No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Secrets Manager vs HashiCorp Vault comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Secrets Manager
Ranking in Enterprise Password Managers
3rd
Ranking in Secrets Management Tools
3rd
Average Rating
9.0
Reviews Sentiment
6.8
Number of Reviews
17
Ranking in other categories
No ranking in other categories
HashiCorp Vault
Ranking in Enterprise Password Managers
4th
Ranking in Secrets Management Tools
1st
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
28
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Enterprise Password Managers category, the mindshare of AWS Secrets Manager is 12.9%, down from 16.5% compared to the previous year. The mindshare of HashiCorp Vault is 4.6%, down from 10.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Enterprise Password Managers Mindshare Distribution
ProductMindshare (%)
AWS Secrets Manager12.9%
HashiCorp Vault4.6%
Other82.5%
Enterprise Password Managers
 

Q&A Highlights

NC
Content Manager at PeerSpot
 

Featured Reviews

Mahadev Metre - PeerSpot reviewer
Dev Ops Engineer at Paydoh
Consistent security and efficiency improvements optimize IT infrastructure with effective management
When creating AWS Secrets Manager, it should be automated using tools such as Terraform, Puppet, or Ansible. With Terraform code, you specify the encryption key, secret name, rotation policy, and secret replication. Human error occurs when feeding secret values manually, especially with large amounts of secrets to input. Secrets should never be protected only by IAM. They should be protected by multiple layers, such as IAM and one or two KMS keys. Additional security measures could be beneficial if necessary. The rotation policy is crucial because some secrets may become obsolete, require updates, or get compromised. With a weekly rotation policy, if unauthorized access occurs, the exposure is limited to seven days. The rotation policy can be customized according to needs.
Manish Indupuri - PeerSpot reviewer
senior DevOps engineer at a tech services company with 10,001+ employees
Centralized secret management has strengthened security and simplified compliance across cloud-native environments
Configuring HashiCorp Vault since we are mainly using it in Kubernetes or OpenShift clusters took some time and effort to align with our deployment. The initial setup can be a little confusing and complex for someone who is newer. However, it is not impossible to achieve, but it will take some time to understand the product. The ACLs within HashiCorp Vault, such as policies and AppRole authentication, were not intuitive at first. However, we slowly became habituated to the product once we began using it. Once we moved past the learning curve of these challenges, HashiCorp Vault becomes a critical security layer of our workloads. The only minor challenge is the initial setup complexity, especially for teams new to HashiCorp Vault's authentication methods and storage backends. Other than that, it works flawlessly.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The API is fine and works well."
"I would highly recommend AWS Secrets Manager for secret management in AWS."
"I would recommend everyone to use AWS Secrets Manager for their security and for storing their passwords, because I see that passwords nowadays are easily compromised."
"Integrating with other services was straightforward, especially within the AWS environment."
"The most valuable feature is the management of credentials."
"All our workloads are running on AWS, so integration with our workload is much easier on AWS Secrets Manager than going with another solution such as Thycotic."
"The most valuable feature is security."
"The most valuable feature of AWS Secrets Manager is the ability to keep data secret and assign access permissions to people to grant or restrict access."
"The most valuable feature of HashiCorp Vault is the management of tickets in the pipeline."
"It is user-friendly and easy to implement from any application point."
"HashiCorp Vault ticked all the boxes for us, and I couldn't fault it."
"The product is free and easy to use. It is well documented with an easy implementation process."
"It is a good product to consider for companies who are looking to build on-premise or hybrid infrastructure."
"HashiCorp Vault has positively impacted my organization because several teams use it in the same way for an automated process with GitHub Actions or other pipeline tools."
"We use the solution for secret management."
"We were using it because we have compliance requirements around secret management. Having a secure vault and encrypting data was an additional requirement. When we looked at it first, we were just looking for a vault, like a lockbox. The greatest benefit of HashiCorp is its ability to manage encryption on the fly. It provides encryption of data at rest, in use, in transit, on the fly, and linked with applications, which was really attractive."
 

Cons

"There is a need for better environmental implementation, such as having a security fund as a solution."
"The price of the solution could improve."
"If you don't have enterprise support, then you will not be able to get through to them to get the help. It is not only applicable to AWS Secrets Manager. It is also applicable to any service on AWS."
"The solution's initial setup process is complicated."
"If you add one more layer of security to AWS Secrets Manager, even the programmer will not be able to see the secrets."
"The only concern with AWS Secrets Manager is its cost, which can be prohibitive for small organizations."
"There is room for improvement in the pricing model."
"We contacted AWS support and waited approximately an hour for assistance."
"The technical support was hard to get a hold of and lacking in service."
"While not a missing feature, I feel that the enterprise license is expensive, especially for some of the smaller use cases."
"We could use more documentation, primarily to do with integrations."
"The product is complicated to install."
"It would be helpful to have more advanced features."
"The ACLs within HashiCorp Vault, such as policies and AppRole authentication, were not intuitive at first."
"The product needs to improve its customization. It should be also more like easy to plug and play."
"In terms of features, the only thing that I found a little bit hinky was that there was no revocation or deletion on the model we were using. Once in a financial year, a client interacts, and you pay for that client for the year. So, there are just little things like that in the pricing. There should be more clarity around the end of the key. I know there is no system like this. They all are the same. I tested Microsoft, Google, and some others, and none of them really want you to delete a key, which makes sense. You delete a key, and you lose everything that it has wrapped or encrypted, but it's actually just a language. Deletion isn't really deletion. It's really revocation, but overall, HashiCorp Vault ticked all the boxes for us, and I couldn't fault it."
 

