---
title: "STACKIT Secrets Manager"
description: "Fully managed key-value secrets storage compatible with HashiCorp Vault KV2 APIs for centralized credential management."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Secrets", "Vault", "Security", "KMS", "Credentials"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-secrets-manager/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-secrets-manager.mdx"
---

STACKIT Secrets Manager provides secure storage for passwords, API tokens, and certificate keys.

## Service Overview
- **Vault API Compatibility**: Drop-in replacement for workflows expecting HashiCorp Vault KV2 APIs.
- **Code Decoupling**: Removes sensitive hardcoded passwords and tokens from application source code.

## Technical Details
- **Security**: Secured via IP-based ACLs, KMS envelope encryption, and audit logging.
- **Kubernetes Integration**: Integrates directly with the Kubernetes External Secrets Operator.

## Service Plans

The values below come from the STACKIT documentation and update themselves.

> From the STACKIT docs: [Features, use cases and service plans › Service plans](https://docs.stackit.cloud/products/security/secrets-manager/basics/features-use-cases-and-service-plans/#service-plans) (Source updated 26.08.2026, copied 05.10.2026)

The Secrets Manager automatically scales in the number of secrets and users, there are no fixed service plans.

The following restrictions apply:

- The number of API accesses is limited to 10,000 accesses per hour per Secrets Manager.
- Up to 100 users can be created per Secrets Manager.

## Limitations & Constraints
- **Instance-Level ACLs**: Access permissions are set per instance; individual secret-level ACLs are unsupported.
- **Public API Access**: Endpoint connections operate over public HTTPS (private endpoints unavailable).

<LinkCard title="STACKIT Secrets Manager Documentation" href="https://docs.stackit.cloud" />
