Software / Cloud Security / HashiCorp Vault

HashiCorp Vault

HashiCorp Vault centralizes secrets, identity-based access, encryption operations, credential rotation and audit logging for self-managed and cloud environments.

8.4/10 TechZella Score
Visit Website ↗
At a glance

Quick Verdict

Vault provides broad secrets, identity, encryption, dynamic credential, PKI, audit and integration capabilities. G2 reports generally positive user sentiment, while the product's operational complexity can increase deployment and administration effort.

Overview

HashiCorp Vault is an identity-based secrets and encryption management system. It centralizes credentials, encryption keys, certificates and other sensitive data behind authentication, authorization policies and audit controls.

Vault supports self-managed deployments across cloud, on-premises and hybrid environments. HCP Vault Dedicated provides a managed Vault Enterprise deployment operated through the HashiCorp Cloud Platform.

IBM completed its acquisition of HashiCorp on February 27, 2025. Vault remains part of the HashiCorp product portfolio within IBM Software.

Key Features

Vault stores static secrets, generates short-lived credentials and rotates access data through configurable secrets engines. It also supports PKI, encryption as a service, identity workflows and detailed audit logging.

Authentication methods include LDAP, OIDC, GitHub, AppRole, JWT, cloud identity systems and Kubernetes authentication. Policy-based authorization controls which clients can access specific paths and operations.

Vault integrates with Kubernetes through Vault Agent Injector, Vault Secrets Operator and the Vault Secrets Store CSI provider. It also supports plugins for authentication, secret storage and database credential generation.

Pricing

Vault Community Edition can be installed as a self-managed product without a listed license charge. Enterprise features require a commercial license and custom pricing.

HCP Vault Dedicated uses trial, pay-as-you-go and contract-based billing options. Development, Essentials and Standard tiers are billed according to cluster tier, size, region and, for some tiers, active clients.

HCP trial organizations can create one Vault Dedicated cluster. Exact trial and pay-as-you-go rates are displayed in the HCP Portal and can change by region and service configuration.

Pros & Cons

Vault suits organizations that need centralized, policy-controlled secrets across multiple clouds, Kubernetes clusters and on-premises systems. Its plugin model and API support complex infrastructure workflows.

The main trade-off is operational complexity. Self-managed deployments require careful configuration of storage, high availability, sealing, upgrades, backups, policies and recovery procedures.

Alternatives

OpenBao is a community-driven, open-source fork with Vault-compatible origins. AWS Secrets Manager, Azure Key Vault and Google Secret Manager are cloud-native choices for organizations centered on one provider.

CyberArk Conjur, Akeyless, Infisical and Doppler are additional alternatives. Their suitability depends on requirements for self-hosting, dynamic credentials, cloud integration, policy control and managed operations.

FAQ

Does Vault have an API?
Yes. Vault exposes an HTTP API using REST-style methods. API routes use the /v1/ prefix, and the CLI also communicates through the API.

Does Vault offer a free trial?
HCP Vault Dedicated provides an HCP trial option. Trial limitations and current usage rates are managed through the HCP Portal.

Which operating systems support Vault?
Official installation documentation lists macOS, Windows, Linux and FreeBSD. Vault can also run in Kubernetes and container environments.

Can Vault generate database credentials?
Yes. Database secrets engines can generate dynamic credentials for supported database systems, including PostgreSQL, MySQL, SQL Server and MongoDB.

Is Vault suitable for Kubernetes?
Yes. HashiCorp documents several Kubernetes integrations, including Vault Agent Injector, Vault Secrets Operator and the Secrets Store CSI provider.

Who is Vault best for?
Vault is best suited to platform engineering, security and operations teams managing secrets across distributed or hybrid infrastructure.

Capabilities

Features

Secrets Management

  • Key/value secret storage
  • Dynamic secrets generation
  • Credential rotation
  • Third-party secret management
  • Secret leasing and revocation

Identity and Access

  • Identity-based authentication
  • LDAP and OIDC authentication
  • GitHub, AppRole and JWT authentication
  • Kubernetes authentication
  • Policy-based authorization
  • Enterprise namespaces

Encryption and PKI

  • Encryption as a service through the Transit secrets engine
  • PKI and certificate issuance
  • Certificate rotation
  • HSM and KMS integration
  • Tokenization and sensitive-data protection

Audit and Governance

  • Detailed audit logging
  • Configurable audit devices
  • Access policies
  • Control groups in supported editions
  • Replication and disaster recovery in supported editions

