{
  "data": {
    "similar": [
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/infisical.json",
        "name": "Infisical",
        "score": 83.7,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "infisical"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/aws-secrets-manager.json",
        "name": "AWS Secrets Manager",
        "score": 77.7,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "aws-secrets-manager"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/google-secret-manager.json",
        "name": "Google Cloud Secret Manager",
        "score": 76.5,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "google-secret-manager"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/azure-key-vault.json",
        "name": "Azure Key Vault",
        "score": 74.7,
        "shared": [
          "secrets.store",
          "secrets.machine-identity",
          "secrets.audit",
          "secrets.rotate"
        ],
        "slug": "azure-key-vault"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/akeyless.json",
        "name": "Akeyless (SecretlessAI and MCP server)",
        "score": 73.6,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "akeyless"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/doppler.json",
        "name": "Doppler",
        "score": 71.4,
        "shared": [
          "secrets.store",
          "secrets.rotate",
          "secrets.machine-identity",
          "secrets.audit"
        ],
        "slug": "doppler"
      }
    ],
    "tool": {
      "slug": "keeper-secrets-manager",
      "name": "Keeper Secrets Manager",
      "vendor": "Keeper Security, Inc.",
      "vendorUrl": "https://www.keepersecurity.com/secrets-manager.html",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Keeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the `ksm` CLI or a local MCP server, decrypting on the client.",
      "url": "https://www.anchorterminal.com/tools/keeper-secrets-manager",
      "markdownUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json",
      "repo": "https://github.com/Keeper-Security/secrets-manager",
      "license": "Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "keeper-secrets-manager-core"
        },
        {
          "registry": "pypi",
          "name": "keeper-secrets-manager-cli"
        },
        {
          "registry": "npm",
          "name": "@keeper-security/secrets-manager-core"
        }
      ],
      "auth": "api-key",
      "authNotes": "Access is granted by a person. A vault user whose role allows it creates a Secrets Manager application, shares folders or records with it, and adds a client device, which yields a one-time access token or a Base64 configuration. The client redeems the token once, registers its own ECC public key and signs every later request with the private key, so no bearer secret is reused. Devices are IP-locked by default, can be given an access expiry and are revoked individually.",
      "pricing": "paid",
      "pricingNotes": "Secrets Manager is an add-on to Keeper's business password manager plans, licensed per user per year, and included with KeeperPAM. The add-ons page shows Custom Pricing and Request a Quote for it, so there is no public figure. A 14-day business trial needs no credit card and can enable Secrets Manager, so an agent's owner can start without a contract. Base plan prices are drawn by script and were blank to our reader (https://www.keepersecurity.com/pricing/business-add-ons/, https://www.keepersecurity.com/trial/keeper-free-trial/, checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Secrets Manager docs, the SDK repository or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 19,
      "popularity": {
        "githubStars": 117,
        "npmWeekly": 52332,
        "pypiWeekly": 45154,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.keeper.io/en/keeperpam/secrets-manager/overview",
      "llmsTxt": "https://docs.keeper.io/llms.txt",
      "capabilities": [
        "secrets.store",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.rotate"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "zero-knowledge",
        "mcp",
        "cli",
        "python",
        "javascript",
        "java",
        "go",
        "dotnet",
        "ruby",
        "rust",
        "llms-txt",
        "sales-led",
        "status-page",
        "bug-bounty",
        "soc2",
        "fedramp"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.4,
        "grade": "B",
        "agentReady": false,
        "rank": 159,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 92,
          "payments": 20,
          "reliability": 76,
          "schema": 71,
          "security": 86,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 76,
            "points": 15.2,
            "reason": "Graded with the hosted lines, because the vault is Keeper's cloud and the SDKs, CLI and MCP server are clients of it. Statuspage at statuspage.keeper.io with a Keeper Secrets Manager component and regional infrastructure components (20). Since 10 July 2026 it lists one minor incident, SMS two-factor messages on 9 September for about three hours, and one notice on EU KeeperPAM connections on 30 July, with nothing posted against Secrets Manager (28 of 30). No request limits with numbers were found in the reviewed documentation (0). The Python SDK retries a throttled call (HTTP 403 with `{\"error\":\"throttled\"}`) five times with backoff from 11 seconds and honours `retry_after`, and every SDK has an optional encrypted local cache for when the endpoint is unreachable, but there are no idempotency keys (10 of 15). The SaaS terms carry Service Level Objectives of 99.9 per cent monthly availability, with termination as the only remedy (8 of 10). Generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 71,
