About AWS Secrets Manager
AWS Secrets Manager is a managed service from Amazon Web Services that keeps sensitive values such as database credentials, API keys and tokens out of application code. Applications fetch secrets at runtime through the AWS API, which lets teams change them without redeploying software. It is intended for organizations that already run workloads on AWS.
The service handles the whole lifecycle of a secret: creating and storing it, controlling who and what can read it, and rotating it on a schedule. Because it is part of AWS, it works with the platform's identity and access controls and is billed as part of an AWS account.
AWS Secrets Manager is proprietary and runs only as a hosted AWS service, so there is no self-hosted edition. Pricing is usage-based and covered on the service's pricing page, and the broader AWS site provides documentation and support options.
Key features
- Central storage for secrets
- Scheduled rotation of credentials
- Runtime retrieval through the AWS API
- Access controlled by AWS permissions
- Support for database credentials and API keys
Good fit for
- →Rotating database passwords for AWS workloads
- →Keeping API keys out of application code
- Tags
- secrets-management
- aws
- security
- credential-rotation
- cloud
- devops
AWS Secrets Manager: questions and answers
- What is AWS Secrets Manager used for?
- AWS Secrets Manager is a managed AWS service for storing, rotating and retrieving database credentials, API keys and other secrets throughout their lifecycle. It is a good fit for rotating database passwords for AWS workloads and keeping API keys out of application code.
- How much does AWS Secrets Manager cost?
- AWS Secrets Manager is a paid product with no free plan. A free trial is available. Pay as you go with no upfront cost: $0.40 per secret per month plus $0.05 per 10,000 API calls. New AWS customers get Free Tier credits.
- Is AWS Secrets Manager open source?
- No. AWS Secrets Manager is proprietary (closed-source) software and can't be self-hosted. Open-source alternatives to AWS Secrets Manager include Infisical and OpenBao.
- What are some alternatives to AWS Secrets Manager?
- AWS Secrets Manager competes with Azure Key Vault, Google Secret Manager and Doppler. For open-source options, see Enlisted's ranked list of open-source AWS Secrets Manager alternatives.
Open-source alternatives to AWS Secrets Manager
See all
Infisical
Security
Infisical is the open-source platform for secrets, certificates, and privileged access man
OSSvs Doppler★ 30k
OpenBao
Security
OpenBao is a software solution to manage, store, and distribute sensitive data including s
MPL-2.0vs AWS Secrets Manager★ 8.3k
SafeLine
Security
CyberServal open-source WAF is a self-hosted WAF with 20.9K GitHub stars. Block SQL inject
GPL-3.0vs Cloudflare★ 23k
fail2ban
Security
Daemon to ban hosts that cause multiple authentication errors
OSS★ 19k
Wazuh
Security
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints a
OSSvs Splunk★ 17k
CrowdSec
Security
Open-source IDS/IPS, WAF and bot detection for Linux, Windows, Docker and Kubernetes, with
MITvs Cloudflare★ 15k
SaaS alternatives to AWS Secrets Manager
See all
Azure Key Vault
Security
Azure service for storing secrets, encryption keys and certificates
SaaS
Google Secret Manager
Security
Google Cloud service for storing and versioning API keys, passwords and certificates
SaaS
Doppler
Security
Secrets management platform that syncs environment variables across apps and teams
SaaS
Akeyless
Security
SaaS secrets management and machine identity platform for apps and pipelines
SaaS
Abnormal Security
Security
Behavior-based cloud email security that blocks phishing and account takeover
SaaS
Adverse Monitor
Security
Cyber threat intelligence tool that watches the dark web for incident claims naming your company
SaaS

