Infisical

    Infisical/infisical

    #337 this week

    Infisical is the open-source platform for secrets, certificates, and privileged access management.

    cli
    database
    security
    acme
    certificate-management
    environment-variables
    go
    golang
    node-js
    open-source
    pki
    postgres
    private-ca
    secret-management
    secret-manager
    secret-scanning
    secrets
    secrets-management
    security-tools
    typescript
    vault
    TypeScript
    NOASSERTION
    26.4K stars
    1.9K forks
    26.4K watching
    Updated 5/4/2026
    View on GitHub

    Scale data-heavy AI workloads

    while keeping costs low with S3-compatible storage.

    BackblazeLearn more

    Loading star history...

    Health Score

    45

    Activity
    100
    Community
    75
    Maintenance
    0
    Last releasetoday

    Weekly Growth

    +0

    +0.0% this week

    Contributors

    218

    Total contributors

    Open Issues

    540

    Use Cases & Benefits

    About infisical

    infisical

    The open-source secret management platform: Sync secrets/configs across your team/infrastructure and prevent secret leaks.

    Slack | Infisical Cloud | Self-Hosting | Docs | Website | Hiring (Remote/SF)

    Infisical is released under the MIT license. PRs welcome! git commit activity Cloudsmith downloads Slack community channel Infisical Twitter

    Dashboard

    Introduction

    Infisical is the open source secret management platform that teams use to centralize their application configuration and secrets like API keys and database credentials as well as manage their internal PKI.

    We're on a mission to make security tooling more accessible to everyone, not just security teams, and that means redesigning the entire developer experience from ground up.

    Features

    Secrets Management:

    Certificate Management

    Infisical Key Management System (KMS):

    Infisical SSH

    • Signed SSH Certificates: Issue ephemeral SSH credentials for secure, short-lived, and centralized access to infrastructure.

    General Platform:

    Getting started

    Check out the Quickstart Guides

    Use Infisical CloudDeploy Infisical on premise
    The fastest and most reliable way to
    get started with Infisical is signing up
    for free to Infisical Cloud.

    View all deployment options

    Run Infisical locally

    To set up and run Infisical locally, make sure you have Git and Docker installed on your system.

    Linux/macOS:

    git clone https://github.com/Infisical/infisical && cd "$(basename $_ .git)" && cp .env.example .env && docker compose -f docker-compose.prod.yml up
    

    Windows (Command Prompt):

    git clone https://github.com/Infisical/infisical && cd infisical && copy .env.example .env && docker compose -f docker-compose.prod.yml up
    

    Once running, create an account at http://localhost:80.

    Contributing? Check out our guide to see how to get started.

    Scan and prevent secret leaks

    On top managing secrets with Infisical, you can also scan for over 140+ secret types in your files, directories and git repositories.

    To scan your full git history, run:

    infisical scan --verbose
    

    Install pre commit hook to scan each commit before you push to your repository

    infisical scan install --pre-commit-hook
    

    Learn about Infisical's code scanning feature here

    Open-source vs. paid

    This repo available under the MIT expat license, with the exception of the ee directory which will contain premium enterprise features requiring a Infisical license.

    If you are interested in managed Infisical Cloud of self-hosted Enterprise Offering, take a look at our website or book a meeting with us.

    Security

    Please do not file GitHub issues or post on our public forum for security vulnerabilities, as they are public!

    Infisical takes security issues very seriously. If you have any concerns about Infisical or believe you have uncovered a vulnerability, please get in touch via the e-mail address [email protected]. In the message, try to provide a description of the issue and ideally a way of reproducing it. The security team will get back to you as soon as possible.

    Note that this security address should be used only for undisclosed vulnerabilities. Please report any security problems to us before disclosing it publicly.

    Contributing

    Whether it's big or small, we love contributions. Check out our guide to see how to get started.

    Not sure where to get started? You can:

    • Join our Slack, and ask us any questions there.

    We are hiring!

    If you're reading this, there is a strong chance you like the products we created.

    You might also make a great addition to our team. We're growing fast and would love for you to join us.

    Discover Repositories

    Search across tracked repositories by name or description