            "points": 11.54,
            "reason": "No OpenAPI or other published contract for the Secrets Manager endpoint at `/api/rest/sm/v1`. The official MCP server defines JSON Schema inputs on all 19 tools (15 of 25). docs.keeper.io has an `llms.txt` index and serves every page as Markdown (10). The docs explain applications, devices, tokens and Keeper notation well, while MCP tool descriptions are short, such as Get a secret by UID, and don't say when to choose one tool over another (11 of 20). SDKs have typed record and field classes, and MCP inputs mark required fields, with free-form objects for record fields (11 of 15). Each SDK page has worked examples and there's a troubleshooting page, but no error reference was found (9 of 15). Each SDK has its own version tags and dated release notes on docs.keeper.io (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 63,
            "points": 10.24,
            "reason": "The MCP server has 19 tools, lists metadata only and masks sensitive fields unless asked (17 of 25). Secrets are fetched by UID, by title or by folder, and Keeper notation reads a single field, with no paging (13 of 20). Throttling is an HTTP 403 with a JSON body and the Python SDK raises a typed `KeeperThrottleError`, but no documented list of error codes was found (10 of 20). No idempotency keys, and the MCP tool definitions carry no `readOnlyHint` or `destructiveHint` annotations, though writes go through a confirmation step (8 of 20). SDKs in seven languages, and a client needs only its configuration to start (15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 86,
            "points": 15.05,
            "reason": "A one-time token bootstraps each device, which then signs every request with its own ECC secp256r1 key. Devices are locked to an IP address by default, can be given an access expiry, and are revoked one at a time with `secrets-manager client revoke`. An application reaches only the shared folders and records assigned to it (27 of 30). Shares are read-only unless made with `--editable`, and the MCP server asks for confirmation before create, update, delete, upload and unmasking, with an `--auto-approve` flag that turns this off (17 of 20). Secrets aren't untrusted content, and the MCP guides warn that data passed to third-party AI tools falls under those tools' practices (10). Device connect, access, record update and blocked-IP events go to the Advanced Reporting and Alerts module, which is sold as a separate add-on, and the MCP server keeps local audit logs (12 of 15). A valid `security.txt` expiring 31 December 2026, a Bugcrowd programme, and SOC 2 Type 2, ISO 27001 and FedRAMP High per the docs (20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 (0). The add-ons page shows Custom Pricing and Request a Quote for Secrets Manager, and the product page says it is licensed per user per year without a figure. Base plan prices are drawn by script and were blank to our reader (0). A 14-day business trial with no credit card, which the quick start says covers Secrets Manager (20). A person signs up, enables a role policy and creates the application and device in the vault or Commander (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 92,
            "points": 8.05,
            "reason": "Newest tag is the JavaScript GCP KMS storage 1.1.0 on 6 October 2026, two days before this check (30). Five tags since 15 September, among them JavaScript SDK 17.6.0, Java SDK 17.4.0 and CLI 1.5.0 (20). Three open issues, each with a reply, and 21 open pull requests (20 of 25). Seven official SDKs are current, the newest Python core being 17.3.0 from 15 June 2026. The Node MCP repository linked from the docs returned 404, and we didn't check the MCP registry (13 of 15). The 30 most recent workflow runs on master all succeeded, with dependency update runs among them (9 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 78,
            "points": 6.83,
            "note": "editorial 58, provenance 98",
            "reason": "The SDKs, CLI, MCP server and agent kit are MIT on GitHub. The service is closed, under published SaaS terms that replaced the previous terms on 9 March 2026 (20 of 30). A privacy policy and a DPA are published and agree with the zero-knowledge model, where Keeper holds ciphertext. Retention is stated as for as long as an account is active, without periods (20 of 30). No deprecation policy for the SDKs or API was found. The legal pages keep an archive of earlier terms and a change summary (4 of 20). Hosting is on AWS in the US, US GovCloud, EU, Australia, Canada and Japan with the tenant fixed to its region. The DPA points to a sub-processor list in the trust centre, which is drawn by script and was unread (14 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP server has 19 tools, lists metadata only and masks sensitive fields unless asked (17 of 25). Secrets are fetched by UID, by title or by folder, and Keeper notation reads a single field, with no paging (13 of 20). Throttling is an HTTP 403 with a JSON body and the Python SDK raises a typed `KeeperThrottleError`, but no documented list of error codes was found (10 of 20). No idempotency keys, and the MCP tool definitions carry no `readOnlyHint` or `destructiveHint` annotations, though writes go through a confirmation step (8 of 20). SDKs in seven languages, and a client needs only its configuration to start (15).",
