HashiCorp Vault
Capability scores
Methodology →- Authentication
- 4.5
- SSO & Federation
- 3.5
- Authorization
- 4.5
- Lifecycle & Provisioning
- 4.0
- MFA & Passwordless
- 3.0
- Governance & Audit
- 4.0
- Developer Experience
- 3.5
- Deployment Flexibility
- 4.5
- Pricing Transparency
- 2.0
- Support & Ecosystem
- 4.5
Scored 0–5 against a published rubric. Independent analysis, no vendor sponsorship.
Overview
HashiCorp Vault is the reference secrets management platform and a cornerstone of machine identity for cloud-native infrastructure. IBM completed its acquisition of HashiCorp on 27 February 2025 for 6.4 billion dollars, and business operations moved to IBM on 1 September 2025. Vault 2.0 landed in April 2026, the first major version bump since 2018, driven by the move to IBM's support lifecycle rather than a breaking rewrite; 2.1.1 shipped 16 September 2026.
Vault is source-available under BUSL 1.1, not open source. Each release converts to MPL 2.0 four years after publication, so current releases convert in 2030.
What it is good at
Dynamic secrets are the signature capability: rather than storing a static database password, Vault generates short-lived credentials on demand and revokes them automatically, shrinking the window that leaked secrets create. Breadth is the other argument, with 26 secrets engines, 21 auth methods, and 23 storage backends documented, covering encryption as a service, a strong PKI engine, and KMIP. Three distinct Kubernetes patterns are supported: the Agent Injector webhook, the Vault Secrets Operator, and a CSI provider. Compliance coverage is real, with ISO 27001, 27017, and 27018, PCI DSS v4.0.1 Level 1 for HCP Vault Dedicated, TISAX, and ENS High.
Where it falls short
Operating Vault well is a genuine responsibility: high availability, seal and unseal, upgrades, and policy design need skilled platform engineers, and teams routinely underestimate it. Six secrets engines and three auth methods are Enterprise-only, including SAML, SPIFFE, and Transform. Pricing is unpublished. FedRAMP status does not appear on HashiCorp's own compliance page and we could not verify it, so federal buyers should confirm directly.
Licensing is the live issue. The BUSL move, then IBM ownership, pushed teams toward OpenBao, the Linux Foundation fork now under OpenSSF governance, which shipped post-quantum ML-DSA support in September 2026.
Pricing
Vault Community is free to self-host. HCP Vault Dedicated bills per cluster-hour plus per unique active client per month across Starter, Development, Essentials, and Standard editions. No list prices are published. Model the operational cost too, with our TCO calculator.
Best for, and who should look elsewhere
Choose Vault for platform teams needing dynamic secrets, PKI, and broad integration who can operate it. Consider Akeyless, Doppler, or Infisical for a lower operational floor, or OpenBao if the license is the blocker. Compare Akeyless vs Vault, AWS Secrets Manager vs Vault, and Vault vs Conjur.
Bottom line
The most capable secrets and machine-identity platform available, for teams with the engineering capacity to run it and no objection to a source-available license.
HashiCorp Vault: frequently asked questions
- Is HashiCorp Vault still open source?
- No, not by the OSI definition. Vault moved from MPL 2.0 to the Business Source License 1.1 on 10 August 2023, first shipping under it in version 1.15.0. BUSL 1.1 is source-available: you can read, modify, and run the code in production, but you may not offer it to third parties on a hosted or embedded basis in competition with IBM's paid versions. That field-of-use restriction is why BUSL is not an OSI-approved license, and why the OpenBao fork exists. HashiCorp APIs, SDKs, and most other libraries remain MPL 2.0.
- When does Vault's license convert back to open source?
- Each release converts individually, four years after that release is published, at which point it becomes MPL 2.0. This is a rolling per-release Change Date, not a single calendar date, and most secondary sources get it wrong. Vault 1.15.0, published September 2023, converts around September 2027. Vault 2.1.1, published September 2026, does not convert until September 2030. So Vault as a shipping product never becomes open source under this arrangement; only individual four-year-old releases do.
- How much does HashiCorp Vault cost?
- IBM and HashiCorp do not publish list pricing for Vault. Terraform has published tiers; Vault does not, and its pricing page routes to a sales contact. The billing model for HCP Vault Dedicated is documented: clusters are billed per hour from creation to deletion (partial hours billed by the minute), plus a monthly charge for unique active clients. A client is an application, service, or user consuming the cluster, counted once per month, and a secret with a configured sync destination counts as a unique client. Editions are Starter, Development (capped at 25 clients per month), Essentials, and Standard, across Extra Small to Large cluster sizes. The per-hour and per-client dollar figures circulating online come from competitor blogs that contradict each other, so we do not repeat them. Vault Community is free to self-host.
