Infisical

Centralize application secrets, certificates, and privileged access management with end to end encryption across multiple environments.

Infisical screenshot 1

Infisical is an open-source and self-hosted web app and server that provides a comprehensive platform for managing secrets, certificates, and privileged access. It allows teams to centralize application configurations and sensitive credentials across multiple environments, such as development and production, to prevent secret leaks and maintain security consistency across an entire infrastructure.

The software is deployed as a server and web application, with additional interaction available through a dedicated CLI, a REST API, and various client SDKs for Node, Python, Go, Ruby, Java, and .NET. It supports both cloud-managed hosting and on-premises deployment using Docker Compose, allowing organizations to keep their sensitive data on their own infrastructure.

Key features

  • Secret synchronization to platforms including GitHub, Vercel, and AWS
  • Secret versioning with point-in-time recovery and automated rotation
  • Dynamic ephemeral secret generation for databases and message brokers
  • Secret scanning and pre-commit hooks to prevent leaks to git
  • Private PKI for issuing and monitoring X.509 certificates
  • Privileged Access Management with just-in-time access and session recording
  • Kubernetes Operator for automatic secret delivery and deployment reloading
  • Agent Vault proxy to broker AI agent access to external APIs
  • Support for multiple machine identity authentication methods including OIDC and cloud providers

The platform is built with Go and TypeScript and uses PostgreSQL for data storage. It integrates with infrastructure tools like Terraform and Ansible, and provides a Gateway to reach private network resources without opening inbound connections to the local environment. The system includes a dedicated Key Management System for symmetric encryption and decryption of data across projects. For certificate management, it supports both internal CA hierarchies and external integrations with authorities like Let’s Encrypt and DigiCert.

Infisical serves as a security infrastructure layer for developers and security teams managing complex environment variables, identity access, and cryptographic keys.

Last Modified
Software TypeWeb App / Server
Platform
Last Activity14 days ago
Repository Age4 years
LicenseMIT
Open Source Alternative to
Open Source Software.io

Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.