            "maintenance": "Newest tag is the JavaScript GCP KMS storage 1.1.0 on 6 October 2026, two days before this check (30). Five tags since 15 September, among them JavaScript SDK 17.6.0, Java SDK 17.4.0 and CLI 1.5.0 (20). Three open issues, each with a reply, and 21 open pull requests (20 of 25). Seven official SDKs are current, the newest Python core being 17.3.0 from 15 June 2026. The Node MCP repository linked from the docs returned 404, and we didn't check the MCP registry (13 of 15). The 30 most recent workflow runs on master all succeeded, with dependency update runs among them (9 of 10).",
            "payments": "No x402, MPP or L402 (0). The add-ons page shows Custom Pricing and Request a Quote for Secrets Manager, and the product page says it is licensed per user per year without a figure. Base plan prices are drawn by script and were blank to our reader (0). A 14-day business trial with no credit card, which the quick start says covers Secrets Manager (20). A person signs up, enables a role policy and creates the application and device in the vault or Commander (0).",
            "reliability": "Graded with the hosted lines, because the vault is Keeper's cloud and the SDKs, CLI and MCP server are clients of it. Statuspage at statuspage.keeper.io with a Keeper Secrets Manager component and regional infrastructure components (20). Since 10 July 2026 it lists one minor incident, SMS two-factor messages on 9 September for about three hours, and one notice on EU KeeperPAM connections on 30 July, with nothing posted against Secrets Manager (28 of 30). No request limits with numbers were found in the reviewed documentation (0). The Python SDK retries a throttled call (HTTP 403 with `{\"error\":\"throttled\"}`) five times with backoff from 11 seconds and honours `retry_after`, and every SDK has an optional encrypted local cache for when the endpoint is unreachable, but there are no idempotency keys (10 of 15). The SaaS terms carry Service Level Objectives of 99.9 per cent monthly availability, with termination as the only remedy (8 of 10). Generally available (10).",
            "schema": "No OpenAPI or other published contract for the Secrets Manager endpoint at `/api/rest/sm/v1`. The official MCP server defines JSON Schema inputs on all 19 tools (15 of 25). docs.keeper.io has an `llms.txt` index and serves every page as Markdown (10). The docs explain applications, devices, tokens and Keeper notation well, while MCP tool descriptions are short, such as Get a secret by UID, and don't say when to choose one tool over another (11 of 20). SDKs have typed record and field classes, and MCP inputs mark required fields, with free-form objects for record fields (11 of 15). Each SDK page has worked examples and there's a troubleshooting page, but no error reference was found (9 of 15). Each SDK has its own version tags and dated release notes on docs.keeper.io (15).",
            "security": "A one-time token bootstraps each device, which then signs every request with its own ECC secp256r1 key. Devices are locked to an IP address by default, can be given an access expiry, and are revoked one at a time with `secrets-manager client revoke`. An application reaches only the shared folders and records assigned to it (27 of 30). Shares are read-only unless made with `--editable`, and the MCP server asks for confirmation before create, update, delete, upload and unmasking, with an `--auto-approve` flag that turns this off (17 of 20). Secrets aren't untrusted content, and the MCP guides warn that data passed to third-party AI tools falls under those tools' practices (10). Device connect, access, record update and blocked-IP events go to the Advanced Reporting and Alerts module, which is sold as a separate add-on, and the MCP server keeps local audit logs (12 of 15). A valid `security.txt` expiring 31 December 2026, a Bugcrowd programme, and SOC 2 Type 2, ISO 27001 and FedRAMP High per the docs (20).",
            "transparency": "The SDKs, CLI, MCP server and agent kit are MIT on GitHub. The service is closed, under published SaaS terms that replaced the previous terms on 9 March 2026 (20 of 30). A privacy policy and a DPA are published and agree with the zero-knowledge model, where Keeper holds ciphertext. Retention is stated as for as long as an account is active, without periods (20 of 30). No deprecation policy for the SDKs or API was found. The legal pages keep an archive of earlier terms and a change summary (4 of 20). Hosting is on AWS in the US, US GovCloud, EU, Australia, Canada and Japan with the tenant fixed to its region. The DPA points to a sub-processor list in the trust centre, which is drawn by script and was unread (14 of 20)."
