infisical is by Infisical — not by us.
We indexed this project so people can find it. We are not selling it, we host no copy of the code, and we are not affiliated with or endorsed by its authors — get it from them.
The core of this project is MIT-licensed (detected from the license text; GitHub could not classify it automatically) and free to use. A separate portion is commercially licensed by the publisher — from the upstream license: "Portions of this software are licensed as follows". Read the upstream LICENSE before relying on any enterprise feature.
We flag this because a repository page rarely makes the boundary obvious — you often find out which features are paid only after building on them.
Indexed Aug 1, 2026 · 28,478 stars at index time. Maintainers: claiming verifies your identity and unlocks a higher assurance tier. Removal requests are honored.
Application · for humans & their agents
infisical
unclaimed listingactively maintainedFree coreMIT
Infisical is the open-source platform for secrets, certificates, and privileged access management.
by Open Source Community · New publisher
Every claim on this page is refundable if it is untrue — refund policy.
☆ Save**Infisical/infisical** is an open-source project by Infisical: Infisical is the open-source platform for secrets, certificates, and privileged access management.. Indexed here so it can be found — not resold.
It is free. Get it from the upstream repository: https://github.com/Infisical/infisical
From the project's own README (excerpt, reproduced for discovery under its null license):
The open-source secret management platform : Sync secrets/configs across your team/infrastructure and prevent secret leaks.
Slack Infisical Cloud Self-Hosting Docs Website Twitter Hiring (Remote/SF)
Introduction
Infisical is the open source security infrastructure platform that teams use for secrets, certificates, and privileged access management.
We're on a mission to make security tooling more accessible to everyone, not just security teams, and that means redesigning the entire developer experience from ground up.
Features
Secrets Management:
Centralize your application secrets and configuration across every environment, with versioning, rotation, and leak prevention built in. • Dashboard: Manage secrets across projects and environments (e.g. development, production, etc.) through a user-friendly interface. • Secret Syncs: Sync secrets to platforms like GitHub, Vercel, AWS, and use tools like Terraform, Ansible, and more. • Secret versioning and Point-in-Time Recovery: Keep track of every secret and project state; roll back when needed. • Secret Rotation: Rotate secrets at regular intervals for services like PostgreSQL, MySQL, AWS IAM, and more. • Dynamic Secrets: Generate ephemeral secrets on-demand for services like PostgreSQL, MySQL, RabbitMQ, and more. • Secret Scanning and Leak Prevention: Prevent secrets from leaking to git. • Infisical Kubernetes Operator: Deliver secrets to your Kubernetes workloads and automatically reload deployments. • Infisical Agent: Inject secrets into applications without modifying any code logic. • Honey Tokens: Plant decoy credentials alongside your real secrets that act as tripwires, instantly alerting your team the moment an attacker tries to use them. • Agent Vault:…
Preview
See what it does before you commit. Previews show behavior, never source code.
01Capabilities
Does
- + Secret management
- + Role-based access control
- + Audit logs
- + Authentication
- + Programmatic API
- + Webhooks
- + Data synchronization
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
- → PostgreSQL database
- → Authentication
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
This listing is unclaimed, so publisher identity cannot be verified and it stays below the “verified” tier by design — that is a statement about the listing, not about the project’s quality. Our automated scans still ran; a maintainer who claims it unlocks identity verification.
- publisher identity Publisher status verified; 0 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns detected in reviewed content
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 0.0.0 | stable | Aug 1, 2026 | Indexed listing — see the upstream repository for real release history. |