Prompt
Are there any developer portals that handle secure secret storage and internal team collaboration?
Latest observation
Yes, several developer portals and internal developer platforms (IDPs) provide secure secret storage (or tight integration with secret managers) alongside features designed for internal team collaboration.
Platforms that combine both capabilities
Harness Internal Developer Portal (IDP)
Includes a software catalog, self-service workflows, ownership tracking, and documentation for team collaboration. It natively supports integration with major secret managers (HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, and others) so credentials used by plugins, workflows, and services stay encrypted and access-controlled. RBAC, audit trails, and policy enforcement (including OPA) further secure collaboration.
Northflank
Functions as both a full internal developer platform and a portal. Developers can self-serve services, databases, jobs, and pipelines. It includes built-in secrets management via secret groups that inject environment variables and connection strings into workloads. Access controls and shared environments support team collaboration while keeping secrets isolated.
Port
A commercial IDP focused on a flexible software catalog, self-service actions, scorecards, and ownership. Collaboration features (catalog discovery, team ownership, workflows) are core. Secrets are typically managed through integrations with external secret managers; the portal itself handles secure credential references for actions and integrations.
Cortex
Emphasizes service catalogs, scorecards, ownership, and engineering-excellence tracking for cross-team collaboration. It provides a secrets store for plugin configuration and API keys (with permissions), and integrates with external secret managers for runtime secrets.
Backstage (and managed variants such as Roadie or Harness IDP)
The open-source standard for developer portals. It excels at service catalogs, documentation, ownership, and plugin-based collaboration. Secure secret handling is achieved through plugins and integrations with Vault or cloud secret managers rather than a built-in vault, but the ecosystem supports this cleanly.
Related tools that lean more toward secrets + collaboration
Onboardbase and Doppler are developer-oriented secret managers with strong team collaboration features (role-based access, environment isolation, audit logs, and secure sharing). They are not full developer portals but are frequently used alongside IDPs.
Coder provides governed, self-hosted workspaces where teams collaborate securely; secrets can be injected via integrations while source code and environments stay under organizational control.
Practical guidance
Most mature IDPs treat the portal as the collaboration and discovery layer (catalog, ownership, self-service, scorecards) and rely on a dedicated secret manager for actual secret storage and rotation. Platforms such as Harness IDP and Northflank go further by offering tighter native or first-class secret handling inside the same control plane.
If your priority is a single place where developers discover services, request resources, share ownership, and safely access secrets, evaluate Harness IDP or Northflank first. If you already run Backstage or prefer a pure catalog + scorecard focus, pair Port or Cortex with an external secrets manager such as Vault, Doppler, or a cloud-native service.
Brands
Citations
- https://developer.harness.io/internal-developer-portal/new-to-idp/overview
- https://developer.harness.io/internal-developer-portal/new-to-idp/whats-supported
- https://northflank.com/blog/top-internal-developer-portals
- https://onboardbase.com/
- https://www.cortex.io/post/cto-pocket-guide-to-idps
- https://kubernetesguru.com/internal-developer-platform-tools-2026/
- https://www.qovery.com/blog/10-best-internal-developer-portals-to-consider
- https://docs.cortex.io/configure/settings/api-keys/secrets