New features andimprovements to Phase
We build in public. Every feature drop, improvement, and fix — as it ships.
Rotated secrets, Tailscale integration & Kubernetes Operator v2.0
We've added support for automated secret rotation, along with several other platform updates and improvements. We also rewrote the Kubernetes Secrets Operator in Go (2.0), overhauled the secret deployment pipeline so references stay in sync across apps, added self-hosting on Tailscale, and shipped rotation support across the CLI, SDK, and REST API.

Teams, SCIM, Platform APIs & Audit Logs
A wave of access control and platform upgrades — Teams with team-owned service accounts and role overrides, SCIM v2 provisioning to drive the user lifecycle from your identity provider, the full management REST API for Apps, Environments, Roles, Service Accounts, and Members, and a new org-wide audit log that captures every management action across your organization. Here's the full recap.

March 2026
March was a major release month. We rewrote the CLI from Python to Go — shipping a single binary across 16 platform targets that's 75-90% smaller. We introduced Secret Types with sealed write-only secrets, added Azure as a second external identity provider, launched Azure Key Vault sync, released Go SDK 2.0 with pure-Go cryptography, and shipped native AI agent integration. Here's everything.

December 2025
December was a stability and reliability month. We resolved a series of secret referencing edge cases across both Console and CLI, shipped a significant backend performance optimization, improved Docker images for self-hosted deployments, and fixed several bugs. Here's the recap.

Dynamic Secrets
We're excited to introduce Dynamic Secrets, a major leap in reducing the attack surface of your secrets. With this update, you can now generate short-lived, one-off credentials on demand that automatically expire once they have been used by the target machine, workflow or environment. This means fewer long-lived static secrets, far smaller blast radius in case of exposure, and stronger auditability across your organization. We're rolling out Dynamic Secrets for Enterprise tier users with support for AWS IAM, with many more providers on the roadmap!

AWS Assume Role, Revamped Access Management, EKS, GitHub Enterprise, and Global Secret Search
Phase now natively integrates with AWS using Assume Role authentication. We've also shipped a complete revamp of access management, and a new search feature for secrets via the command palette. This is one of our biggest releases to date, and we're excited to share it with you.

Network Access Policies, Cross-app referencing, and more
The Phase platform has seen significant feature updates and improvements this April, including support for cross-app secret referencing, network access policies, enhanced log filtering and more. Here's a recap of all the recent changes.

Workers Integration, OIDC Auth support + more
We've added native integration for Cloudflare Workers along with a host of new features and DX updates including:
- OIDC Auth for self-hosted instances supporting Google, Microsoft Entra ID and JumpCloud
- Drag & drop imports in the Console to seamlessly import .env files into apps and environments
- A one-click programmatic access menu to get a one-liner shell command to fetch secrets based on your app, environment and folder
- Improved folder UX when managing secrets across environments
- Editable app names
- UI optimizations for smaller screens

Node SDK and UX Updates
We're happy to announce the release of our Node.js SDK with full secrets management support including end-to-end encryption, secret referencing, personal override support and more! We've also updated the Console with a suite of UX and DX improvements to make common workflows around things like Integrations, Service Accounts and the CLI require fewer clicks and be more seamless.

Improved Cross-Environment Secret Management & More
The Console has been updated with new features and UX improvements to make managing secrets across environments easier and more intuitive. We've also shipped several performance optimizations, bugfixes, and improved secret handling for self-hosted users.

Service Accounts, Vercel Teams, performance improvements & more
Service accounts provide a new and improved way to access secrets programmatically, functioning like the machine equivalent of human user accounts. Service accounts improve upon service tokens by enabling access across multiple apps and environments, and integrating natively with the new access control and permissions engine.

All-new Role-Based Access Control Engine, Custom Roles and more
Access control across the Phase platform has been reworked from the ground up to be more granular and completely customizable. We've added a whole new modular permissions framework, with 3 managed roles and full support for custom roles.

Hashicorp Terraform Integration
We're excited to announce the release of the official Phase Terraform Provider. This integration allows you to securely retrieve secrets stored in Phase directly within your Terraform configurations, enabling seamless incorporation of secret management into your infrastructure-as-code workflows.

GitLab CI Integration
The Phase Console now natively integrates with GitLab CI, allowing you to sync secrets and variables to your GitLab CI pipelines and jobs. You can sync secrets to both groups and projects. We've also added the ability to use self-hosted GitLab instances to authenticate with the Phase Console.

Secret sharing with Phase Lockbox
You can now securely share secrets with users outside of your team with Phase Console's Secret Sharing feature: Lockbox. Secrets shared with Lockbox are encrypted with zero-trust encryption, and can only be accessed and views using the link. You can set a custom expiry policy for the link based on either number of views or a fixed expiry time.

Hashicorp Vault Integration
The Phase Console now has native integration with Hashicorp Vault, allowing you to keep your existing Vault setup in-place while using Phase for development or staging environments. The integration works for self-hosted instances of Vault as well as Hashicorp Cloud Platform.

GitHub Actions Integration
The Phase Console now has native integration with GitHub Actions, allowing you to use Phase to inject secrets into your Workflows. Phase will make sure your CI runs, build pipelines and test environments use up-to-date secrets without any manual intervention required.

Webauth
Running phase auth in the CLI now opens up a new tab in your default web browser and redirects you to the Phase Console for authentication.
This is a seamless process that allows users to authenticate with their existing accounts without needing to manually generate, copy and paste personal access tokens.

Keep your secrets
Self-host or start on fully managed Cloud in under a minute.
Run Phase on your own infrastructure. Free and open source.


















