7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Infisical

Open source

Infisical is an open-source platform for managing secrets, certificates and privileged access, with syncing, rotation and leak prevention.

infisical.com
Infisical homepage screenshot
GitHub stars
30k
Last commit
today
Repository age
4 years
Version
v0.165.16
Licence
Custom
Self-hosted
Yes

About Infisical

Infisical is an open-source security infrastructure platform used by teams to manage application secrets, certificates and privileged access. It centralizes secrets and configuration across environments, with versioning, rotation and leak prevention. The stack is TypeScript and Go on PostgreSQL, and the project offers both a hosted Infisical Cloud and a self-hosting option.

Secrets are organized by project and environment, such as development and production, in a dashboard. Secret syncs push values to platforms like GitHub, Vercel and AWS and work with tools such as Terraform and Ansible. Further features include point-in-time recovery, scheduled rotation for databases and AWS IAM, ephemeral dynamic secrets, secret scanning that stops leaks into git, a Kubernetes operator, and an agent that injects secrets without code changes. It also offers honey tokens as decoy credentials and brokered access for AI agents. The repository metadata lists the license as Other, so check it for exact terms.

Key features

  • Secrets dashboard across projects and environments
  • Secret syncs to GitHub, Vercel and AWS
  • Versioning with point-in-time recovery
  • Automatic secret rotation and dynamic secrets
  • Secret scanning to prevent leaks into git
  • Kubernetes operator and injection agent

Good fit for

  • →Replacing .env files shared across a team
  • →Rotating database credentials automatically
  • →Delivering secrets to Kubernetes workloads
Tags
secrets-management
security
pki
certificates
devops
self-hosted
kubernetes
secret-scanning

Infisical: questions and answers

What is Infisical used for?
Infisical is an open-source platform for managing secrets, certificates and privileged access, with syncing, rotation and leak prevention. It is a good fit for replacing .env files shared across a team, rotating database credentials automatically and delivering secrets to Kubernetes workloads.
Is Infisical open source?
Yes. Infisical is open source under a custom licence. Its source code is on GitHub at Infisical/infisical and is written mainly in TypeScript.
Is Infisical free?
Yes. Infisical is open source, so the software itself is free to use under the terms of its own licence. A managed cloud version is also available, with paid plans from $23 per seat per month.
Can I self-host Infisical?
Yes. Infisical can be self-hosted on your own server or infrastructure.
What is Infisical an alternative to?
Infisical is an open-source alternative to Doppler, AWS Secrets Manager, Akeyless and Azure Key Vault. Other open-source alternatives to Doppler include OpenBao.
Is Infisical actively maintained?
Yes. The most recent commit to Infisical was on 2 October 2026, and the latest release is v0.165.16, published on 23 September 2026. The project has 30k stars on GitHub.

Open-source alternatives to Infisical

See all

SaaS alternatives to Infisical

See all