Learn the

Provision, Secure, Connect, and Run

Any infrastructure for any application

A Tool for Managing Secrets
Get Started Launch Interactive Tutorial

HashiCorp Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Vault handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more.


Secret Storage

Vault can store your existing secrets, or it can dynamically generate new secrets to control access to third-party resources or provide time-limited credentials for your infrastructure. All data that Vault stores is encrypted. Any dynamically-generated secrets are associated with leases, and Vault will automatically revoke these secrets after the lease period ends. Access control policies provide strict control over who can access what secrets.

Key Rolling

Secrets you store within Vault can be updated at any time. If using Vault's encryption-as-a-service functionality, the keys used can be rolled to a new key version at any time, while retaining the ability to decrypt values encrypted with past key versions. For dynamically-generated secrets, configurable maximum lease lifetimes ensure that key rolling is easy to enforce.

Audit Logs

Vault stores a detailed audit log of all authenticated client interaction: authentication, token creation, secret access, secret revocation, and more. Audit logs can be sent to multiple backends to ensure redundant copies. Paired with Vault's strict leasing policies, operators can easily trace the lifetime and origin of any secret.

Get Started with Vault

Completely free and open source.

Latest Vault News

Vault 0.10 released

We are proud to announce the release of HashiCorp Vault 0.10. This version includes an open source web UI, versioned key-value secrets, Azure authentication, Google Cloud Secrets Engine, Root DB credential rotation, and much more!

Vault 0.9 released

We are proud to announce the release of HashiCorp Vault 0.9. This version includes Identity, Seal Wrap (FIPS 140-2 compliance), new Vault UI, Sentinel integration, cloud auto-unseal, and much more!

Vault 0.8.1 released

We are proud to announce the release of HashiCorp Vault 0.8.1. This version includes Google Cloud IAM authentication, Oracle database backends, self-reloading plugins, and much more!