AWS Secrets Manager is the simpler choice if your workloads run on AWS; HashiCorp Vault is the stronger choice if you run across several clouds or on-premises, or need dynamic secrets, PKI and encryption as a service from one platform. Secrets Manager is fully managed, integrates natively with IAM, KMS and AWS databases, and costs nothing to operate beyond per-secret and per-request fees. Vault works anywhere, generates short-lived credentials for many systems, and acts as a certificate authority, but someone has to run it, or you pay HashiCorp to run it for you.
This comparison covers architecture, features, security model, operations and pricing models, then answers a related question that confuses many AWS teams: AWS Secrets Manager vs AWS KMS. For the wider market, see our guide to the best secrets management tools.
HashiCorp Vault vs AWS Secrets Manager at a glance
| Area | HashiCorp Vault | AWS Secrets Manager |
|---|---|---|
| Where it runs | Anywhere: self-managed on VMs or Kubernetes, or HashiCorp-managed cloud | AWS regions only, fully managed |
| Scope | Multi-cloud, on-premises, hybrid | AWS workloads (reachable from elsewhere with AWS credentials) |
| Static secrets | Key/value engine with versioning | Secrets with versioning and staging labels |
| Dynamic secrets | Yes: databases, AWS, Azure, GCP, SSH and more, with leases | No; rotates long-lived secrets on a schedule |
| Rotation | Built into dynamic engines; static rotation for some engines | Lambda-based rotation, including managed rotation for supported AWS databases |
| PKI and certificates | Built-in private certificate authority | Separate AWS services handle certificates |
| Encryption as a service | Transit engine | Uses AWS KMS for its own encryption; app encryption goes through KMS directly |
| Authentication | Kubernetes, AWS IAM, Azure, GCP, OIDC, LDAP, AppRole, TLS certificates | AWS IAM identities and resource policies |
| Multi-tenancy | Namespaces in enterprise editions | AWS accounts and IAM boundaries |
| Operations | You run HA clusters, unsealing, upgrades and backups (unless managed) | None beyond configuration |
| Pricing model | Free community edition; enterprise and managed editions by usage or quote | Per secret per month plus per 10,000 API calls |
What is the core difference between Vault and AWS Secrets Manager?
AWS Secrets Manager is a managed store for long-lived secrets inside AWS. You put a database password or API key in, grant IAM roles permission to read it, and optionally let AWS rotate it on a schedule. It does one job well and needs no infrastructure.
Vault is a security platform built around the idea that secrets should be short-lived and identity-based. Instead of storing a database password, Vault can create a unique database user for each application instance with a lease of, say, an hour, and revoke it automatically. It does the same for cloud credentials, SSH certificates and TLS certificates, and it encrypts data for applications without handing them keys. That breadth is why platform teams pick it; the cost is operational complexity.
Features compared
Dynamic secrets vs scheduled rotation
Rotation changes a long-lived secret periodically; everyone who reads it gets the new value. Dynamic secrets give each consumer its own credential that expires. Dynamic secrets limit blast radius more, because a leaked credential identifies exactly which workload leaked it and dies on its own. Secrets Manager rotation is simpler to adopt for existing apps that expect one shared password.
Access control
Secrets Manager uses IAM policies and resource policies, which AWS teams already know, plus KMS key policies for the encryption key. Vault uses its own policy language attached to tokens issued after authentication. Vault’s AWS auth method lets EC2 instances, Lambda functions and IAM roles log in with their AWS identity, so Vault can still lean on IAM for workloads running in AWS.
Kubernetes
Both integrate with Kubernetes. Vault offers an agent injector, a CSI provider and a secrets operator, and authenticates pods by service account. Secrets Manager works with EKS through the Secrets Store CSI driver with the AWS provider or through External Secrets Operator, using IAM roles for service accounts.
Multi-region and disaster recovery
Secrets Manager replicates secrets to other AWS regions on request. Vault supports replication between clusters in enterprise editions; community edition users rely on backups and integrated storage snapshots.
Audit
Secrets Manager API calls are logged in AWS CloudTrail. Vault writes detailed audit logs of every request to file, syslog or socket devices. Both feed a SIEM; see SIEM vs SOAR for how security teams use that data.
Security model
Secrets Manager encrypts each secret with an AWS KMS key, either the AWS managed key or a customer managed key you control. Access requires both IAM permission to the secret and permission to use the key. Vault encrypts its storage with a root key protected by an unseal mechanism: key shares held by operators, or auto-unseal through a cloud KMS or HSM. In both cases, the strongest control is limiting who and what can authenticate, and keeping human access to production secrets rare and logged. Human admin access is a job for privileged access management tools.
Operations and total cost
This is where many decisions are made. Running Vault in production usually means a three- or five-node cluster, integrated storage or a backend, TLS, auto-unseal configuration, monitoring, upgrades and a documented recovery plan. That is platform engineering time every month. HashiCorp’s managed service removes most of that work for a subscription. AWS Secrets Manager has no servers to run; your cost is the per-secret and per-call fees plus the time spent writing rotation functions for non-AWS systems.
Rules of thumb: a handful of AWS accounts with standard databases favours Secrets Manager; dozens of teams across clouds and data centers favours Vault, where central policy and dynamic secrets pay back the operating cost.
