Alternatives

Tessera vs Boundary

HashiCorp Boundary is an open-source identity-aware proxy that brokers access to targets, with an Enterprise edition and a hosted HCP offering.

Boundary and Tessera agree on the shape — a proxy, nothing on your targets, identity-aware authorisation — and differ on where the line between free and paid falls. In Boundary Community, credentials are brokered to the user rather than injected into the session, and session recording is Enterprise or HCP Plus and SSH-only. Tessera puts credential injection, recording and read-only in one product, and enforces read-only itself rather than leaving it to the target.

Side by side

Tessera Boundary
Kill write access mid-session — no reconnect flip a live session RW → RO in one tap — on SSH, Kubernetes and SQL alike yes no
Nothing installed — and nothing reconfigured — on your targets your servers, clusters and databases stay exactly as they are yes yes
Fully self-hosted control plane no vendor cloud anywhere in the access path yes yes
One read-only switch across SSH · Kubernetes · SQL same policy, every protocol — not a per-protocol reimplementation yes no
Credentials injected on the controller — never on the user's machine SSH · Kubernetes · SQL yes partial
Session recording + live watch & force-close yes partial
Just-in-time access · RBAC · SSO · SCIM yes partial
Audit export to your SIEM yes partial

Every cell checked against Boundary's own documentation, 14 August 2026. Products change; if you find something out of date here, tell us and we will correct it.

Where Boundary is stronger

  • Open source, and no licence needed. Boundary Community is genuinely free software; an air-gapped install has no entitlement to install at all, which is simpler than ours.
  • The HashiCorp ecosystem. If you already run Vault and Terraform, Boundary's integration with them is something no third party can match.
  • Governance. A large open-source project with public roadmaps and a community, against a young commercial product from a small company.

Choose Boundary if…

You want open source with no vendor relationship, or you are already invested in Vault and Terraform and want access brokering that speaks the same language.

Choose Tessera if…

You want credential injection, session recording and read-only enforcement without an Enterprise tier — or read-only that the broker enforces across SSH, Kubernetes and SQL rather than something you configure on each target.

Comparing something else? Tessera vs Teleport · Tessera vs StrongDM