          },
          "sources": [
            {
              "what": "Secrets Manager overview",
              "url": "https://docs.keeper.io/en/keeperpam/secrets-manager/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index (`llms.txt`)",
              "url": "https://docs.keeper.io/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "architecture and local cache",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/about/architecture",
              "seen": "2026-10-08"
            },
            {
              "what": "security and encryption model, IP lock, revocation, certifications",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/about/security-encryption-model",
              "seen": "2026-10-08"
            },
            {
              "what": "one-time access token and application sharing",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/about/one-time-token",
              "seen": "2026-10-08"
            },
            {
              "what": "Secrets Manager events",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/about/event-reporting",
              "seen": "2026-10-08"
            },
            {
              "what": "quick start and trial",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/quick-start-guide",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK library and configuration keys",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/developer-sdk-library",
              "seen": "2026-10-08"
            },
            {
              "what": "Python SDK docs",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/developer-sdk-library/python-sdk",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI install and commands",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/secrets-manager-command-line-interface",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP guide (Docker)",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/integrations/model-context-protocol-mcp-for-ai-agents-docker",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP guide (Node), whose repository link returned 404",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/integrations/model-context-protocol-mcp-for-ai-agents-node",
              "seen": "2026-10-08"
            },
            {
              "what": "AI agents page and agent kit",
              "url": "https://docs.keeper.io/keeperpam/secrets-manager/integrations/ai-agents",
              "seen": "2026-10-08"
            },
            {
              "what": "rotation overview (KeeperPAM licence and gateway)",
              "url": "https://docs.keeper.io/keeperpam/privileged-access-manager/password-rotation/rotation-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "2026 release notes",
              "url": "https://docs.keeper.io/release-notes/enterprise/keeper-secrets-manager/2026",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK and CLI repository, tags, workflows, `LICENSE`, Python core `README.md` and `core.py`",
              "url": "https://github.com/Keeper-Security/secrets-manager",
              "seen": "2026-10-08"
            },
            {
              "what": "workflow runs on master",
              "url": "https://api.github.com/repos/Keeper-Security/secrets-manager/actions/runs?branch=master\u0026per_page=30",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues and pull requests",
              "url": "https://api.github.com/repos/Keeper-Security/secrets-manager/issues?state=open\u0026per_page=50",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server source, `internal/mcp/tools.go` and `README.md`",
              "url": "https://github.com/Keeper-Security/keeper-mcp-golang-docker",
              "seen": "2026-10-08"
            },
            {
              "what": "agent kit repository",
              "url": "https://github.com/Keeper-Security/keeper-agent-kit",
              "seen": "2026-10-08"
            },
            {
              "what": "npm package",
              "url": "https://registry.npmjs.org/@keeper-security/secrets-manager-core/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI core package",
              "url": "https://pypi.org/pypi/keeper-secrets-manager-core/json",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI CLI package",
              "url": "https://pypi.org/pypi/keeper-secrets-manager-cli/json",
              "seen": "2026-10-08"
            },
            {
              "what": "product page",
              "url": "https://www.keepersecurity.com/secrets-manager.html",
              "seen": "2026-10-08"
            },
            {
              "what": "business pricing",
              "url": "https://www.keepersecurity.com/pricing/business-and-enterprise.html",
              "seen": "2026-10-08"
            },
            {
              "what": "add-ons pricing",
              "url": "https://www.keepersecurity.com/pricing/business-add-ons/",
              "seen": "2026-10-08"
            },
            {
              "what": "trial page",
              "url": "https://www.keepersecurity.com/trial/keeper-free-trial/",
              "seen": "2026-10-08"
            },
            {
