credentials with short-lived SSH certificates and dynamic secrets

Limitations and Considerations

  • Some premium/enterprise functionality is separated into an enterprise directory and may require a commercial license

Infisical is well-suited for organizations that need a modern developer experience for secrets and PKI while maintaining strong governance through access controls and auditing. It can serve as a unified layer for managing credentials and certificates across diverse stacks and deployment environments.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Vaultwarden

Vaultwarden

Bitwarden-compatible password manager server written in Rust

53.6k
2.5k
Last commit: 3d ago

Vaultwarden is a lightweight, Bitwarden-compatible password manager server in Rust, designed for self-hosting with official Bitwarden clients.

Alternative to:
Bitwarden
Bitwarden
+9
KeePassXC

KeePassXC

Cross-platform offline password manager using encrypted KDBX databases

25.5k
1.7k
Last commit: 1mo ago

KeePassXC is a secure, cross-platform password manager that stores credentials and sensitive notes in encrypted KeePass-compatible KDBX files with autofill and browser in...

Alternative to:
KeePassXC
KeePassXC
+10
Ente

Ente

End-to-end encrypted cloud for photos and 2FA

23.9k
1.4k
Last commit: 1d ago

Open-source, end-to-end encrypted platform for private photo backup, sharing, and authenticator (2FA) sync across devices, with optional self-hosting.

Alternative to:
Google Photos
Google Photos
+14
Bitwarden

Bitwarden

Open-source password manager with zero-knowledge security and self-hosting.

17.9k
1.5k
Last commit: 16h ago

Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.

Alternative to:
1Password
1Password
+9
Passbolt

Passbolt

Open-source password and secret manager for teams

5.6k
361
Last commit: 26d ago

Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.

Alternative to:
Passbolt Cloud
Passbolt Cloud
+11
OpenBao

OpenBao

Open source secrets management for keys, certificates, and tokens

5.2k
309
Last commit: 1d ago

OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access c...

Alternative to:
HashiCorp Vault
HashiCorp Vault
+3