Skip to content

Which Secrets Manager? Explained

Answer a few questions about team size, whether you need rotation and audit logs, your budget for self-hosting, and where your apps run to choose between .env files, a managed vault, HashiCorp Vault, or a team password manager.

A secrets manager stores values your code must not hardcode: API keys, database URLs, tokens. The decision turns on four forces: how many people and services share them, whether you must rotate and audit, how much you will operate yourself, and where the consuming apps run. Answer below to get a recommendation, ranked against the alternatives.

Decision guide · 4 options

The options

.env files

Plain key=value files loaded into the process environment.

Solo developers and small local projects where simplicity beats ceremony and secrets never leave the machine. Never commit the file.

Managed vault (Doppler, AWS Secrets Manager, GCP)

A hosted service that centralizes secrets and injects them at runtime.

Teams that want rotation, audit logs, and per-environment config without running their own infrastructure.

HashiCorp Vault

A self-hosted secrets and encryption platform with dynamic secrets.

Security-conscious or regulated organizations that need fine-grained policies, dynamic short-lived secrets, and full control on their own hardware or cloud.

Team password manager (1Password, Bitwarden)

A shared vault with a CLI and secrets-injection for smaller teams.

Small teams who already share logins and want one tool for both human credentials and machine secrets, with low operational overhead.

Which one fits you?

Answer a few questions to get a recommendation.

Question 1 of 4

Who consumes the secrets?