Infisical
Infisical is an open-source secrets management platform that provides developers with a centralized, end-to-end encrypted vault for storing, syncing, and rotating secrets across teams, environments, and cloud infrastructure. The platform offers a REST API enabling programmatic management of secrets, machine identities, PKI certificates, and privileged access controls. Infisical integrates with CI/CD pipelines, Kubernetes, cloud providers, and developer toolchains through official SDKs for Node.js, Python, Go, Java, Ruby, .NET, Rust, C++, and PHP. Available as both a managed cloud service and a self-hostable open-source deployment, Infisical (YC W23) supports audit logging, SAML SSO, SCIM, dynamic secrets, and secret rotation workflows for enterprise teams.
Real signal across most facets with visible, nameable gaps — the contract exists but is thin, or the portal is good while governance and commercial terms are absent.
API Evangelist profiles Infisical the way a machine reads it — 164 machine-readable artifacts across 1 API, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Infisical scores 40.0/100 (developing), with a separate agent-readiness read of 24/100 (agent aware). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance. Every facet and dimension name is a link: it opens that measurement's page on APIs.io, where the rating runs across the whole catalog — the exact checks that feed it, how every profiled provider distributes on it, and who is at the top of it.
Put this on your own site. The badge is drawn live from Infisical's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/infisical/"
title="Infisical on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/infisical.svg"
alt="Infisical Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>
[](https://providers.apievangelist.com/providers/infisical/)
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/infisical/"
title="Infisical on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/infisical/card.svg"
alt="Infisical Kin Score — API readiness rating by API Evangelist" width="340" height="120" loading="lazy">
</a>
More shapes, themes and sizes → · Score as JSON · How badges work
How we profile Infisical
Each block below is one kind of artifact we hold for Infisical. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 73
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Infisical Admin API
The Admin API from Infisical — 1 operation(s) for admin.
Infisical Alibaba Cloud Auth API
The Alibaba Cloud Auth API from Infisical — 2 operation(s) for alibaba cloud auth.
Infisical App Connections API
The App Connections API from Infisical — 347 operation(s) for app connections.
Infisical Audit Logs API
The Audit Logs API from Infisical — 1 operation(s) for audit logs.
Infisical AWS Auth API
The AWS Auth API from Infisical — 2 operation(s) for aws auth.
Infisical Azure Auth API
The Azure Auth API from Infisical — 2 operation(s) for azure auth.
Infisical Cert Manager API
The Cert Manager API from Infisical — 4 operation(s) for cert manager.
Infisical Dynamic Secrets API
The Dynamic Secrets API from Infisical — 7 operation(s) for dynamic secrets.
Infisical Environments API
The Environments API from Infisical — 8 operation(s) for environments.
Infisical Event Subscriptions API
The Event Subscriptions API from Infisical — 1 operation(s) for event subscriptions.
Infisical Folders API
The Folders API from Infisical — 16 operation(s) for folders.
Infisical GCP Auth API
The GCP Auth API from Infisical — 2 operation(s) for gcp auth.
Infisical Groups API
The Groups API from Infisical — 11 operation(s) for groups.
Infisical Identities API
The Identities API from Infisical — 7 operation(s) for identities.
Infisical Identity Specific Privileges API
The Identity Specific Privileges API from Infisical — 4 operation(s) for identity specific privileges.
Infisical Identity Specific Privileges V2 API
The Identity Specific Privileges V2 API from Infisical — 3 operation(s) for identity specific privileges v2.
Infisical Identity Templates API
The Identity Templates API from Infisical — 5 operation(s) for identity templates.
Infisical Integrations API
The Integrations API from Infisical — 11 operation(s) for integrations.
Infisical JWT Auth API
The JWT Auth API from Infisical — 2 operation(s) for jwt auth.
Infisical KMS Encryption API
The KMS Encryption API from Infisical — 2 operation(s) for kms encryption.
