Infisical
Infisical is an open-source platform for managing secrets, certificates and privileged access, with syncing, rotation and leak prevention.
- GitHub stars
- 30k
- Last commit
- today
- Latest release
- v0.165.16
- Self-hosted
- Yes
- Hosted version
- Available

Infisical is an open-source security infrastructure platform used by teams to manage application secrets, certificates and privileged access. It centralizes secrets and configuration across environments, with versioning, rotation and leak prevention. The stack is TypeScript and Go on PostgreSQL, and the project offers both a hosted Infisical Cloud and a self-hosting option.
Secrets are organized by project and environment, such as development and production, in a dashboard. Secret syncs push values to platforms like GitHub, Vercel and AWS and work with tools such as Terraform and Ansible. Further features include point-in-time recovery, scheduled rotation for databases and AWS IAM, ephemeral dynamic secrets, secret scanning that stops leaks into git, a Kubernetes operator, and an agent that injects secrets without code changes. It also offers honey tokens as decoy credentials and brokered access for AI agents. The repository metadata lists the license as Other, so check it for exact terms.
Key features
- Secrets dashboard across projects and environments
- Secret syncs to GitHub, Vercel and AWS
- Versioning with point-in-time recovery
- Automatic secret rotation and dynamic secrets
- Secret scanning to prevent leaks into git
- Kubernetes operator and injection agent
Pricing: Free for up to 5 identities. Pro is $23 and Advanced $46 per identity per month, or $20 and $40 billed annually; Enterprise is custom. Paid plans include a free trial.
