Secrets management choices are messy because the category spans broad secrets platforms, certificate automation, Kubernetes operators, Git-native workflows, .env syncing, and smaller self-hostable vaults.

The ranking uses only open/source-visible tools, sorted by ToolVitals score descending, with GitHub stars used as the secondary popularity signal when needed.

Rankings

Rank Tool Openness License Health Shipping GitHub Stars Score Status
1 Infisical OSI-approved OSS MIT 93 100 27525 97 🟢 Excellent
2 OneCLI OSI-approved OSS Apache-2.0 91 100 2416 96 🟢 Excellent
3 Phase OSI-approved OSS MIT 90 89 878 92 🟢 Excellent
4 certd OSI-approved OSS AGPL-3.0 84 95 4846 91 🟢 Excellent
5 SecretZero OSI-approved OSS Apache-2.0 81 84 6 87 🟢 Excellent
6 OpenBao Operator OSI-approved OSS Apache-2.0 76 90 18 84 🟢 Excellent
7 Relic OSI-approved OSS MIT 61 47 175 67 🟢 Good
8 Arcan OSI-approved OSS Apache-2.0 41 20 0 47 🟡 Fair
9 Dotenv Vault OSI-approved OSS MIT 36 0 1242 37 🔴 Needs Attention
10 EnvSecrets OSI-approved OSS Apache-2.0 31 0 96 33 🔴 Needs Attention
11 Envie OSI-approved OSS Apache-2.0 28 0 127 28 🔴 Needs Attention

Top 3 Highlights

Infisical ranks first with a ToolVitals score of 97, the highest score in the set, plus a 93 health score and 100 shipping score. It also has the strongest popularity signal at 27,525 GitHub stars. The supplied description positions it as a platform for secrets, certificates, and privileged access management. Its openness_label is OSI-approved OSS and its license_label is MIT.

OneCLI ranks second with a ToolVitals score of 96, only one point behind Infisical, and also has a 100 shipping score. Its 91 health score is the second-highest health score in the dataset. The description is narrower than Infisical’s: an open-source credential vault for AI agents. Its openness_label is OSI-approved OSS and its license_label is Apache-2.0.

Phase ranks third with a ToolVitals score of 92, a 90 health score, and an 89 shipping score. It has 878 GitHub stars, so its standing comes more from the ToolVitals metrics than from broad GitHub popularity. The description frames it around application secrets and configuration management for developers. Its openness_label is OSI-approved OSS and its license_label is MIT.

Want to see the full health, shipping, openness, and evidence details for every tool in Secrets Management? Browse all Secrets Management Tools →