Rotated secrets, Tailscale integration & Kubernetes Operator v2.0
We've added support for automated secret rotation, along with several other platform updates and improvements. We also rewrote the Kubernetes Secrets Operator in Go (2.0), overhauled the secret deployment pipeline so references stay in sync across apps, added self-hosting on Tailscale, and shipped rotation support across the CLI, SDK, and REST API.

March 2026
March was a major release month. We rewrote the CLI from Python to Go — shipping a single binary across 16 platform targets that's 75-90% smaller. We introduced Secret Types with sealed write-only secrets, added Azure as a second external identity provider, launched Azure Key Vault sync, released Go SDK 2.0 with pure-Go cryptography, and shipped native AI agent integration. Here's everything.

December 2025
December was a stability and reliability month. We resolved a series of secret referencing edge cases across both Console and CLI, shipped a significant backend performance optimization, improved Docker images for self-hosted deployments, and fixed several bugs. Here's the recap.

Dynamic Secrets
We're excited to introduce Dynamic Secrets, a major leap in reducing the attack surface of your secrets. With this update, you can now generate short-lived, one-off credentials on demand that automatically expire once they have been used by the target machine, workflow or environment. This means fewer long-lived static secrets, far smaller blast radius in case of exposure, and stronger auditability across your organization. We're rolling out Dynamic Secrets for Enterprise tier users with support for AWS IAM, with many more providers on the roadmap!

Network Access Policies, Cross-app referencing, and more
The Phase platform has seen significant feature updates and improvements this April, including support for cross-app secret referencing, network access policies, enhanced log filtering and more. Here's a recap of all the recent changes.

Improved Cross-Environment Secret Management & More
The Console has been updated with new features and UX improvements to make managing secrets across environments easier and more intuitive. We've also shipped several performance optimizations, bugfixes, and improved secret handling for self-hosted users.

All-new Role-Based Access Control Engine, Custom Roles and more
Access control across the Phase platform has been reworked from the ground up to be more granular and completely customizable. We've added a whole new modular permissions framework, with 3 managed roles and full support for custom roles.

Webauth
Running phase auth in the CLI now opens up a new tab in your default web browser and redirects you to the Phase Console for authentication.
This is a seamless process that allows users to authenticate with their existing accounts without needing to manually generate, copy and paste personal access tokens.

Keep your secrets
Self-host or start on fully managed Cloud in under a minute.
Run Phase on your own infrastructure. Free and open source.