              "what": "SaaS terms, Service Level Objectives and privacy policy",
              "url": "https://www.keepersecurity.com/legal/terms-of-use/",
              "seen": "2026-10-08"
            },
            {
              "what": "DPA",
              "url": "https://www.keepersecurity.com/legal/dpa/",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.keepersecurity.com/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "`security.txt`",
              "url": "https://www.keepersecurity.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents",
              "url": "https://statuspage.keeper.io/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "status components",
              "url": "https://statuspage.keeper.io/api/v2/components.json",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP record",
              "url": "https://rdap.verisign.com/com/v1/domain/keepersecurity.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: base plan prices on the business pricing page, which are drawn by script and were blank to our reader. Secrets Manager's own price is by quote.",
            "unchecked: the sub-processor list, which the DPA places in the trust centre at trust.keeper.io. That page is drawn by script.",
            "unchecked: whether the MCP server is in the official MCP registry, and the Docker Hub page for `keeper/keeper-mcp-server`.",
            "unchecked: the troubleshooting page, so an error reference may exist that we didn't read.",
            "No request limits with numbers were found. The only evidence of throttling is the SDK's retry code and release note.",
            "The Node MCP repository linked from the docs returned 404, so the Node server could not be read. The Go and Docker server was graded instead.",
            "Whether a trial account can keep Secrets Manager after 14 days without a quote.",
            "The category's `secrets.rotate` capability is listed because Keeper sells rotation with Secrets Manager, but it runs through KeeperPAM with a gateway and its own licence."
          ]
        },
        "negative": 0,
        "verdict": "Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.",
        "bestFor": "Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.",
        "strengths": [
          "Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone",
          "Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page",
          "An application sees only the shared folders and records assigned to it, read-only unless shared as editable",
          "Official MIT MCP server with 19 typed tools, masked values by default and confirmation for writes, deletes and unmasking",
          "SDKs for Python, Java, JavaScript, .NET, Go, Ruby and Rust in one MIT repository, with 5 tagged releases since 15 September 2026"
        ],
        "weaknesses": [
          "Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote",
          "No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with `{\"error\":\"throttled\"}`",
          "No OpenAPI or documented raw HTTP use for `/api/rest/sm/v1`. The SDKs are the only supported route",
          "The Node MCP guide links a GitHub repository that returned 404 on 8 October 2026",
          "Rotation needs a KeeperPAM licence and a Keeper Gateway, and access events are read in the separately sold reporting module"
        ],
        "agentNotes": [
          "Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token",
          "Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context",
          "Expect HTTP 403 with `{\"error\":\"throttled\"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits",
          "A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address",
          "Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.4
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 92,
          "payments": 20,
          "reliability": 76,
          "schema": 71,
          "security": 86,
          "transparency": 58
        },
        "provenanceScore": 98
      },
      "connect": {
        "install": "pip3 install keeper-secrets-manager-cli   # or: pip3 install keeper-secrets-manager-core, npm install @keeper-security/secrets-manager-core",
        "http": "ksm profile init XX:XXXX   # one-time access token from the vault\nksm secret list   # values decrypt on the client, so plain curl can't read them",
        "claudeCode": "/plugin marketplace add Keeper-Security/keeper-agent-kit\n/plugin install keeper-secrets@keeper-security",
        "config": {
          "mcpServers": {
            "ksm": {
              "args": [
                "run",
                "-i",
                "--rm",
                "-e",
                "KSM_CONFIG_BASE64=YOUR_BASE64_CONFIG_STRING_HERE",
                "keeper/keeper-mcp-server:latest"
              ],
              "command": "docker"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/keeper-secrets-manager"
      },
      "notable": [
        "A one-time access token is a provisioning credential. The client authenticates with an HMAC-SHA512 hash of it once, registers an ECC secp256r1 public key and signs later requests with the private key (https://docs.keeper.io/keeperpam/secrets-manager/about/security-encryption-model)",
