# Infisical/infisical

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Repository: https://github.com/Infisical/infisical
Canonical: https://ross.abutalabs.com/products/infisical
Homepage: https://infisical.com
Language: TypeScript
License: NOASSERTION
License Family: other
Topics: cli, environment-variables, secret-management, secrets, security, open-source, golang, typescript, secret-manager, go, postgres, secret-scanning, security-tools, certificate-management, private-ca, pki, acme, node-js, secrets-management, vault
Last push: 2026-08-27T00:24:44+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 87, longevity 100
- inputs: {"age_days": 1489, "days_push": 7, "days_rel": 6, "gap_med": 1, "n_releases_24m": 304}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 28981, forks 2221 (observed 2026-08-28T04:11:52.971025+00:00)

## What it is
Infisical is an open-source platform for secrets management, certificate lifecycle management, KMS, and privileged access management, usable as a hosted service or self-hosted. It centralizes application secrets with versioning, rotation, dynamic secrets, RBAC, audit logs, and integrations for CI/CD, Kubernetes, and AI agent credential brokering.

## Use cases
- manage environment variables and api keys across teams
- self-host a vault alternative for secrets
- rotate database and cloud credentials automatically
- prevent hardcoded secrets leaking into git and ci
- issue short-lived dynamic credentials for services
- manage x509 certificates and private ca
- give ai agents api access without exposing secrets
- sync secrets to aws, vercel, and github actions

## When to choose
- you need a centralized, developer-friendly secrets manager with a dashboard, CLI, and SDKs
- you want self-hosting with secret rotation, dynamic secrets, and audit logs in one platform
- your team is replacing scattered .env files and ad-hoc secret stores

## When to avoid
- you only need simple local .env file handling with no team sharing
- you require an FIPS-certified or compliance-heavy enterprise vault with HSM clustering out of the box
- you need a minimal library rather than a full platform to operate

## Facets
- artifact type: service
- maturity: stable
- function: secrets-management, security, cryptography, configuration-management, auth, authorization, cli, self-hosted, developer-tools
- domain: security, developer-tools, self-hosted, cloud-computing
- platform: self-hosted, cli, cross-platform, cloud
- tags: secret-manager, environment-variables, pki, certificate-management, kms, privileged-access-management, secret-scanning, vault-alternative, dynamic-secrets, agent-proxy, devops, docker, kubernetes, web-server

## Member repositories
- Infisical/infisical (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:52.971025+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:53:16.185445+00:00, confidence not recorded.
  - readme: https://github.com/Infisical/infisical (fetched 2026-08-28T04:11:52.971025+00:00, sha b82370bd3077)
  - homepage: https://infisical.com (fetched 2026-08-29T07:50:54.559622+00:00, sha 957b318bce91)
  - site_page: https://infisical.com/docs (fetched 2026-08-29T07:50:54.565632+00:00, sha 87c6665df10e)
  - site_page: https://infisical.com/docs/documentation/getting-started/overview (fetched 2026-08-29T07:50:54.567400+00:00, sha cd569bb47a6e)
  - site_page: https://infisical.com/docs/documentation/platform/secrets-mgmt/overview (fetched 2026-08-29T07:50:54.570208+00:00, sha 3a1726da67d6)
  - site_page: https://infisical.com/docs/documentation/platform/access-controls/overview (fetched 2026-08-29T07:50:54.572897+00:00, sha 1485ec4400dc)
  - site_page: https://infisical.com/docs/documentation/platform/secret-rotation/overview (fetched 2026-08-29T07:50:54.575457+00:00, sha 6f6d9f9f6588)
  - site_page: https://infisical.com/docs/documentation/platform/pr-workflows (fetched 2026-08-29T07:50:54.577407+00:00, sha 0bd0a1675d9f)
  - site_page: https://infisical.com/docs/documentation/platform/agent-proxy/overview (fetched 2026-08-29T07:50:54.579299+00:00, sha 67bdcdefe103)
  - site_page: https://infisical.com/pricing (fetched 2026-08-29T07:50:54.562710+00:00, sha 0175d24e15fa)
- Data as of 2026-08-30T08:39:29.467469+00:00.
