{
 "categories": [
  "identity",
  "developer-tools"
 ],
 "deployment": "hybrid",
 "evidence": [
  {
   "date": "2026-09-27",
   "fact": "homepage",
   "note": "Infisical pricing presents a secrets platform with a free plan and paid plans, including a free trial on paid plans.",
   "source": "https://infisical.com/pricing",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "license",
   "note": "The secrets-management Free plan is $0 forever for 5 identities and unlimited projects. Paid plans exist above it.",
   "source": "https://infisical.com/pricing",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "deployment",
   "note": "The API reference documents Infisical Cloud regions and says a self-hosted or dedicated instance replaces the host.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "platforms",
   "note": "The CLI install page documents Linux packages. The API introduction documents the web cloud hosts and a self-hosted host.",
   "source": "https://infisical.com/docs/cli/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.api.exists",
   "note": "Infisical documents a REST API served over HTTPS for programmatic management of secrets and related resources.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.api.kinds[0]",
   "note": "The reference describes HTTPS endpoints under /api, for example /api/v3/secrets/raw.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.api.auth[0]",
   "note": "Universal Auth and Token Auth return a short-lived access token. Every API request sends Authorization: Bearer <token>. Cloud, OIDC, JWT, and other methods also authenticate the caller before that token is used.",
   "source": "https://infisical.com/docs/api-reference/overview/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.api.coverage",
   "note": "Infisical says the API supports every action available in the dashboard, including reading and writing secrets, projects, machine identities, and audit logs.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.sdk.exists",
   "note": "The API introduction says callers can also use the CLI and SDKs. It does not list languages on this page.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.mcp.first_party",
   "note": "The Infisical organization README describes @infisical/mcp as Infisical's MCP server for the Infisical API, with universal auth or an access token.",
   "source": "https://github.com/Infisical/infisical-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.cli.exists",
   "note": "Infisical documents an official CLI that retrieves, modifies, exports, and injects secrets, with install paths for macOS, Windows, npm, and Linux.",
   "source": "https://infisical.com/docs/cli/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.data_access.export[0]",
   "note": "The REST API reads secrets and other resources. The CLI page says the CLI can export secrets.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.data_access.import[0]",
   "note": "The secrets MCP and the API introduction both describe writing secrets. The MCP tools include create-secret and update-secret.",
   "source": "https://github.com/Infisical/infisical-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.rpa.ui_stack[0]",
   "note": "The API is described as covering actions available in the Infisical dashboard, which is a web application at app.infisical.com.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Opened a plain-text documentation index for Infisical docs.",
   "source": "https://infisical.com/docs/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "verdict.scores.api",
   "note": "Infisical states dashboard parity for the REST API, with bearer tokens after Universal Auth or Token Auth.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "verdict.scores.mcp",
   "note": "The official local server can create, update, and delete secrets. Masking secret values is optional and defaults to false. https://infisical.com/docs/mcp is a separate read-only docs server.",
   "source": "https://github.com/Infisical/infisical-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "verdict.scores.cli",
   "note": "The CLI is officially packaged for several operating systems and is documented for retrieve, modify, export, and inject. This page does not list every non-interactive flag.",
   "source": "https://infisical.com/docs/cli/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "freshness.watch[0].url",
   "note": "Opened the Infisical API introduction, including cloud and self-hosted base URLs.",
   "source": "https://infisical.com/docs/api-reference/overview/introduction",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "freshness.watch[1].url",
   "note": "Opened the API authentication page, including Bearer tokens from Universal Auth and Token Auth.",
   "source": "https://infisical.com/docs/api-reference/overview/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-27",
   "fact": "freshness.watch[2].url",
   "note": "Opened the secrets MCP README, including tools and the optional secret-masking variable.",
   "source": "https://github.com/Infisical/infisical-mcp-server",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-27",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://infisical.com/docs/api-reference/overview/introduction"
   },
   {
    "type": "docs",
    "url": "https://infisical.com/docs/api-reference/overview/authentication"
   },
   {
    "type": "docs",
    "url": "https://github.com/Infisical/infisical-mcp-server"
   }
  ]
 },
 "homepage": "https://infisical.com/",
 "id": "infisical",
 "license": "freemium",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "bearer"
   ],
   "coverage": "full",
   "docs": "https://infisical.com/docs/api-reference/overview/introduction",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": [
    "json"
   ]
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The Infisical REST API, CLI, and secrets MCP server cover secret and project operations without browser control of the dashboard.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Infisical",
 "platforms": [
  "web",
  "linux"
 ],
 "related": {
  "alternatives": [
   "hashicorp-vault",
   "1password",
   "bitwarden"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Infisical",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": 7,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 8,
   "rpa": null
  },
  "summary": "Infisical is automatable today through its REST API. This record is the Infisical secrets platform, including projects, environments, folders, and secrets on Infisical Cloud and self-hosted instances. HashiCorp Vault, 1Password, and Bitwarden are separate products. The API is HTTPS JSON. Cloud bases are https://app.infisical.com/api and https://eu.infisical.com/api. A self-hosted instance uses https://<your-instance>/api. Infisical says the API supports every dashboard action, including secrets, projects, machine identities, and audit logs. Universal Auth and Token Auth return a short-lived access token sent as Authorization: Bearer. Other login methods, including cloud workload identity and OIDC, also exchange for that bearer token. The CLI installs with Homebrew, winget, Scoop, npm, and Linux packages, and can retrieve, modify, export, and inject secrets. Infisical publishes a local secrets MCP server, npm @infisical/mcp, using universal auth or an access token. Tools can list, get, create, update, and delete secrets and can create projects, environments, and folders. Secret values are returned unless INFISICAL_MASK_SECRET_VALUES is true. A separate read-only MCP at https://infisical.com/docs/mcp searches public docs and does not manage secrets. Connector catalogs were not opened. https://infisical.com/docs/llms.txt is a documentation index. Computer-use viability is unassessed. The API scores 8 and is the best path. The CLI scores 7. The secrets MCP scores 6 because it is official and can write secrets, and it runs locally with credentials on the machine.\n"
 }
}