        "Client devices are IP-locked by default and `secrets-manager client add --unlock-ip` turns the lock off. `secrets-manager client revoke --client \u003cid\u003e` cuts off one device (https://docs.keeper.io/keeperpam/secrets-manager/about/security-encryption-model)",
        "The official MCP server runs over stdio from the `keeper/keeper-mcp-server` Docker image with 19 tools. Sensitive fields are masked by default and writes, deletes and unmasking need confirmation (https://github.com/Keeper-Security/keeper-mcp-golang-docker)",
        "The Node MCP guide links https://github.com/Keeper-Security/keeper-mcp-node, which returned 404 on 8 October 2026 (https://docs.keeper.io/keeperpam/secrets-manager/integrations/model-context-protocol-mcp-for-ai-agents-node)",
        "The Keeper Agent Kit installs three skills for Claude Code, Cursor, Codex and GitHub Copilot that drive the `ksm` and `keeper` CLIs (https://docs.keeper.io/keeperpam/secrets-manager/integrations/ai-agents)",
        "The add-ons page lists Secrets Manager at Custom Pricing with Request a Quote, and the product page says it is licensed per user per year (https://www.keepersecurity.com/pricing/business-add-ons/)",
        "The Service Level Objectives state 99.9 per cent monthly availability, with termination as the sole remedy (https://www.keepersecurity.com/legal/terms-of-use/#service-level-objectives)",
        "Every docs page ends with a block headed Agent Instructions, placed by GitBook, that tells AI agents how to query the documentation. We read it as data and did not act on it (https://docs.keeper.io/keeperpam/secrets-manager/about/architecture.md)"
      ],
      "area": "agent-runtime",
      "details": [
        {
          "label": "Interfaces",
          "value": "SDKs for Python, Java and Kotlin, JavaScript, .NET, Go, Ruby and Rust, a PowerShell plugin, the `ksm` CLI (binary or `pip3 install keeper-secrets-manager-cli`), and a stdio MCP server as a Docker image or Go binary"
        },
        {
          "label": "Credentials",
          "value": "One-time access token (region prefix plus 43 characters) redeemed once for a device configuration holding an ECC secp256r1 private key and the AES-256 application key. Requests are ECDSA-signed"
        },
        {
          "label": "Scoping",
          "value": "An application is shared individual records or shared folders, read-only unless `--editable`. Devices are IP-locked by default and can carry an access expiry"
        },
        {
          "label": "MCP server",
          "value": "`keeper/keeper-mcp-server` on Docker Hub, source in Keeper-Security/keeper-mcp-golang-docker, v2.5.0 of 16 July 2026, 19 tools. Confirmation for writes, deletes and unmasking, `--auto-approve` to skip it"
        },
        {
          "label": "Agent kit",
          "value": "Keeper-Security/keeper-agent-kit 1.2.0 (10 June 2026) with three skills, keeper-secrets, keeper-admin and keeper-setup, for Claude Code, Cursor, Codex and GitHub Copilot"
        },
        {
          "label": "Throttling",
          "value": "HTTP 403 with `{\"error\":\"throttled\"}`. The Python SDK retries five times at 11, 22, 44, 88 and 176 seconds with jitter and honours `retry_after`. No published limits found"
        },
        {
          "label": "Offline cache",
          "value": "Optional encrypted local cache in every SDK, read when the Keeper endpoint is unreachable"
        },
        {
          "label": "Audit events",
          "value": "`app_client_connected`, `app_client_access`, `app_client_record_update`, blocked-IP denials and share changes, in the Advanced Reporting and Alerts module, with SIEM export and webhooks"
        },
        {
          "label": "Regions",
          "value": "US, EU, AU, CA, JP and US GovCloud on AWS, fixed per tenant"
        },
        {
          "label": "Service levels",
          "value": "99.9 per cent monthly availability in the Service Level Objectives, recovery time objective 8 hours, remedy limited to termination"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2, ISO 27001, FedRAMP High and StateRAMP High per the docs. Reports on request through trust.keeper.io"
        },
        {
          "label": "Rotation",
          "value": "Through KeeperPAM, which needs its own licence and a Keeper Gateway. SDK record updates accept a rotation transaction type"
        }
      ],
      "provenance": {
        "legalEntity": "Keeper Security, Inc.",
        "domain": "keepersecurity.com",
        "domainRegistered": "2007-04-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.keepersecurity.com/legal/terms-of-use/#saas-terms",
        "privacy": "https://www.keepersecurity.com/legal/terms-of-use/?s=privacy",
        "statusPage": "https://statuspage.keeper.io",
        "changelog": "https://docs.keeper.io/release-notes/enterprise/keeper-secrets-manager/2026",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "Keeper publishes its website terms, SaaS Terms of Use, partner terms, privacy policy and Service Level Objectives as sections of one page at www.keepersecurity.com/legal/terms-of-use/. The SaaS section governs the service and the `?s=privacy` view is the privacy policy. The old `/termsofuse.html` and `/privacypolicy.html` addresses redirect there.",