Pricing and Cost Advice

"The cost is somewhat high."
"We purchase a monthly license for the product."
"We've observed that AWS Secrets Manager pricing is based on a per-secret-per-month model. As a result, we prefer to divide our secrets into individual pieces to increase security and grant specific access permissions to certain secrets, systems, or individuals. However, this approach results in higher costs. Therefore, we have been exploring ways to combine our secrets into groups to reduce expenses and simplify management. Nonetheless, we acknowledge that this issue may not be related to the secret manager's functionality."
"The solution is expensive."
"I don't believe there is a license cost for the solution."
"I am using the open-source version of Vault and I would have to buy a license if I want to get support."
"The solution's cost is reasonable."
"The AWS version is much cheaper than HashiCorp Vault."
"In my case, the open-source version works well. It's advisable for small to medium-scale organizations, but for large-scale organizations, you should go with the enterprise version."
"It could do everything we wanted it to do and it is brilliant, but it is super pricey. To be fair to HashiCorp, we drove the price up with our requirements around resiliency. Because of the nature of our company, we don't really operate in the cloud."
"The product is expensive."
report
Use our free recommendation engine to learn which Enterprise Password Managers solutions are best for your needs.
912,022 professionals have used our research since 2012.
 

Answers from the Community

NC
Content Manager at PeerSpot
Dec 12, 2021
Dec 12, 2021
HashiCorp Vault was designed with your needs in mind. One of the features that makes this evident is its ability to work as both a cloud-agnostic and a multi-cloud solution. As a cloud-agnostic solution, HashiCorp Vault allows you to be flexible in the cloud infrastructure that you choose to use. It is completely compatible and integratable with a myriad of different platforms. You can determin...
See 2 answers
KK
Works at Zerto
Nov 23, 2021
yet to learn both
DG
Tech blogger
Dec 12, 2021
HashiCorp Vault was designed with your needs in mind. One of the features that makes this evident is its ability to work as both a cloud-agnostic and a multi-cloud solution. As a cloud-agnostic solution, HashiCorp Vault allows you to be flexible in the cloud infrastructure that you choose to use. It is completely compatible and integratable with a myriad of different platforms. You can determine what you want to use and HashiCorp Vault will function without issue, regardless of what you choose. If you are using HashiCorp Vault as a multi-cloud solution, then you have an even greater number of platform options. You will be able to mix and match which cloud platforms you like to use to customize your data protection. The only limits on your customization will end up being your imagination. HashiCorp Vault’s user interface is simple for you to both use and navigate. The UI was designed to be basic enough for users to manage without forcing an organization to spend a great deal of time and resources having to train employees in its use. It might be a little confusing for employees when they start using it. However, once they have used it for a little while they will be proficient in its use. Should an organization choose to invest in training employees in the use of this UI, the required investment will be minimal. AWS Secrets Manager is an extremely user-friendly solution. It is intuitive in its design, which makes it a valuable product. However, AWS Secrets Manager lacks the level of cloud flexibility that HashiCorp Vault offers. Conclusion: While AWS Secrets Manager is a fairly competent product, we found HashiCorp Vault to be superior. HashiCorp Vault‘s greater flexibility and integration capabilities make it the more robust solution.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Comms Service Provider
9%
Manufacturing Company
8%
Computer Software Company
8%
Financial Services Firm
18%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Large Enterprise10
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise17
 

Questions from the Community

Which is better - Azure Key Vault or AWS Secrets Manager?
Azure Key Vault is a SaaS solution. You can easily store passwords and secrets securely and encrypt them. Azure Key Vault is a great solution to ensure you are compliant with security and governanc...
Which is better - HashiCorp Vault or AWS Secrets Manager?
HashiCorp Vault was designed with your needs in mind. One of the features that makes this evident is its ability to work as both a cloud-agnostic and a multi-cloud solution. As a cloud-agnostic sol...
What needs improvement with AWS Secrets Manager?
AWS Secrets Manager could not be better because there has been no frustration with the product.
What is your experience regarding pricing and costs for HashiCorp Vault?
The pricing setup cost for HashiCorp Vault is quite expensive, especially if you consider it against native, cloud-native equivalent tooling. So within GCP, I'm thinking about Secret Manager, AWS S...
What needs improvement with HashiCorp Vault?
Setting up HashiCorp Vault can present operational challenges because deploying it involves complex initial setup, especially for a highly available cluster with integrated storage, auto-unseal, di...
What is your primary use case for HashiCorp Vault?
HashiCorp Vault has numerous use cases, with secrets management being the most commonly used. I securely store sensitive information such as database passwords, cloud credentials, API keys, SSH key...
 

Overview

 

Sample Customers

Autodesk, Clevy, Stackery
Adobe, SAP Ariba, Citadel, Spaceflight, Cruise
Find out what your peers are saying about AWS Secrets Manager vs. HashiCorp Vault and other solutions. Updated: August 2026.
912,022 professionals have used our research since 2012.