Boundary Review, Pricing & Features

Boundary is HashiCorp's open-source tool for identity-based, zero-trust secure remote access to dynamic hosts and services, with a managed HCP option.

Category
Security
Pricing
Open Source / Usage-based, from Free (self-managed Community Edition)
Verified
Not yet
Last updated
July 18, 2026
Founded
2020
Headquarters
San Francisco, California, USA
Free PlanAPIOpen SourceSelf-Hosted

Overview

Boundary is HashiCorp's open-source, identity-based secure remote access solution, first announced in October 2020. It lets organizations grant users and machines access to dynamic hosts and services based on verified identity and role rather than network location, avoiding traditional VPN-style network exposure.

HashiCorp, founded in 2012 and headquartered in San Francisco, became a subsidiary of IBM in February 2025 following a $6.4 billion acquisition, while continuing to develop and support Boundary and its other infrastructure tools.

Key Features

Boundary brokers just-in-time connections to SSH, RDP, database, and web targets based on identity and role, with dynamic host catalogs that automatically keep resource inventories current as cloud infrastructure changes.

Session recording and visibility support auditing, while integration with HashiCorp Vault enables dynamic, short-lived credentials so end users never handle static secrets. Access can be automated via CLI, API, Terraform provider, or SDKs.

Pricing

Boundary Community Edition is free and open source for self-managed deployments. HCP Boundary, the managed cloud offering, is available in Standard and Plus tiers and billed on a usage basis per authenticated "HCP Boundary User" per month; exact unit rates are not published and require contacting HashiCorp. A self-managed Boundary Enterprise edition is also available for organizations that want additional features and support without using the managed cloud control plane.

Key Features

Pros & Cons

Pros

  • Free, open-source Community Edition for self-managed use
  • Removes need for traditional VPN network exposure
  • Deep integration with Vault, Terraform, and the wider HashiCorp ecosystem
  • Session recording supports compliance and audit requirements

Cons

  • Operational complexity to self-host and integrate with existing infrastructure
  • Advanced features (recording, HA, enterprise governance) require paid Enterprise or HCP tiers
  • HCP Boundary per-user pricing is not publicly listed
  • Best value requires familiarity with the broader HashiCorp toolchain

Pricing

Frequently Asked Questions

Is HashiCorp Boundary free?

The self-managed Community Edition is free and open source. Boundary Enterprise and the managed HCP Boundary service are paid offerings with additional features and support.

How is Boundary different from a VPN?

Boundary grants access based on authenticated identity and role rather than placing a user on the network, so users never get broad network-level access to systems they aren't authorized for.

Does Boundary require other HashiCorp products?

No, but it integrates closely with Vault for dynamic credentials and Terraform for infrastructure-as-code automation, and many users already run those tools alongside it.

Who owns HashiCorp now?

HashiCorp became a wholly owned subsidiary of IBM after the acquisition closed in February 2025, though it continues to operate and develop its product line, including Boundary, under the HashiCorp brand.

What protocols does Boundary support for target access?

Boundary supports SSH, RDP, TCP, and database connections, brokering sessions to these target types based on user identity and role.

Comparisons

Related Tools