Infisical KMS Keys API
The KMS Keys API from Infisical — 6 operation(s) for kms keys.
Infisical KMS Signing API
The KMS Signing API from Infisical — 4 operation(s) for kms signing.
Infisical Kubernetes Auth API
The Kubernetes Auth API from Infisical — 2 operation(s) for kubernetes auth.
Infisical LDAP Auth API
The LDAP Auth API from Infisical — 3 operation(s) for ldap auth.
Infisical LDAP SSO API
The LDAP SSO API from Infisical — 1 operation(s) for ldap sso.
Infisical OCI Auth API
The OCI Auth API from Infisical — 2 operation(s) for oci auth.
Infisical OIDC Auth API
The OIDC Auth API from Infisical — 2 operation(s) for oidc auth.
Infisical OIDC SSO API
The OIDC SSO API from Infisical — 1 operation(s) for oidc sso.
Infisical Organization Identity Membership API
The Organization Identity Membership API from Infisical — 1 operation(s) for organization identity membership.
Infisical Organization Roles API
The Organization Roles API from Infisical — 3 operation(s) for organization roles.
Infisical Organizations API
The Organizations API from Infisical — 4 operation(s) for organizations.
Infisical PKI ACME API
The PKI ACME API from Infisical — 13 operation(s) for pki acme.
Infisical PKI Alerting API
The PKI Alerting API from Infisical — 6 operation(s) for pki alerting.
Infisical Pki API
The Pki API from Infisical — 4 operation(s) for pki.
Infisical PKI Applications API
The PKI Applications API from Infisical — 21 operation(s) for pki applications.
Infisical PKI Certificate Authorities API
The PKI Certificate Authorities API from Infisical — 48 operation(s) for pki certificate authorities.
Infisical PKI Certificate Collections API
The PKI Certificate Collections API from Infisical — 6 operation(s) for pki certificate collections.
Infisical PKI Certificate Policies API
The PKI Certificate Policies API from Infisical — 2 operation(s) for pki certificate policies.
Infisical PKI Certificate Profiles API
The PKI Certificate Profiles API from Infisical — 12 operation(s) for pki certificate profiles.
Infisical PKI Certificate Templates API
The PKI Certificate Templates API from Infisical — 9 operation(s) for pki certificate templates.
Infisical PKI Certificates API
The PKI Certificates API from Infisical — 26 operation(s) for pki certificates.
Infisical PKI Discovery API
The PKI Discovery API from Infisical — 6 operation(s) for pki discovery.
Infisical PKI Installations API
The PKI Installations API from Infisical — 2 operation(s) for pki installations.
Infisical PKI Signers API
The PKI Signers API from Infisical — 21 operation(s) for pki signers.
Infisical PKI Subscribers API
The PKI Subscribers API from Infisical — 9 operation(s) for pki subscribers.
Infisical PKI Syncs API
The PKI Syncs API from Infisical — 72 operation(s) for pki syncs.
Infisical Project Groups API
The Project Groups API from Infisical — 9 operation(s) for project groups.
Infisical Project Identities API
The Project Identities API from Infisical — 7 operation(s) for project identities.
Infisical Project Identity Membership API
The Project Identity Membership API from Infisical — 3 operation(s) for project identity membership.
Infisical Project Roles API
The Project Roles API from Infisical — 6 operation(s) for project roles.
Infisical Project Templates API
The Project Templates API from Infisical — 2 operation(s) for project templates.
Infisical Project Users API
The Project Users API from Infisical — 8 operation(s) for project users.
Infisical Projects API
The Projects API from Infisical — 10 operation(s) for projects.
Infisical Relays API
The Relays API from Infisical — 1 operation(s) for relays.
Infisical SAML SSO API
The SAML SSO API from Infisical — 1 operation(s) for saml sso.
Infisical SCIM API
The SCIM API from Infisical — 1 operation(s) for scim.
Infisical Secret Imports API
The Secret Imports API from Infisical — 6 operation(s) for secret imports.