          "The SaaS terms name Keeper Security, Inc., 311 W. Monroe Street, Suite 406, Chicago, IL 60606, with Keeper Security EMEA Limited and Keeper Security APAC KK for other regions. The page links legacy terms for the period before 9 March 2026.",
          "The SaaS terms forbid a customer to perform penetration or load testing on the services, and the website terms prohibit scraping or automated data collection on the website.",
          "www.keepersecurity.com/.well-known/security.txt answers with a Bugcrowd contact and Expires 2026-12-31T23:59:59Z.",
          "The SDKs call https://\u003cregion host\u003e/api/rest/sm/v1, where the host is keepersecurity.com, keepersecurity.eu, keepersecurity.com.au, keepersecurity.ca, keepersecurity.jp or govcloud.keepersecurity.us.",
          "The status page and the docs sit on keeper.io. statuspage.keeper.io is Atlassian Statuspage with a Keeper Secrets Manager component.",
          "RDAP for keepersecurity.com gives a registration date of 2007-04-12."
        ],
        "score": 98,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Keeper Security, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "keepersecurity.com, registered 2007-04-12 (19 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "keepersecurity.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects",
            "points": 9.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "statuspage.keeper.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.keepersecurity.com/legal/terms-of-use/#saas-terms",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 16617,
            "points": 9.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement is governed by the laws of the State of Delaware, without regard to conflicts of laws principles.",
                "says": "The law of the State of Delaware"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…REGARDLESS OF THE FORM OF THE ACTION (WHETHER IN CONTRACT, TORT, NEGLIGENCE OR OTHERWISE), THE MAXIMUM AGGREGATE LIABILITY OF EACH PARTY TO THE OTHER ARISING IN CONNECTION WITH THIS AGREEMENT SHALL BE LIMITED: (a) TO TWO TIMES THE AMOUNT PAID IN THE TWELVE (12) MONTHS PRIOR TO THE ACCRUAL OF THE APPLICABLE CLAIM IN CO…",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "We may suspend or terminate your access to the Website at any time, without notice, if you violate these Terms or engage in unlawful activity."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "…becomes adjudicated bankrupt, becomes involved in an assignment for the benefit of its creditors, (y) on 10 days written notice where such failure is due to nonpayment of Undisputed fees or (z) on 30 days written notice where the failure continues uncured for such time frame after receipt of written notice.",
                "says": "Gives thirty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You may not use the Website in any way that could harm the Website, interfere with other users or infringe upon the rights of others."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "The Service will be available 99.9% of the time as measured on a monthly basis (\"Uptime Availability\") excluding \"Emergency Maintenance\" (unscheduled maintenance activities that are necessary to address or prevent critical issues affecting the availability, security or functionality of the service) and Force Majeure E…",
                "says": "Names 99.9% availability"
              }
            ],
            "toKnow": [
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "In the event of a breach of any obligations in this section 6 by Customer, Keeper may immediately and without notice suspend or terminate Customer access to the Services."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "…ANY DISPUTE, CONTROVERSY OR CLAIM ARISING OUT OF OR RELATING TO THIS AGREEMENT SHALL BE RESOLVED BY BINDING ARBITRATION ADMINISTERED BY THE AMERICAN ARBITRATION ASSOCIATION (\"AAA\") IN ACCORDANCE WITH ITS COMMERCIAL ARBITRATION RULES THEN IN EFFECT."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Neither party may make Confidential Information received under the agreement available to AI tools, except for internal use in a secure, access-controlled environment with no model training.",
                "quote": "Except as expressly permitted in writing, neither party shall make any Confidential Information received hereunder available to any artificial intelligence tools (including generative AI or large language models)"
              },
              {
                "date": "2026-10-08",
                "text": "Keeper may delete vault records that contain files if a paid subscription expires and is not renewed within 90 days.",
                "quote": "If a paid subscription expires and is not renewed within ninety (90) days, Keeper Security reserves the right to delete any Keeper Records in the account that contain files (such as documents, photos or videos)."
