SikkerKey Blog
Security writeups, engineering deep-dives, and practical guides from the team building SikkerKey.
RSS feedDynamic Secrets vs Leased Credentials: What's the Difference?
Dynamic secrets (HashiCorp Vault, Infisical, etc) and SikkerKey's leased credentials both mint short-lived database logins on demand. The difference is how a machine proves it may mint one: a bearer token, or a signed request with nothing reusable issued.
Alternatives to .env Files
The simplest alternative to a .env file is to stop keeping secrets in files. With SikkerKey you bootstrap a machine in one command, and the CLI and SDKs read secrets with no token and no config, plus rotation, a full audit log, and per-secret access.
Secrets Manager Pricing: Is Your Team Spending Too Much In 2026?
A SikkerKey-first 2026 pricing comparison showing how managed secrets manager pricing changes across machines, identities, users, secrets, versions, and usage meters.
Traditional vs Modern Secrets Management In 2026
Traditional secrets managers use your strong login only to mint a weaker bearer token, then bolt crutches like short expiry and rotation around it. A modern secrets manager proves a machine's identity on every request instead, so there is nothing reusable to steal.
Best EU Secrets Managers in 2026
A practical 2026 comparison of EU secrets managers: SikkerKey, STACKIT Secrets Manager, Scaleway Secret Manager, and OVHcloud Secret Manager, by jurisdiction, machine authentication, cloud independence, and the teams each one fits.