Vault vs AWS Secrets Manager pricing
AWS Secrets Manager charges a monthly fee for each secret stored and a fee per 10,000 API calls; replica secrets are billed as additional secrets. Caching secrets in applications with AWS’s caching libraries keeps call volume down. Check current pricing on the AWS Secrets Manager pricing page or our AWS Secrets Manager pricing summary.
Vault’s community edition has no license fee but carries infrastructure and staffing costs. Enterprise features such as namespaces, replication and advanced governance come with commercial editions, and the managed cloud version is billed by usage. See our HashiCorp Vault pricing page and check current pricing with HashiCorp.
AWS Secrets Manager vs KMS: what is the difference?
They solve different problems and work together. AWS Key Management Service (KMS) creates and controls encryption keys. The keys never leave KMS’s hardware-backed boundary in plaintext; applications send data or data keys to KMS to encrypt or decrypt. AWS Secrets Manager stores secret values, such as passwords and tokens, and uses KMS keys to encrypt them.
| Question | AWS KMS | AWS Secrets Manager |
|---|---|---|
| What does it protect? | Encryption keys | Secret values (passwords, API keys, tokens) |
| Can you read the stored value? | No, keys are used inside KMS | Yes, authorised callers retrieve the secret |
| Rotation | Automatic key rotation for KMS keys | Rotation of the secret value via Lambda |
| Typical use | Encrypt S3, EBS, RDS and application data | Supply credentials to applications |
| Pricing model | Per key per month plus per request | Per secret per month plus per API call |
Use KMS when you need to encrypt data; use Secrets Manager when an application needs to fetch a credential. If you are tempted to store a password encrypted with KMS in a config file, Secrets Manager is the managed version of that pattern with rotation and audit built in. Our AWS KMS vs AWS Secrets Manager page lists them side by side.
What about Parameter Store and Azure Key Vault?
AWS Systems Manager Parameter Store holds configuration values and SecureString parameters encrypted with KMS. It is cheaper and fine for simple config, but lacks built-in rotation and cross-region replication of secrets. Teams often use Parameter Store for configuration and Secrets Manager for credentials. On Azure, Azure Key Vault combines the jobs of KMS and Secrets Manager in one service, managing keys, secrets and certificates together.
Common mistakes with either tool
- Solving “secret zero” with another static secret. If an app needs a hard-coded token to log in to Vault, the problem has moved, not gone. Use platform identity: IAM roles in AWS, Kubernetes service accounts, or OIDC tokens from CI.
- Granting wildcard read access. A policy that lets every role read every secret turns the manager into a single point of compromise. Scope paths or resource ARNs per application.
- Fetching on every request. Calling the API for each transaction drives cost and latency. Cache with a sensible refresh interval.
- Enabling rotation without testing consumers. Apps that read a secret only at startup break after rotation. Test reload behaviour before turning rotation on in production.
- Ignoring humans. Engineers with console access can often read production secrets directly. Limit that with just-in-time access and log every human read.
When to choose each
| Situation | Better fit |
|---|---|
| All workloads on AWS, small platform team | AWS Secrets Manager |
| Workloads across AWS, Azure, Google Cloud and data centers | HashiCorp Vault |
| Need per-workload, short-lived database credentials | HashiCorp Vault |
| Need a private certificate authority and app-level encryption service | HashiCorp Vault |
| Want zero infrastructure to operate | AWS Secrets Manager (or managed Vault) |
| Strict open source license requirement | OpenBao, the open source Vault fork |
Many organisations run both: Vault as the central platform, with Secrets Manager holding secrets for AWS-native services, or Vault’s AWS secrets engine issuing short-lived AWS credentials. If neither fits, compare AWS Secrets Manager alternatives and HashiCorp Vault alternatives, or see the side-by-side AWS Secrets Manager vs HashiCorp Vault page.
Is HashiCorp Vault better than AWS Secrets Manager?
It is more capable, not always better. Vault adds dynamic secrets, PKI, encryption as a service and multi-cloud reach. Secrets Manager is simpler and needs no operations, which makes it the better fit for AWS-only teams.
Can Vault use AWS KMS?
Yes. Vault can auto-unseal with an AWS KMS key, and its AWS secrets engine can issue short-lived AWS credentials to workloads.
Does AWS Secrets Manager rotate secrets automatically?
Yes, on a schedule you set. Supported AWS databases have managed rotation; other systems need a rotation Lambda function that knows how to change the credential.
Is AWS Secrets Manager the same as KMS?
No. KMS manages encryption keys that never leave the service; Secrets Manager stores secret values that applications retrieve, encrypted with KMS keys.
Can I use AWS Secrets Manager outside AWS?
Yes, any system with AWS credentials can call the API, but you then need to manage those credentials somewhere, which is the problem you were trying to solve. Multi-environment estates usually prefer a platform-neutral manager.
How do I migrate from Secrets Manager to Vault?
Inventory secrets and consumers, set up Vault auth for each workload platform, copy static secrets into Vault’s key/value engine, switch applications to read from Vault, then replace static database credentials with dynamic ones team by team.
Compare alternatives to the tools in this post
Related Articles
Buyers guide
Best MFA Software in 2026: 12 Multi-Factor Authentication Tools Compared
Continue reading →
Best Tools
9 Best SailPoint Alternatives in 2026 (IGA Tools Compared)
Continue reading →
Cybersecurity
1Password vs Bitwarden for Business (2026): SSO, SCIM and Cost Per User
Continue reading →
Cybersecurity
Teleport vs StrongDM (2026): Infrastructure Access Compared, Plus Alternatives
Continue reading →
