{"data":{"slug":"openbao","name":"OpenBao","tagline":"MPL-2.0 Vault-compatible secrets engine after the Vault fork","category":"nextjs","categoryName":"Next.js","url":"https://openbao.org","github":"https://github.com/openbao/openbao","pricing":"open-source","hook":"OpenBao is the Vault-shaped secrets engine you run when the HashiCorp license line is the problem.","whatsGood":"MPL-2.0. Linux Foundation Vault-compatible fork. KV, transit, auth methods, policies — the engine shape teams already know. Self-host is the free path.","theCatch":"Vault-engine / IdP-secrets lane, not Infisical app-secrets DX. Infisical already shipped — this is the engine/compat fork, not the developer-secrets UI. Do not invent Cloud free tiers.","verdict":"MPL Vault-compat engine. Fork for license, not Infisical DX.","addedAt":"2026-09-04","featured":false,"domain":"Auth","subSpecialty":"Secrets","capabilities":["secrets","vault-compat","self-host"],"surfaces":["Self-host"],"ecosystem":["Multi-platform"],"licenseModel":"OSS/MIT","githubStars":7272},"related":[{"slug":"vercel","name":"Vercel","tagline":"The platform that made Next.js deployment trivial"},{"slug":"prisma","name":"Prisma","tagline":"Type-safe database access with killer DX"},{"slug":"drizzle","name":"Drizzle ORM","tagline":"TypeScript ORM that feels like SQL"},{"slug":"trpc","name":"tRPC","tagline":"End-to-end typesafe APIs without codegen"},{"slug":"clerk","name":"Clerk","tagline":"Auth that actually ships with your UI"}],"links":{"self":"/api/gems/openbao","html":"/gems/openbao","markdown":"/gems/openbao.md","category":"/api/gems?category=nextjs","categoryPage":"/stacks/nextjs"}}