# secrets-management

Source: https://startwithidentity.com/glossary/secrets-management/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

Centralized storage, distribution, rotation, and audit of credentials used by applications and infrastructure. Modern secrets management issues short-lived dynamic credentials rather than long-lived static secrets.

The measure of a secrets program is not how many secrets are in the vault but how many exist outside it, and the winning move is issuing short-lived dynamic credentials so there is nothing durable to steal. Vaulting a static database password improves auditability; generating a 15-minute one on demand removes the asset. Most incidents still start with a credential in a repository, not in a vault.

See also: [what is secrets management](https://startwithidentity.com/guides/fundamentals/what-is-secrets-management/), [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/), [workload identity](https://startwithidentity.com/glossary/workload-identity/), [secrets vendors](https://startwithidentity.com/vendors/secrets/)
