Manage secrets andenvironment variables
Open source platform for teams and AI agents to securely access, manage and deploy application secrets, from development to production.
Console
Production

Agency without exposure
Agents use freshly minted dynamic secrets with their own identity. If they run into any access issues, they automatically ping a team member and ask for higher privileges only when needed.
Complete visibility throughout: destructive actions like SQL DROP get blocked and audit-logged.
ReadLatency p99 812ms CPUUtilization avg 34%
count ---------- 41883306 (1 row)
service/api desiredCount 4 → 12 rollout IN_PROGRESS → STEADY_STATE
Guardrails at the network edge
Agents use decoy secrets managed by Phase when making outbound requests to third-party services. The Phase AI proxy inspects each request and checks it against your policy — then injects the real secret mid-flight.
Deploy Secrets
Centralize, integrate and automate secret deployment pipelines across your infrastructure.
Govern Access
Effortlessly manage authentication, role-based access control (RBAC), and network access policies.
Group members and service accounts into Teams, then grant a Team access to apps scoped to specific environments. Environment keys are provisioned automatically when someone joins and revoked when they leave — with team-owned service accounts and optional role overrides.
TeamsManaged and custom roles with a granular permission matrix, per-environment and per-path scoping, service accounts for machines.
Access controlRestrict access to your secrets by IP address or CIDR range with network access policies for users and service accounts.
Every CRUD operation logged with actor, source, and diff. Point-in-time rollback for any secret.
Logs- Created12 days agobyEFElena Fischer
- Updated10 days agobyPNPriya NairTAGS:aws
- Updated8 days agobyMCMarcus ChenCOMMENT:
temp key for stagingProd IAM key · payments-service - Updated2 days agobySASofia AlmeidaVALUE:
AKIAIX4ONRSG6ODEFVJAAKIAIX4ONRSG6ODEFVJB - Read4h agobyCIci-runner
Trust & Compliance
Every control here is cryptographically enforced, independently audited, or open to inspection.
SOC 2 Type 2 Certified
Independently audited under SOC 2 Type 2, with controls examined continuously over time. Penetration tested annually by Oneleet, an independent security firm. Reports are available in our trust center.
Trust centerStrong cryptography
End-to-end encrypted: keys, values and comments, with an independent key for every environment. Optionally enable server-side encryption (SSE) for integrations and API access.
How it worksNo telemetry
Every line of code that secures your secrets is public and auditable. Run on Phase Cloud or your own infrastructure: Docker, Kubernetes, any cloud, or fully air-gapped. No outbound usage analytics or telemetry.
Deploy guidesBatteries included.
Global search, offline mode, dynamic secrets, machine identity. The parts of a secrets manager you would otherwise build yourself.
Global secret search
Find any secret across every app, environment and folder in your organization. Search runs client-side: values are never decrypted.
Work offline
The CLI caches secrets locally, encrypted at rest. Set PHASE_OFFLINE=1 and keep shipping when the network is down.
Rotating secrets
Phase mints, exposes, and revokes third-party credentials on a schedule — your app picks up fresh values with no code changes.
Secret referencing
Compose configuration from other secrets, across environments, folders and apps. References resolve at inject time.
Authentication for humans and machines
External identities for workloads: no bootstrap credential to provision, rotate, or leak. SSO with SCIM provisioning for people.
Workloads authenticate with their platform identity: an AWS SigV4-signed request or an Azure managed-identity JWT. Phase verifies the identity upstream with AWS STS or Microsoft Entra, matches it against your trusted principals, and returns a short-lived scoped token straight to the workload.
Single sign-on through your identity provider. Users are provisioned and deprovisioned over SCIM v2: Entra ID, Okta, JumpCloud, or any compatible directory.
Dynamic secrets
Lease short-lived AWS IAM credentials on demand. Renew within the max TTL, or revoke instantly.
Audit logs
Every management action captured org-wide — actor, timestamp, and before/after diffs — built for compliance and incident response.
Sealed secrets
Write-only secrets: once saved, the plaintext is never visible or editable in the UI again — ideal for signing keys and tokens.
Kubernetes Operator
Declare a PhaseSecret and the operator keeps native Kubernetes secrets in sync, auto-redeploying your workloads on change.
kind: PhaseSecret spec: phaseApp: 'satcommand' phaseAppEnv: 'production' managedSecretReferences: - secretName: 'api-secrets'
Trusted by builders
Engineers across a wide range of industries use Phase to build world-class software and secure critical infrastructure.

I tried out Phase a while back and was pretty impressed. The DX is amazing, especially the CLI. Managing secrets has been such a pain, I am definitely gonna use Phase for projects I work on going forward. … Super easy for me to recommend it to my peers.

Phase has one of the most well thought out security architectures I've seen. The encryption implementation is one I show my students as a benchmark for robust cryptography in a real-world application.

Phase looks like a solid tool for managing secrets in a secure and efficient way. I've used similar tools, but the ease of integration with other services like GitHub and AWS really sets this apart.

Phase is a valuable resource for any engineering team looking to improve their security practices and deployment processes. Highly recommended for those looking for robust solutions!

This is a great tool. When you work with a distributed team it is always a real pain to share secrets and credentials. I also love the fact that you offer a self-hosted version. Especially in Europe a lot of companies insist on hosting on premise 😅

Great work with Phase, such a delightful piece of software.

Great work with Phase, it's a blast to use.

Awesome one. This is what I've been looking for!

We have started using phase to inject secrets into our deployment app… Awesome product btw
Keep your secrets
Self-host or start on fully managed Cloud in under a minute.
Run Phase on your own infrastructure. Free and open source.