Infisical Secret Rotations API
The Secret Rotations API from Infisical — 152 operation(s) for secret rotations.
Infisical Secret Scanning API
The Secret Scanning API from Infisical — 26 operation(s) for secret scanning.
Infisical Secret Sharing API
The Secret Sharing API from Infisical — 3 operation(s) for secret sharing.
Infisical Secret Syncs API
The Secret Syncs API from Infisical — 254 operation(s) for secret syncs.
Infisical Secrets API
The Secrets API from Infisical — 14 operation(s) for secrets.
Infisical Service Tokens API
The Service Tokens API from Infisical — 1 operation(s) for service tokens.
Infisical SPIFFE Auth API
The SPIFFE Auth API from Infisical — 3 operation(s) for spiffe auth.
Infisical SSH Certificate Authorities API
The SSH Certificate Authorities API from Infisical — 6 operation(s) for ssh certificate authorities.
Infisical SSH Certificate Templates API
The SSH Certificate Templates API from Infisical — 4 operation(s) for ssh certificate templates.
Infisical SSH Certificates API
The SSH Certificates API from Infisical — 2 operation(s) for ssh certificates.
Infisical SSH Host Groups API
The SSH Host Groups API from Infisical — 6 operation(s) for ssh host groups.
Infisical SSH Hosts API
The SSH Hosts API from Infisical — 8 operation(s) for ssh hosts.
Infisical Sub Organizations API
The Sub Organizations API from Infisical — 3 operation(s) for sub organizations.
Infisical TLS Certificate Auth API
The TLS Certificate Auth API from Infisical — 2 operation(s) for tls certificate auth.
Infisical Token Auth API
The Token Auth API from Infisical — 4 operation(s) for token auth.
Infisical Universal Auth API
The Universal Auth API from Infisical — 8 operation(s) for universal auth.
Scroll within the panel for all 73 ·
Open Collections 74
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONInfisical Admin API
OPEN COLLECTIONInfisical Admin Alibaba Cloud Auth API
OPEN COLLECTIONInfisical Admin App Connections API
OPEN COLLECTIONInfisical Admin Audit Logs API
OPEN COLLECTIONInfisical Admin AWS Auth API
OPEN COLLECTIONInfisical Admin Azure Auth API
OPEN COLLECTIONInfisical Admin Cert Manager API
OPEN COLLECTIONInfisical Admin Dynamic Secrets API
OPEN COLLECTIONInfisical Admin Environments API
OPEN COLLECTIONInfisical Admin Event Subscriptions API
OPEN COLLECTIONInfisical Admin Folders API
OPEN COLLECTIONInfisical Admin GCP Auth API
OPEN COLLECTIONInfisical Admin Groups API
OPEN COLLECTIONInfisical Admin Identities API
OPEN COLLECTIONInfisical Admin Identity Specific Privileges API
OPEN COLLECTIONInfisical Admin Identity Specific Privileges V2 API
OPEN COLLECTIONInfisical Admin Identity Templates API
OPEN COLLECTIONInfisical Admin Integrations API
OPEN COLLECTIONInfisical Admin JWT Auth API
OPEN COLLECTIONInfisical Admin KMS Encryption API
OPEN COLLECTIONInfisical Admin KMS Keys API
OPEN COLLECTIONInfisical Admin KMS Signing API
OPEN COLLECTIONInfisical Admin Kubernetes Auth API
OPEN COLLECTIONInfisical Admin LDAP Auth API
OPEN COLLECTIONInfisical Admin LDAP SSO API
OPEN COLLECTIONInfisical Admin OCI Auth API
OPEN COLLECTIONInfisical Admin OIDC Auth API
OPEN COLLECTIONInfisical Admin OIDC SSO API
OPEN COLLECTIONInfisical Admin Organization Identity Membership API
OPEN COLLECTIONInfisical Admin Organization Roles API
OPEN COLLECTIONInfisical Admin Organizations API
OPEN COLLECTIONInfisical Admin PKI ACME API
OPEN COLLECTIONInfisical Admin PKI Alerting API
OPEN COLLECTIONInfisical Admin Pki API
OPEN COLLECTIONInfisical Admin PKI Applications API
OPEN COLLECTIONInfisical Admin PKI Certificate Authorities API
OPEN COLLECTIONInfisical Admin PKI Certificate Collections API
OPEN COLLECTIONInfisical Admin PKI Certificate Policies API
OPEN COLLECTIONInfisical Admin PKI Certificate Profiles API
OPEN COLLECTIONInfisical Admin PKI Certificate Templates API
OPEN COLLECTIONInfisical Admin PKI Certificates API
OPEN COLLECTIONInfisical Admin PKI Discovery API
OPEN COLLECTIONInfisical Admin PKI Installations API
OPEN COLLECTIONInfisical Admin PKI Signers API
OPEN COLLECTIONInfisical Admin PKI Subscribers API
OPEN COLLECTIONInfisical Admin PKI Syncs API
OPEN COLLECTIONInfisical Admin Project Groups API
OPEN COLLECTIONInfisical Admin Project Identities API
OPEN COLLECTIONInfisical Admin Project Identity Membership API
OPEN COLLECTIONInfisical Admin Project Roles API
OPEN COLLECTIONInfisical Admin Project Templates API
OPEN COLLECTIONInfisical Admin Project Users API
OPEN COLLECTIONInfisical Admin Projects API
OPEN COLLECTIONInfisical Admin Relays API
OPEN COLLECTIONInfisical Admin SAML SSO API
OPEN COLLECTIONInfisical Admin SCIM API
OPEN COLLECTIONInfisical Admin Secret Imports API
OPEN COLLECTIONInfisical Admin Secret Rotations API
OPEN COLLECTIONInfisical Admin Secret Scanning API
OPEN COLLECTIONInfisical Admin Secret Sharing API
OPEN COLLECTIONInfisical Admin Secret Syncs API
OPEN COLLECTIONInfisical Admin Secrets API
OPEN COLLECTIONInfisical Admin Service Tokens API
OPEN COLLECTIONInfisical Admin SPIFFE Auth API
OPEN COLLECTIONInfisical Admin SSH Certificate Authorities API
OPEN COLLECTIONInfisical Admin SSH Certificate Templates API
OPEN COLLECTIONInfisical Admin SSH Certificates API
OPEN COLLECTIONInfisical Admin SSH Host Groups API
OPEN COLLECTIONInfisical Admin SSH Hosts API
OPEN COLLECTIONInfisical Admin Sub Organizations API
OPEN COLLECTIONInfisical Admin TLS Certificate Auth API
OPEN COLLECTIONInfisical Admin Token Auth API
OPEN COLLECTIONInfisical Admin Universal Auth API
OPEN COLLECTIONScroll within the panel for all 74 ·
Pricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the things the Kin Score reads for access clarity — renamed from commercial clarity in rubric 0.12, because a free statutory interface has access terms and no commercial ones.
Published pricing tiers and plan structures.
Rate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Infisical Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Infisical Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.
JSON-LD contexts and semantic vocabularies used across these APIs.
Infisical Context
JSON-LDSpectral Rules 1
Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.
Infisical API Rules
SPECTRALJSON Schema 5
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
Dynamic Secret Create
JSON SCHEMASecret Create
JSON SCHEMASecret Delete
JSON SCHEMASecret Update
JSON SCHEMAUniversal Auth Login
JSON SCHEMAExamples 3
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.
Recommended x-agentic-access execution contracts for AI agents.
Resources
Every other property we hold for Infisical — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Documentation 6
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 2
Properties that don't map to a standard resource type
← All providers · Data indexed from github.com/api-evangelist/infisical · machine-readable index on apis.io
This is an independent, third-party profile of Infisical, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.