# hashicorp-vault

Source: https://startwithidentity.com/vendors/machine-identity/hashicorp-vault/
Last updated: 2026-09-20
License: content by Start with Identity. Cite the source URL.

---

## Overview

HashiCorp Vault is the reference [secrets management](https://startwithidentity.com/guides/fundamentals/what-is-secrets-management/) platform and a cornerstone of [machine identity](https://startwithidentity.com/guides/fundamentals/what-is-machine-identity/) for cloud-native infrastructure. IBM [completed its acquisition of HashiCorp](https://newsroom.ibm.com/2025-02-27-ibm-completes-acquisition-of-hashicorp,-creates-comprehensive,-end-to-end-hybrid-cloud-platform) on 27 February 2025 for 6.4 billion dollars, and business operations moved to IBM on 1 September 2025. Vault 2.0 landed in April 2026, the first major version bump since 2018, driven by the move to IBM's support lifecycle rather than a breaking rewrite; 2.1.1 shipped 16 September 2026.

Vault is source-available under [BUSL 1.1](https://github.com/hashicorp/vault/blob/main/LICENSE), not open source. Each release converts to MPL 2.0 four years after publication, so current releases convert in 2030.

## What it is good at

Dynamic secrets are the signature capability: rather than storing a static database password, Vault generates short-lived credentials on demand and revokes them automatically, shrinking the window that [leaked secrets](https://startwithidentity.com/glossary/secrets-rotation/) create. Breadth is the other argument, with 26 secrets engines, 21 auth methods, and 23 storage backends documented, covering encryption as a service, a strong [PKI](https://startwithidentity.com/glossary/pki/) engine, and KMIP. Three distinct Kubernetes patterns are supported: the Agent Injector webhook, the Vault Secrets Operator, and a CSI provider. Compliance coverage is real, with ISO 27001, 27017, and 27018, PCI DSS v4.0.1 Level 1 for HCP Vault Dedicated, TISAX, and ENS High.

## Where it falls short

Operating Vault well is a genuine responsibility: high availability, seal and unseal, upgrades, and policy design need skilled platform engineers, and teams routinely underestimate it. Six secrets engines and three auth methods are Enterprise-only, including SAML, SPIFFE, and Transform. Pricing is unpublished. FedRAMP status does not appear on HashiCorp's own compliance page and we could not verify it, so federal buyers should confirm directly.

Licensing is the live issue. The BUSL move, then IBM ownership, pushed teams toward [OpenBao](https://openbao.org), the Linux Foundation fork now under OpenSSF governance, which shipped post-quantum ML-DSA support in September 2026.

## Pricing

Vault Community is free to self-host. HCP Vault Dedicated bills per cluster-hour plus per unique active client per month across Starter, Development, Essentials, and Standard editions. No list prices are published. Model the operational cost too, with our [TCO calculator](https://startwithidentity.com/tools/tco-calculator/).

## Best for, and who should look elsewhere

Choose Vault for platform teams needing dynamic secrets, PKI, and broad integration who can operate it. Consider [Akeyless](https://startwithidentity.com/vendors/machine-identity/akeyless/), [Doppler](https://startwithidentity.com/vendors/secrets/doppler/), or [Infisical](https://startwithidentity.com/vendors/secrets/infisical/) for a lower operational floor, or OpenBao if the license is the blocker. Compare [Akeyless vs Vault](https://startwithidentity.com/compare/akeyless-vs-hashicorp-vault/), [AWS Secrets Manager vs Vault](https://startwithidentity.com/compare/aws-secrets-manager-vs-hashicorp-vault/), and [Vault vs Conjur](https://startwithidentity.com/compare/hashicorp-vault-vs-cyberark-conjur/).

## Bottom line

The most capable secrets and machine-identity platform available, for teams with the engineering capacity to run it and no objection to a source-available license.
