Secrets Manager plans and features

IBM Cloud® Secrets Manager offers three distinct plans to meet different organizational needs: Trial, Standard, and Vault Dedicated. Each plan provides secure secrets management capabilities with varying features and operational characteristics.

Trial and Standard plans

The Trial and Standard plans provide the same comprehensive secrets management capabilities. The Trial plan offers a time-limited way to explore Secrets Manager at no cost, while the Standard plan provides production-ready secrets management for applications and services.

Trial and Standard plans offer the same feature set. The only difference is that Trial plans are limited to 30 days and you can have only one Trial instance per account.

Trial and Standard plan capabilities

With the Trial and Standard plans, you get:

  • A single-tenant, dedicated instance for each service instance.
  • Support for all secret types (arbitrary, user credentials, service credentials, IAM credentials, key-value, imported certificates, public certificates, and private certificates).
  • Automatic secret rotation capabilities.
  • Secret versioning and lifecycle management.
  • Secret groups for organizing and controlling access.
  • Secret locks to prevent accidental deletion or modification.
  • Private and public endpoints for secure access.
  • Data encryption at rest with either service-managed encryption or customer-managed keys.
  • Integration with IBM Cloud services and third-party tools.
  • Activity tracking through IBM Cloud Logs.
  • Event notifications for secret lifecycle events.

Trial plan limitations

The Trial plan has the following limitations:

  • 30-day time limit.
  • Only 1 Trial instance per account.
  • Can only upgrade to Standard (not to Vault Dedicated).

For more information, see Upgrading to the Standard plan.

For more information about pricing, see Pricing for the Trial and Standard plans.

Vault Dedicated plan

The Vault Dedicated plan is a distinct offering that delivers Vault Enterprise as a managed service in IBM Cloud. It is designed for workloads that need dedicated Vault capabilities together with managed operations in IBM Cloud.

The Vault Dedicated is currently available as a public beta. Beta features are provided for evaluation and testing purposes and have limitations compared to generally available features.

Vault Dedicated public beta limitations

During the public beta period, the Vault Dedicated plan has the following temporary restrictions:

  • Instance limit: Only 1 Vault Dedicated instance per account during beta.
  • No upgrade path: Cannot upgrade from beta to GA. All beta instances will be deleted before general availability.
  • Regional availability: Available in Dallas and Frankfurt.
  • Free during beta: No charges apply during the beta period.
  • Beta to GA migration: Data migration from beta instances to GA instances is not supported.

These limitations will be removed or modified when the Vault Dedicated plan reaches general availability.

vault Dedicated capabilities

With the Vault Dedicated plan, you get:

  • A managed Vault Enterprise cluster that is configured for high availability across three nodes in a multi-zone region.

  • Namespace-based isolation for multi-team environments.

  • Private and public endpoints for secure access to your instance.

    The Vault Dedicated plan supports VPE (Virtual Private Endpoint) gateways only for private connectivity — Cloud Service Endpoints (CSE) are not supported. If you provision a private-only instance, a VPE gateway is required for API access and a Client-to-Site VPN is required to access the Vault UI from a browser. For more information, see Service endpoints for the Vault Dedicated plan.

  • Data encryption at rest with either service-managed encryption or customer-managed keys.

  • The native Vault UI for management and configuration tasks.

  • Advanced compliance and security features:

    • FIPS 140-3 compliant cryptography using the Vault Enterprise FIPS build for supported Vault cryptographic operations.
    • Advanced policy enforcement capabilities:
      • Vault ACL policies with fine-grained path and operation-level authorization
      • Sentinel policy enforcement for code-based policy guardrails and compliance automation
      • Control Groups for human approval workflows on high-value operations
    • Transit Encryption Engine for encryption-as-a-service: encrypt, decrypt, sign, verify, and derive keys without key material leaving Vault.
  • Enterprise-scale Vault capabilities for complex deployments.

  • Dedicated activity tracking events that are routed through IBM Cloud Logs for auditing and monitoring.

For more information about auditing events for the service, see Instance operations events. For more information about pricing, see Pricing.

Key capabilities include:

  • Namespace-based isolation for multi-team environments.
  • Advanced compliance and security features.
  • High availability and disaster recovery support.
  • Enterprise-scale Vault capabilities for complex deployments.

Vault Dedicated plan limitations

The Vault Dedicated plan has the following limitations:

  • Not compatible with the Trial or Standard plan. You cannot upgrade or migrate between plan types.
  • Vault Dedicated instances cannot be provisioned in all regions. For more information, see Regions and endpoints.
  • The native Secrets Manager UI is not available. Management is performed through the native Vault UI, API, or CLI.
  • Secret types supported by Trial and Standard plans (such as IAM credentials and service credentials) are not available.