Skip to main content
Cloud / STACKIT / Products / STACKIT Secrets Manager - Secure Credential Management

STACKIT Secrets Manager - Secure Credential Management

STACKIT Secrets Manager: Secure management of API keys, passwords, certificates. Versioning, audit logs, GDPR compliant.

Security
Pricing Model Hourly billing based on capacity tier (e.g. 100, 1k, 10k, 100k, 1M secrets)
Availability Germany (STACKIT regions)
Data Sovereignty 100% German data centers
Reliability SLA as published by the provider SLA

What is STACKIT Secrets Manager?

STACKIT Secrets Manager is a fully managed service that provides a secure key-value store for sensitive data such as passwords, API keys, certificates, and configuration parameters. The service enables separation of secrets from source code in line with common security requirements. STACKIT operates the service exclusively in German data centers for complete GDPR compliance.

Core Features

  • Centralized, encrypted key-value store for secrets, separate from source code
  • Versioning of secrets for traceability and rollback
  • API modeled on the HashiCorp Vault KV2 interface
  • Integration with tools such as Terraform
  • KMS integration for encrypting stored secrets
  • Managed high-availability infrastructure with automatic updates
  • AppRole authentication (Public Preview since August 31, 2026): Applications and automated workloads authenticate via Role-ID and Secret-ID instead of a username/password
  • Granular audit logs: Logging of individual secret lifecycle events (creation, deletion, enabling/disabling, and destruction of secret versions)

Typical Use Cases

Database Credentials for Microservices: Instead of storing passwords in environment variables, credentials are retrieved from Secrets Manager at runtime.

API Keys for External Services: Payment providers, email services, and cloud APIs require API keys. Secrets Manager stores these encrypted and versioned for quick rollback.

Centralized Configuration Management: Application configurations and credentials are managed centrally and distributed across environments (dev, staging, production) via the API.

Automated Workload Authentication: With AppRole authentication, available in Public Preview since August 31, 2026, applications and CI/CD pipelines authenticate with a Role-ID and Secret-ID instead of hard-coding credentials.

Benefits

  • Complete data sovereignty in German data centers
  • Versioning for quick rollback in case of faulty changes
  • Compatibility with existing Vault-based workflows through a KV2-compatible API
  • GDPR compliant with an audit trail

Integration with innFactory

As an official STACKIT partner, innFactory supports you with STACKIT Secrets Manager: architecture, migration, operations, and cost optimization.

Available Tiers & Options

Typical Use Cases

API key management
Database credential storage
Certificate management
Application configuration
Service account credentials
Multi-environment secrets
Automated workload authentication via AppRole

Frequently Asked Questions

What is STACKIT Secrets Manager?

STACKIT Secrets Manager is a managed key-value store for protecting and managing sensitive data such as passwords, API keys, and configuration files, kept separate from source code.

How are secrets encrypted?

Secrets are stored encrypted server-side, with encryption configurable via a KMS integration. Configuration details are documented in the current STACKIT documentation.

Is the API compatible with HashiCorp Vault?

The Secrets Manager API is modeled on the HashiCorp Vault KV2 API, allowing existing Vault CLI workflows and tools to be reused with adjustments.

How do applications access secrets?

Access happens via an API as well as integrations with common tools such as Terraform. For production use, check the current integration documentation for your target system.

How do applications authenticate automatically?

Since August 31, 2026, AppRole authentication is available in Public Preview: applications and automated workloads authenticate with a Role-ID and Secret-ID instead of a username and password, and exchange them for a Vault-compatible token. Creating and managing AppRoles and Secret-IDs is supported on the stable v1 API.

How granular is audit logging?

Since January 2026, Secrets Manager logs events not just at the instance level but also at the individual secret level: creation and deletion of secrets, and enabling, disabling, and destroying secret versions are all recorded.

Is STACKIT Secrets Manager GDPR compliant?

Yes, the service operates exclusively in German data centers. STACKIT provides data processing agreements and is ISO 27001 certified.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Access Context Manager - Attribute-Based Access Control

Access Context Manager defines access levels and service perimeters for fine-grained, attribute-based access control in …

Pricing Free: according to the official pricing …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Advisory Notifications - Security and Privacy Communications

Advisory Notifications delivers communications about critical security and privacy events in the Google Cloud console.

Pricing Google does not publish a dedicated …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Artifact Analysis - Vulnerability Scanning for Artifacts

Artifact Analysis scans container images and packages for vulnerabilities and stores the associated metadata. The …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Assured Open Source Software - Curated OSS Packages from Google

Assured OSS provides open source packages that Google itself secures and uses, with SBOMs, VEX data, and signed …

Pricing Free tier and Premium tier; the Premium …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Audit Manager - Compliance Audits in Google Cloud

Audit Manager runs automated compliance assessments against built-in and custom frameworks and collects evidence for …

Pricing Free tier with core features and a …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Cloud IDS - Managed Intrusion Detection for VPC Networks

Cloud IDS monitors network traffic in Google Cloud and alerts you when it detects malicious activity. Detection is …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →

103 comparable products found across other clouds.

Ready to start with STACKIT Secrets Manager - Secure Credential Management?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation