HashiCorp Vault and BSL 1.1: What It Means and What to Do About It
Apr 14, 2026
ArticlePlan a Vault-to-OpenBao migration after HashiCorp BSL: keep the API, cut licensing cost and protect unseal keys with customer-held MPC.
Read article
OpenBAO is the Linux Foundation fork of Vault with 100% API compatibility. MPL 2.0 instead of BSL 1.1, MPC auto-unseal without extra HSM hardware, EU-hosted managed service from an OpenBAO co-maintainer. Free migration assessment.
If you are searching for a HashiCorp Vault Enterprise alternative, the migration fear is usually the same: "we cannot rewrite every application that speaks the Vault API." OpenBAO removes that fear first. Everything else (licence, unseal model, who runs it) comes after.
OpenBAO is the Linux Foundation fork of HashiCorp Vault. For application teams, the operational claim that matters is simple:
OpenBAO speaks the Vault API. You point clients at a new address. You do not rewrite secret reads, AppRoles, or transit calls.
That is the point that neutralises migration fear. Programme risk becomes infrastructure cutover and unseal design, not a multi-quarter application refactor.
Product path: OpenBAO + DuoKey SD-HSM.
In August 2023 HashiCorp moved Vault to Business Source License 1.1 (BSL). That change is a public, vendor-declared licence shift away from the open-source terms many estates had budgeted against.
OpenBAO remains under Mozilla Public License 2.0 with Linux Foundation governance. You keep an open-source licence model and a neutral foundation process, instead of a proprietary source licence with a "competing product" framing.
For the licence history and migration checklist, see our deeper guide: HashiCorp Vault BSL licence change and OpenBAO migration.
Vault and OpenBAO both need a seal/unseal story. Classic Enterprise patterns push teams toward extra HSM hardware or an additional cloud KMS just to unseal and protect seal wrap material.
DuoKey SD-HSM uses multi-party computation so unseal and seal-wrap key material is split across nodes. The complete unseal secret is never reconstituted in plaintext on one appliance. You avoid:
Background: MPC vs HSM.
DuoKey's managed OpenBAO service is delivered by a co-maintainer of OpenBAO and a member of the Linux Foundation Technical Steering Committee (TSC) for the project, hosted in the EU.
That is a verifiable authority claim, not a reseller badge: we help build the software we operate. Support, upgrades and incident response sit with people who work in the upstream project, not only against a vendor binary.
| Dimension | Typical Vault Enterprise pressure | OpenBAO + DuoKey |
|---|---|---|
| Licence | BSL 1.1 since August 2023 | MPL 2.0, Linux Foundation |
| API | Vault API | Same API (OpenBAO) |
| Unseal | HSM or cloud KMS add-on | MPC SD-HSM auto-unseal |
| Operations | Customer-run or HashiCorp commercial support | EU-hosted managed service from OpenBAO co-maintainers |
| Application change | Often feared as a rewrite | Address change; no app code rewrite for API-compatible clients |
On TCO. Industry and internal programme estimates often cite up to 60-80% lower secrets-management run-rate when per-client-token Enterprise licensing and dedicated unseal HSM cost are removed. Treat that range as an estimate: actual savings depend on token count, support tier, HSM estate and how much operations you move to managed service. We quantify it on a free migration assessment rather than publishing a single guaranteed percentage.
Entry offer: a free migration assessment. We map your Vault usage (auth methods, secrets engines, seal configuration, token growth) to an OpenBAO + SD-HSM target and a 2-4 week style cutover plan where the estate fits that window.
Start from the product page or contact sales for the assessment.
Q: Is OpenBAO really API-compatible with Vault?
OpenBAO is maintained as an open fork intended to preserve Vault API compatibility for existing clients. In practice, migration programmes treat endpoint cutover and behavioural testing as the work, not application rewrites. Validate your specific plugins and auth methods in the assessment.
Q: Does this replace the need for any HSM forever?
Some regulated controls still call for FIPS-validated modules in specific contexts. For auto-unseal and seal wrap, MPC SD-HSM is designed to remove the "extra HSM only for Vault unseal" pattern. Bring your compliance mapping to the assessment.
Q: How is this different from the case study on the platform?
The platform case study summarises an outcome. This page and the product are the commercial landing for teams actively evaluating a Vault Enterprise alternative.
A credible Vault Enterprise alternative has to clear the API fear first. OpenBAO does that with Linux Foundation governance and MPL 2.0. DuoKey adds MPC auto-unseal without a parallel HSM tax, and a managed EU service run by OpenBAO co-maintainers. Start with a free migration assessment; bring token counts and seal design, leave with a cutover plan.
Written by
Nagib Aouini
Related Resources
Tell us where control is difficult today. We will help you identify a practical next step.