HashiCorp Vault (IBM)
The reference secrets manager: store, issue, rotate, audit — now issuing SPIFFE identities. Group: Secrets management & detection.
Compiled from published analyses — principally the Aembit vendor guide and the 2026 NHI tools survey — and the vendor's own materials. Date verified: 18 August 2026. Not a hands-on assessment; capabilities and pricing move monthly and corrections are welcome via comms.
What it does
Vault centralises secrets: storage, rotation, on-demand dynamic credentials, encryption as a service, and audit of client interactions. It now natively issues SPIFFE-based workload identities for non-human workloads including agents, bridging the secrets layer and the workload-identity layer.
Key capabilities
- Centralised secrets storage and rotation
- Dynamic, on-demand credentials
- Encryption as a service
- Audit of client interactions
- Native SPIFFE workload identity issuance
Which part of the question it answers
The secrets layer. The cited analysis is candid: it manages credentials rather than eliminating them, and does not by itself establish agent identity, preserve user context, or enforce contextual access policy.
And for rented agents?
A rented agent given a Vault token is still holding a bearer credential — narrower and rotatable, which shrinks the hope without removing it.
Pricing
Open-source edition free; HCP Vault and enterprise tiers priced on the vendor's published pricing page.