On this page
Overview
Infisical is an open-source security infrastructure platform centered on secrets management and extended to certificates, cryptographic keys, and privileged access. It is available as both cloud and self-hosted software.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Centralize secret storage, sync, and rotation
Manage secrets by environment, sync them to platforms such as GitHub, Vercel, and AWS, retain versions and recovery points, rotate credentials, and issue short-lived dynamic secrets.
Sources: [2]
Manage PKI and certificate lifecycles
Operate private or external certificate authorities and manage X.509 issuance, renewal, revocation, synchronization, expiry alerting, and code-signing workflows.
Sources: [2]
Broker privileged access without exposing underlying credentials
PAM uses user identity to broker access to PostgreSQL, SSH, Kubernetes, Active Directory, and other resources, with session recording and managed credential rotation.
Sources: [2]
Best fit
Fits organizations consolidating DevOps and security credential workflows
It is relevant when CI/CD secrets, machine identities, certificates, keys, and privileged access should share common access controls and audit trails.
Sources: [2]
Before adoption
Design production self-hosting separately from the local Docker quick start
The README provides a Docker Compose path for local evaluation, while production deployments still need deliberate database, availability, backup, and secret-protection design based on the self-hosting documentation.
Sources: [2]
Code under ee/ uses terms separate from the root MIT scope
The root LICENSE assigns a separate license to content under ee/ and makes other covered content available under MIT Expat. GitHub reports the repository SPDX value as NOASSERTION.
Sources: [4]
Official sources
- [1]Infisical/infisical repository(2026-09-30)
- [2]Infisical README(2026-09-30)
- [3]Infisical v0.165.16 release(2026-09-30)
- [4]Infisical repository license(2026-09-30)
Supplemental curator note
Infisical extends beyond environment-variable storage into certificate management and privileged access management on the same platform. The root LICENSE applies separate terms under ee/, so check feature and licensing boundaries together.
Try it in 3 steps
- 1
Clone Infisical
Fetch the official repository for local evaluation. Git and Docker are required.
git clone https://github.com/Infisical/infisical && cd infisical - 2
Create the environment file
Copy the example environment configuration as documented. Do not reuse sample secrets for a production deployment.
cp .env.example .env - 3
Start with Docker Compose
Open http://localhost:80 after startup and create the initial account.
docker compose -f docker-compose.prod.yml up
Growth
Growth trends · Last 30 days
29,525 Stars
Trend data is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- acme
- certificate-management
- cli
- environment-variables
- go
- golang
- node-js
- open-source
- pki
- postgres
- private-ca
- secret-management
- Stars
- 29,525
- Forks
- 2,295
- Watchers
- 76
- Open issues
- 784
- Owner type
- Organization
- Primary language
- TypeScript
- License
- Not determined
- Repository last updated
- Sep 30, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- JumpServer31,685 Stars
2 shared tag(s) · 3 shared category(s)
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - Defguard2,851 Stars
2 shared tag(s) · 3 shared category(s)
combine WireGuard, identity, MFA, and firewall policy in a self-hosted access platform
Rust - Logto14,646 Stars
2 shared tag(s) · 2 shared category(s) · Same language
centralize authentication, authorization, and organizations for SaaS and AI apps on OIDC and OAuth 2.1
TypeScript - Keycloak37,062 Stars
2 shared tag(s) · 2 shared category(s)
an IAM server providing authentication and authorization to applications
Java - Hanko9,035 Stars
2 shared tag(s) · 2 shared category(s)
API-first authentication from passkeys to SSO with native multi-tenancy
Go - OpenBao8,237 Stars
2 shared tag(s) · 2 shared category(s)
encrypt secrets, issue short-lived credentials, and provide PKI/Transit cryptographic services
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.