Infisical
Open-source platform for secrets, PKI certificates, and privileged access

Infisical is an open-source security platform for centrally managing application secrets and configuration, internal and external PKI certificates, and privileged access workflows. It helps teams reduce credential sprawl by securely delivering, rotating, and auditing sensitive values across environments and infrastructure.
Key Features
- Secrets management across projects and environments with web UI, CLI, SDKs, and API
- Dynamic secrets and scheduled secret rotation for supported backends
- Secret syncs and delivery options for CI/CD, cloud platforms, and Kubernetes workloads
- Secret scanning and leak prevention tooling to catch exposed credentials
- Built-in PKI with private CA hierarchy, certificate issuance, renewal, and revocation
- ACME-based certificate enrollment and certificate lifecycle governance policies
- SSH certificate issuance for short-lived, centralized infrastructure access
- Key Management System (KMS) for encrypt/decrypt workflows and key governance
- Role-based access controls, approvals, temporary access, and audit logs
Use Cases
- Centralize and distribute application secrets to developers, CI pipelines, and runtime environments
- Run an internal CA and manage X.509 certificates for services, devices, and apps
- Replace long-lived infrastructure credentials with short-lived SSH certificates and dynamic secrets
Limitations and Considerations
- Some premium/enterprise functionality is separated into an enterprise directory and may require a commercial license
Infisical is well-suited for organizations that need a modern developer experience for secrets and PKI while maintaining strong governance through access controls and auditing. It can serve as a unified layer for managing credentials and certificates across diverse stacks and deployment environments.
Categories:
Tags:
Tech Stack:
Similar Services

Vaultwarden
Bitwarden-compatible password manager server written in Rust
Vaultwarden is a lightweight, Bitwarden-compatible password manager server in Rust, designed for self-hosting with official Bitwarden clients.

KeePassXC
Cross-platform offline password manager using encrypted KDBX databases
KeePassXC is a secure, cross-platform password manager that stores credentials and sensitive notes in encrypted KeePass-compatible KDBX files with autofill and browser in...

Ente
End-to-end encrypted cloud for photos and 2FA
Open-source, end-to-end encrypted platform for private photo backup, sharing, and authenticator (2FA) sync across devices, with optional self-hosting.

Bitwarden
Open-source password manager with zero-knowledge security and self-hosting.
Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.


Passbolt
Open-source password and secret manager for teams
Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.
OpenBao
Open source secrets management for keys, certificates, and tokens
OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access c...
Docker
TypeScript
Node.js