Boundary is HashiCorp's open-source tool for identity-based, zero-trust secure remote access to dynamic hosts and services, with a managed HCP option.
Boundary is HashiCorp's open-source, identity-based secure remote access solution, first announced in October 2020. It lets organizations grant users and machines access to dynamic hosts and services based on verified identity and role rather than network location, avoiding traditional VPN-style network exposure.
HashiCorp, founded in 2012 and headquartered in San Francisco, became a subsidiary of IBM in February 2025 following a $6.4 billion acquisition, while continuing to develop and support Boundary and its other infrastructure tools.
Boundary brokers just-in-time connections to SSH, RDP, database, and web targets based on identity and role, with dynamic host catalogs that automatically keep resource inventories current as cloud infrastructure changes.
Session recording and visibility support auditing, while integration with HashiCorp Vault enables dynamic, short-lived credentials so end users never handle static secrets. Access can be automated via CLI, API, Terraform provider, or SDKs.
Boundary Community Edition is free and open source for self-managed deployments. HCP Boundary, the managed cloud offering, is available in Standard and Plus tiers and billed on a usage basis per authenticated "HCP Boundary User" per month; exact unit rates are not published and require contacting HashiCorp. A self-managed Boundary Enterprise edition is also available for organizations that want additional features and support without using the managed cloud control plane.
The self-managed Community Edition is free and open source. Boundary Enterprise and the managed HCP Boundary service are paid offerings with additional features and support.
Boundary grants access based on authenticated identity and role rather than placing a user on the network, so users never get broad network-level access to systems they aren't authorized for.
No, but it integrates closely with Vault for dynamic credentials and Terraform for infrastructure-as-code automation, and many users already run those tools alongside it.
HashiCorp became a wholly owned subsidiary of IBM after the acquisition closed in February 2025, though it continues to operate and develop its product line, including Boundary, under the HashiCorp brand.
Boundary supports SSH, RDP, TCP, and database connections, brokering sessions to these target types based on user identity and role.