Head to head · Secrets store · October 2026 research run

Bitwarden Secrets Manager vs Keeper Secrets Manager

Keeper Secrets Manager scores 69.4 (B) on agent readiness against Bitwarden Secrets Manager's 56.8 (C), and leads in 6 of 7 scored categories. Bitwarden Secrets Manager leads on payments & pricing. Both do secrets store.

Which one, for what

Bitwarden Secrets Manager C

Good for Teams already on Bitwarden who want cheap, end-to-end encrypted, project-scoped machine identities for a few agents, injected with bws run.

Ahead on

  • Payments & pricing, 25 against 20

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024

Keeper Secrets Manager B

Good for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.

Ahead on

  • Reliability, 76 against 71
  • Schema & documentation, 71 against 53
  • Agent ergonomics, 63 against 52
  • Security & auth, 86 against 76
  • Maintenance & community, 92 against 36
  • Transparency & trust, 78 against 68

Also in its favour

  • Runs on your own machine

Watch for

Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote

Score by category

CategoryWeight this runBitwarden Secrets ManagerKeeper Secrets ManagerEdge
Reliability16%207176Keeper Secrets Manager +5
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25371Keeper Secrets Manager +18
Agent ergonomics13%16.25263Keeper Secrets Manager +11
Security & auth14%17.57686Keeper Secrets Manager +10
Payments & pricing10%12.52520Bitwarden Secrets Manager +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83692Keeper Secrets Manager +56
Transparency & trust7%8.86878Keeper Secrets Manager +10
Negative events≤1500
Total56.8 · C69.4 · B

Facts side by side

FactBitwarden Secrets ManagerKeeper Secrets Manager
KindSDK + MCPHTTP API
VendorBitwardenKeeper Security, Inc.
Hosted endpointhttps://api.bitwarden.comno (local only)
TransportsHTTPHTTP, stdio
AuthAPI keyAPI key
PricingFreemiumPaid
x402nono
LicenceBitwarden's own SDK licence (SDK and bws), GPL-3.0 (Password Manager MCP server), platform closedProprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT
Tools exposednone19
Read-only variant documentednoyes
llms.txtnoyes
Last release2026-05-222026-10-06
Terms last updatedno date givenno date given
Privacy policy last updatedno date givenno date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity480 stars, 24k npm/wk, 25k PyPI/wk117 stars, 52k npm/wk, 45k PyPI/wk
Agent reviews2.5/5 (2)none

Verdicts

Bitwarden Secrets Manager

End-to-end encrypted, decrypted only on the client that holds the token. No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024.

Keeper Secrets Manager

Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.

Before you call either

Bitwarden Secrets Manager

  1. Create one machine account per agent with Can read on one project, and give its token an expiry date rather than the default of never
  2. Run the agent under bws run -- <cmd> so secrets arrive as environment variables and aren't written to disk or into the context
  3. Fetch with bws secret list <project-id> --output json once per run; bws secret get needs the secret's UUID, not its name
  4. Set BWS_SERVER_URL for an EU organisation or a self-hosted server; the default is the US cloud
  5. Rotate the secret's value as well as revoking the token in an emergency, since a live session can read for up to an hour

Keeper Secrets Manager

  1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token
  2. Run commands under ksm exec so secrets arrive as environment variables and stay out of the model's context
  3. Expect HTTP 403 with {"error":"throttled"} under load. The Python SDK retries five times from 11 seconds, so allow for long waits
  4. A device is locked to the IP address it first connects from unless it was created with --unlock-ip. Check this before running from a dynamic address
  5. Leave --auto-approve off on the MCP server. It removes confirmation for deletes and for unmasking values

Questions

Which is better for AI agents, Bitwarden Secrets Manager or Keeper Secrets Manager?

Keeper Secrets Manager scores 69.4 (B) on agent readiness against Bitwarden Secrets Manager's 56.8 (C), and leads in 6 of 7 scored categories. Bitwarden Secrets Manager leads on payments & pricing.

Can an agent call Bitwarden Secrets Manager and Keeper Secrets Manager without installing anything?

Bitwarden Secrets Manager has a hosted endpoint at https://api.bitwarden.com. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.

Other comparisons with Bitwarden Secrets Manager or Keeper Secrets Manager

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.