- Is HCP Vault Secrets still available?
- No. HCP Vault Secrets reached end of sale on 30 June 2025 and end of life on 1 July 2026, so it is gone as of this review. The documented migration path is HCP Vault Dedicated or self-hosted Vault Community. Any comparison or review still listing HCP Vault Secrets as a current tier is out of date.
- What changed after IBM acquired HashiCorp?
- IBM completed the acquisition on 27 February 2025 at 6.4 billion dollars enterprise value, 35 dollars per share. Business operations moved to IBM on 1 September 2025. The LICENSE file now names IBM as licensor, compliance requests route to IBM rather than HashiCorp, and the self-managed product is sold as IBM Vault Self-Managed under IBM product ID 5900-BJF, with Boundary sold under the same product ID. Support moved to IBM Support Cycle-2 from April 2026, guaranteeing a minimum of two years of standard support per major release. The product still ships and documents under the Vault name, so this is IBM branding on SKUs, billing, and lifecycle rather than a full rename.
- What is OpenBao and is it a real alternative to Vault?
- OpenBao is the fork of Vault created after the BUSL relicensing, governed under the Linux Foundation and, since June 2025, OpenSSF. It is materially mature: v2.6.2 shipped in August 2026, and the v2.7 beta in September 2026 added external key support for PKI and Transit via KMS plugins plus ML-DSA post-quantum signatures and pure post-quantum TLS. The v2.6 cycle drew 42 first-time contributors. Notably, OpenBao is now diverging from Vault rather than merely tracking it, shipping post-quantum cryptography and namespace sealing ahead of upstream. For teams whose objection is the license rather than the capability, it is a credible destination.
- Is Vault FIPS 140-3 validated?
- Not exactly, and the distinction matters. Vault Enterprise ships FIPS builds using BoringCrypto, which holds NIST CMVP certificate 4735, with binaries carrying the +ent.fips1403 and +ent.hsm.fips1403 suffixes. FIPS 140-3 Level 1 compliance was added in Vault Enterprise 1.21, with support stated from 1.19.4. However, HashiCorp's own documentation states that the 140-3 certificate belongs to the BoringCrypto module rather than to Vault, and that Vault's own full 140-3 evaluation is pending. Accurate phrasing: Vault Enterprise ships validated cryptography; Vault as a product is not itself 140-3 validated.
- What are the best HashiCorp Vault alternatives?
- OpenBao if the BUSL license is the objection and you want a drop-in fork. AWS Secrets Manager or Azure Key Vault if you are single-cloud and want the native option with no operational burden. Akeyless, Doppler, or Infisical if you want managed secrets with a lower operational floor than Vault. CyberArk Conjur if you need secrets management inside an established enterprise privileged access programme. Vault remains the broadest option, with 26 secrets engines, 21 auth methods, and 23 storage backends, but breadth is exactly what you pay for in operational complexity.
HashiCorp Vault comparisons
More Machine Identity vendors
All Machine Identity →- SPIFFE / SPIRE4.5/5
- Venafi4.4/5
- Akeyless4.3/5
- SPIRL3.9/5
Related on Start with Identity
- Comparisonspiffe-spire-vs-hashicorp-vault
SPIFFE and SPIRE answer who a workload is. HashiCorp Vault answers what it may hold. They overlap enough to compare and differ enough that many teams run both.
- ArticleHashiCorp Vault Alternatives: 7 Options Compared
Vault is source-available under BUSL, not open source, and now sits inside IBM. Seven alternatives compared on licensing, operational burden and what you actual
- CVEHashiCorp Vault LDAP auth username enumeration
Vault's LDAP auth method returned different errors for unknown and known users. Enumeration is how a lockout or MFA-bypass chain starts. Fixed in 1.14.1 and the
- ComparisonHashiCorp Vault vs AWS Secrets Manager vs Doppler
These three secrets managers sit at different points on the control-versus-convenience spectrum. HashiCorp Vault is a portable platform with the deepest dynamic
- CVEVaultFault, first public HashiCorp Vault RCE
Vault's plugin catalog and audit-log handling combined into remote code execution. Cyata, Black Hat USA 2025. A flaw about nine years old. CVSS 9.1. Fixed in Va
- VendorSPIFFE / SPIRE
top_tier
By SWI Community Team · Last evaluated 2026-09-20
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].