Deployment: Invicti Platform on-demand
Secret managers overview
Invicti Platform integrates with external secret managers so credentials are retrieved directly from your vault at scan time. Instead of storing credentials in Invicti Platform, you configure a connection to your secret manager and map individual secrets to the fields where they're needed. For managing credentials stored directly in Invicti Platform, refer to the Secrets document.
This document explains how secret manager integrations work in Invicti Platform and which systems are supported.
Why this matters
Storing scan credentials outside Invicti Platform means your security team keeps full control of credential lifecycle in one place. Rotation, revocation, and access auditing happen in your vault - Invicti Platform reads the current value at scan time and never caches it.
How it works
Secret manager integrations follow a two-step model:
- Configure the connection - authenticate Invicti Platform against your secret manager by entering the vault URL, authentication method, and any required credentials or certificates.
- Map secrets to scan fields - when configuring authentication for a target, use the secret picker to select Use Integration and specify the path and key of the secret in your vault. Invicti Platform stores only the reference, not the value.
At scan time, Invicti Platform resolves the reference and injects the current secret value. The credential is never stored or displayed in Invicti Platform.
Supported secret managers
| Secret manager | Authentication methods |
|---|---|
| HashiCorp Vault | Token, TLS certificate |
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center