Integrations

  • AWS, Azure and Google Cloud integrations
  • Kubernetes integrations
  • Database plugins for systems such as PostgreSQL, MySQL, SQL Server and MongoDB
  • Terraform, Nomad and Ansible workflows
  • CI/CD pipeline integrations
  • Vault Agent and Secrets Store CSI provider

Developer Access

  • HTTP REST API
  • Command-line interface
  • Web user interface
  • Go, Ruby, C#, Python and Java integration examples
  • OpenAPI document generation
  • Plugin development framework
Product details

Specifications

Product categorySecrets management and identity security
Deployment modelsSelf-managed, cloud-hosted HCP Vault Dedicated, hybrid
APIHTTP REST API v1
AuthenticationLDAP, OIDC, GitHub, AppRole, JWT, Kubernetes and cloud identity methods
StorageIntegrated Raft storage, filesystem, external storage and in-memory development storage
Operating systemsmacOS, Windows, Linux and FreeBSD
Container supportDocker and Kubernetes
Free trialAvailable through HCP Vault Dedicated trial
IntegrationsAWS, Azure, Google Cloud, Kubernetes, databases, Terraform, Nomad, Ansible, CI/CD, HSM and KMS
Managed serviceHCP Vault Dedicated
Self-managed editionsCommunity Edition and Enterprise
HeadquartersSan Francisco, California, United States
Visual preview

Demo & Screenshots

Screenshots are not available yet.TechZella will add verified product images when suitable official screenshots are found.
Our evidence-based assessment

TechZella Score

A proprietary editorial score based on product capabilities, usability, value, performance, support and user sentiment evidence.

8.4/10Moderate confidence
Features9.2
Ease of Use7.4
Value for Money7.8
Performance8.7
Support8.0
User Sentiment8.6

Vault provides broad secrets, identity, encryption, dynamic credential, PKI, audit and integration capabilities. G2 reports generally positive user sentiment, while the product's operational complexity can increase deployment and administration effort.

Methodology v1.0. This is a TechZella editorial assessment, not a direct user-review average.

Independent review sources

Trusted Ratings

Ratings are published by the respective review platforms and may change over time.

Plans & pricing

Pricing

Community Edition

$0
No license charge listed

Self-managed Vault distribution with core secrets management capabilities. Installation and infrastructure operations remain the customer's responsibility.

Check current pricing →

HCP Vault Dedicated Development

Usage-based
Hourly

Managed single-node environment intended for sandboxing, prototyping and non-production use. HCP trial access is available, subject to account limitations.

Check current pricing →

HCP Vault Dedicated Essentials

Usage-based
Hourly plus active-client charges

Managed production tier with high availability, audit and telemetry streaming, backup and restore capabilities, and a 99.9% SLA.

Check current pricing →

HCP Vault Dedicated Standard

Usage-based or contract
Hourly plus active-client charges or annual contract

Managed tier adding capabilities such as performance replication, Sentinel policies, control groups and advanced data protection.

Check current pricing →

Vault Enterprise

Contact sales
u5951u7d04

Self-managed commercial edition with enterprise capabilities such as namespaces, replication, advanced governance and additional security controls.

Check current pricing →

Pricing may change. Verify current plans on the vendor's website.

Editorial assessment

Pros & Cons

Pros

  • Supports self-managed, hybrid-cloud and managed-cloud deployments.
  • Combines static secrets, dynamic credentials, PKI and encryption services.
  • Provides extensive authentication, secrets-engine and plugin integrations.
  • Offers policy-based authorization and detailed audit logging.
  • Provides a documented HTTP API, CLI, UI and client-library examples.

Cons

  • Self-managed deployment requires substantial operational and security expertise.
  • Pricing for managed and enterprise offerings depends on usage, configuration or contract terms.
  • The breadth of configuration can make initial implementation difficult for smaller teams.
  • Some advanced capabilities require Enterprise or higher HCP tiers.
  • HCP Dedicated development clusters have production limitations, including single-node operation.
Similar software

Alternatives

OpenBao
AWS Secrets Manager
Azure Key Vault
Google Secret Manager
CyberArk Conjur
Akeyless
Compare options

Top Competitors

AWS Secrets Manager
Azure Key Vault
Google Secret Manager
CyberArk Conjur
Akeyless
Delinea Secret Server
Community feedback

Reviews

No reviews yet. Be the first to share your experience.

Write a Review