Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in
Azure Key Vault is a service for storing your application's secrets, keys and certificates securely - so they don't need to live in your code or configuration.
Locally supports both provisioning Key Vaults (and Managed HSMs) and managing the secrets, keys and certificates within them - so you can fully test your application against it.
When you provision a Key Vault in Locally, it's available at https://<vault>.vault.locally:5661/ (and a Managed HSM at https://<hsm>.managedhsm.locally:5661/), which you can connect to using the Azure Key Vault SDKs, the Azure CLI and Terraform.
Once a Key Vault has been created, you can find its Vault URI on its resource page within the Locally Dashboard - and Open in emulator takes you to the emulator:
Within the Key Vault Emulator you can browse and create secrets, keys and certificates, and look back through their versions:
You can also recover or purge soft-deleted items, and switch off public network access to see how your application copes. The Timeline shows what's happened in the vault.
The Key Vault emulator supports:
As of Locally v2026.09.02, the following API versions are supported for the Key Vault data plane:
Authentication is supported using a Microsoft Entra token - checked against the built-in data-plane roles (such as Key Vault Secrets User) for an RBAC vault, or the vault's access policies otherwise.
Keys use real cryptography for encrypt, decrypt, sign, verify, wrap and unwrap, and certificates are real self-signed certificates. A Managed HSM serves keys only, uses its own local RBAC, and needs activating by downloading its security domain - as it does in Azure.
Chaos Engineering (on the Team plan) can throttle, fail, slow down or drop requests - or simulate a regional outage - for Key Vault and Managed HSM separately.
Key Vault also works with Locally's other emulators, as you'd expect - for example:
NewVersionCreated, NearExpiry and Expired events for secrets, keys and certificates are sent to the vault's system topics in the Event Grid Emulator.@Microsoft.KeyVault(...) references using the app's managed identity.The locallybuild/examples repository has examples that provision a Key Vault, with keys and secrets, in Locally using:
As of Locally v2026.09.02, the Key Vault emulator has the following differences from Azure:
networkAcls) and private endpoints aren't applied to the data plane - only public network access is.503, rather than failing to resolve.7.0 to 7.6 and 2025-07-01, plus the previews from 7.2-preview) behaves the same way.Should you encounter any issues, please take a look at the troubleshooting section.
Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in
Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.