HashiCorp Boundary

Session broker from HashiCorp, pairs with Vault for JIT credential injection

ToolPrivileged Access ManagementOpen SourceCloudSelf-hosted

Pricing: Free and open source; paid tiers on the vendor site.

Reviewed by the CyberSecTool editorial team against the public sources cited below · Last reviewed February 2026 · How we review listings

What is HashiCorp Boundary?

HashiCorp Boundary is an identity-aware session broker for remote access to infrastructure. It pairs naturally with HashiCorp Vault to provide just-in-time credential brokering: users authenticate with Boundary using their identity provider, Boundary requests short-lived credentials from Vault, and injects them into the session without exposing them. Boundary is open source (MPL 2.0) with a commercial HCP Boundary cloud offering.

Best for: Teams already invested in HashiCorp tooling who want unified secrets + session access
Pros
  • Natural fit for teams already running HashiCorp Vault
  • Open source core with no license cost
  • Terraform-native workflow for declarative access policies
  • HCP option removes operational overhead
Things to check
  • Younger product; smaller community than Teleport
  • Session recording requires Enterprise tier
  • Best value comes bundled with Vault. Less compelling standalone
  • Fewer enterprise integrations than legacy PAM

Reported in public reviews and vendor documentation. See sources below.

Key Features

Identity-aware session brokering for SSH, RDP, databases
Credential injection via HashiCorp Vault integration
Targets and host catalogs for dynamic discovery
Role-based access with SSO integration
Session recording (Enterprise/HCP tier)
Works across multi-cloud and on-premises
Terraform provider for infrastructure-as-code auth policies
HCP Boundary managed cloud offering
Ingress workers for private network access
Audit events and session telemetry

Are you HashiCorp Boundary? Improve this listing with screenshots, case studies and more.