Open-source, end-to-end encrypted platform to manage secrets and configs across your team and infrastructure.
Slack | Infisical Cloud | Self-Hosting | Docs | Website
Infisical is an open source, end-to-end encrypted secret management platform that teams use to centralize their secrets like API keys, database credentials, and configurations.
We're on a mission to make secret management more accessible to everyone, not just security teams, and that means redesigning the entire developer experience from ground up.
- User-friendly dashboard to manage secrets across projects and environments (e.g. development, production, etc.)
- Client SDKs to fetch secrets for your apps and infrastructure on demand
- Infisical CLI to fetch and inject secrets into any framework in local development
- Native integrations with platforms like GitHub, Vercel, Netlify, and more
- Automatic Kubernetes deployment secret reloads
- Complete control over your data - host it yourself on any infrastructure
- Secret versioning and Point-in-Time Recovery to version every secret and project state
- Audit logs to record every action taken in a project
- Role-based Access Controls per environment
- Simple on-premise deployments to AWS and Digital Ocean
- 2FA with more options coming soon
And much more.
Check out the Quickstart Guides
The fastest and most reliable way to get started with Infisical is signing up for free to Infisical Cloud.
Deployment options: AWS EC2, Kubernetes, and more.
To set up and run Infisical locally, make sure you have Git and Docker installed on your system. Then run the command for your system:
Linux/macOS:
git clone https://github.com/Infisical/infisical && cd "$(basename $_ .git)" && cp .env.example .env && docker-compose -f docker-compose.yml up
Windows Command Prompt:
git clone https://github.com/Infisical/infisical && cd infisical && copy .env.example .env && docker-compose -f docker-compose.yml up
Create an account at http://localhost:80
On top managing secrets with Infisical, you can also scan for over 140+ secret types in your files, directories and git repositories.
To scan your full git history, run:
infisical scan --verbose
To scan your uncommitted git changes, run:
infisical scan git-changes --verbose
You can also scan your uncommited but staged changes by running the command below. This command can also be used as a pre-commit hook to prevent secret leak.
infisical scan git-changes --staged --verbose
Lean about Infisical's code scanning feature here
This repo available under the MIT expat license, with the exception of the ee
directory which will contain premium enterprise features requiring a Infisical license in the future.
Please do not file GitHub issues or post on our public forum for security vulnerabilities, as they are public!
Infisical takes security issues very seriously. If you have any concerns about Infisical or believe you have uncovered a vulnerability, please get in touch via the e-mail address security@infisical.com. In the message, try to provide a description of the issue and ideally a way of reproducing it. The security team will get back to you as soon as possible.
Note that this security address should be used only for undisclosed vulnerabilities. Please report any security problems to us before disclosing it publicly.
Whether it's big or small, we love contributions. Check out our guide to see how to get started.
Not sure where to get started? You can:
- Book a free, non-pressure pairing sessions with one of our teammates!
- Join our Slack, and ask us any questions there.
- Docs for comprehensive documentation and guides
- Slack for discussion with the community and Infisical team.
- GitHub for code, issues, and pull requests
- Twitter for fast news
- YouTube for videos on secret management
- Blog for secret management insights, articles, tutorials, and updates
- Roadmap for planned features