Oracle Cloud Infrastructure Secret Management
Oracle Cloud Infrastructure Secret Management stores and manages credentials that applications and cloud environments need, including database passwords, API keys, access tokens, SSH private keys, configuration secrets, and OAuth2 or JWT signing credentials. Teams can retrieve secrets through APIs, SDKs, the CLI, or the OCI Console. OCI Vault keys encrypt them, while OCI handles encryption, decryption, access control, and audit logging; IAM policies let administrators set granular permissions. Automatic rotation can run every one to 12 months and integrates with Autonomous AI Database and OCI Functions. Secrets can be replicated to as many as three destination regions, but those replicas are read-only and inherit changes from the source. A tenancy can hold up to 5,000 secrets, with 30 active and 30 pending-deletion versions per secret. The service is listed as free, and the stated plan limits help clarify its capacity.
Who it is for
It suits teams managing application and cloud credentials centrally rather than embedding them in source code or configuration files. It is also relevant where automated rotation, access policies, and audit logs are needed.
What is good
- Supports varied application and infrastructure secret types
- Access through APIs, SDKs, CLI, and console
- Automatic rotation supports one-to-12-month intervals
- Replicates secrets to up to three regions
What to know first
- Replicas are read-only
- Tenancy limit is 5,000 secrets
- No price is listed
Verdict
OCI Secret Management brings secret storage, access controls, audit logging, and rotation into one service. Its free listing and defined capacity limits make the stated scope clear, while replicas remain read-only.
Oracle Cloud Infrastructure Secret Management plans and pricing
All plansCompared on passkey authentication software
- Free plan
- Yes
- Automatic renewal
- Yes
- Deployment automation
- Yes
- Revocation workflows
- Yes
- Certificate types
- tls
- CA integrations
- Yes



