Skip to content

Secrets Manager

The STACKIT Secrets Manager is a managed service that provides a secure key-value store for protecting and managing sensitive data, such as passwords and configuration files.

  • Storage of secrets in accordance with security requirements (e.g. separation of source code and secrets)
  • The customer can order a Secrets Manager quickly and easily via the self-service user interface in the STACKIT Portal
  • Secrets can be managed via a user-friendly configuration interface and API
  • Traceability of changes through versioning of individual secrets
  • Preconfigured auto-update functions keep components up to date
  • High availability ensures the secure operation of the Secrets Manager
  • Single source of truth: Store all your secrets like passwords, configuration files and text in one place

  • Secure storage: Keep all your secrets safe and secure for your whole team and all of your applications

  • Enabler for automation: Integrate your secrets via API into your applications and workflows

  • announcement

    STACKIT Secrets Manager AppRole authentication is now in Public Preview

    Section titled “STACKIT Secrets Manager AppRole authentication is now in Public Preview”

    We are excited to announce that AppRole authentication for the STACKIT Secrets Manager has reached Public Preview as of August 31, 2026. You can now use AppRole to authenticate applications and automated workloads.

    AppRole lets applications and automated workloads authenticate with a Role-ID and Secret-ID instead of a username and password, and exchange them for a Vault-compatible token—making it easier to manage credentials for automated access to your secrets.

    Public Preview scope

    • API: Full support for creating and managing AppRoles and Secret-IDs, and for authenticating with AppRole, on the stable v1 API. Explore our documentation to learn how to configure and use AppRoles.
  • feature

    STACKIT Secrets Manager - Extended audit log functionalities

    Section titled “ STACKIT Secrets Manager - Extended audit log functionalities”

    We have expanded the auditing capabilities of the STACKIT Secrets Manager to provide deeper visibility into your security landscape.

    While audit logs were previously limited to instance-level events (such as instance creation or deletion), we have now introduced granular logging at the secret level.

    Audit logs will now be generated for the following secret lifecycle events:

    • Creation of a secret
    • Deletion of a secret
    • Enabling of a secret version
    • Disabling of a secret version
    • Destruction of a secret version

    For more information, see our Secrets Manager to get started. If there are any questions, support is available via the Help Center.

  • feature

    STACKIT Secrets Manager - JSON editor for Secrets

    Section titled “STACKIT Secrets Manager - JSON editor for Secrets”

    As of now, STACKIT Secrets Manager supports editing secrets with a JSON editor directly within your Service Dashboard. For secrets containing simple key-value pairs as a string, you can still switch back to the familiar key-value pair mode.

    Our Help Center is always available if you have any questions.