              },
              {
                "date": "2026-10-08",
                "text": "All subscription fees are non-refundable and treated as earned on receipt.",
                "quote": "Since the Software is delivered in full at the time of purchase and we cannot uninstall it from your device(s) all fees are nonrefundable and considered earned on receipt."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.keepersecurity.com/legal/terms-of-use/?s=privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 16617,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy explains how we collect, use and protect personal information when you use our services, visit our website, receive marketing communications or participate in our partner programs."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Keeper will retain information for as long as an account is active or as needed to provide the services."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Unless expressly agreed in writing, all Services furnished to Customer under this Agreement shall be used by Customer only for Customer's internal business purposes, shall not be shared with third parties nor reproduced or copied in whole or in part."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Keeper does not sell or share personal information as those terms are defined under applicable U.S.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "It also describes the choices available to you and how you can exercise your privacy rights."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If the assigned person or your prospect chooses to decline, s/he may contact us at privacy@keepersecurity.com to request that we remove this information from our database.",
                "says": "privacy@keepersecurity.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "To learn more about the Data Privacy Framework (\"DPF\") program and to view our certification, please visithttps://www.dataprivacyframework.gov/",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Keeper may display the company badge or logo of an active business customer on its website.",
                "quote": "For active business customers, Keeper may display your company badge or logo on our website."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager.json",
      "live": {
        "slug": "keeper-secrets-manager",
        "vendorStatus": {
          "page": "https://statuspage.keeper.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:58:00.288548858Z"
        },
        "updatedAt": "2026-10-08T21:58:00.288548858Z"
      }
    },
    "verify": {
      "accepts": "a page on keepersecurity.com or one of its subdomains, or the README of github.com/Keeper-Security/secrets-manager",
      "badgeUrl": "https://www.anchorterminal.com/badges/keeper-secrets-manager.svg",
      "body": {
        "slug": "keeper-secrets-manager",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/keeper-secrets-manager",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/keeper-secrets-manager\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/keeper-secrets-manager.svg\" alt=\"Keeper Secrets Manager on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Keeper Secrets Manager on Anchor Terminal](https://www.anchorterminal.com/badges/keeper-secrets-manager.svg)](https://www.anchorterminal.com/tools/keeper-secrets-manager)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/keeper-secrets-manager\"\u003eKeeper Secrets Manager on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/keeper-secrets-manager",
    "json": "https://www.anchorterminal.com/tools/keeper-secrets-manager.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/keeper-secrets-manager.md",
    "slim": "https://www.anchorterminal.com/tools/keeper-secrets-manager.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 69.4/100 · rank #159 of 722 · #9 in Secrets \u0026 credential vaults · not agent-ready · confidence medium**\n\n\n## Assessment\n\nEach client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Keeper Security, Inc. (https://www.keepersecurity.com/secrets-manager.html) |\n| Kind | HTTP API |\n| Category | Secrets \u0026 credential vaults (https://www.anchorterminal.com/categories/secrets) |\n| Transport | HTTP, stdio |\n| Auth | API key · Access is granted by a person. A vault user whose role allows it creates a Secrets Manager application, shares folders or records with it, and adds a client device, which yields a one-time access token or a Base64 configuration. The client redeems the token once, registers its own ECC public key and signs every later request with the private key, so no bearer secret is reused. Devices are IP-locked by default, can be given an access expiry and are revoked individually. |\n| Pricing | Paid (Paid) · Secrets Manager is an add-on to Keeper's business password manager plans, licensed per user per year, and included with KeeperPAM. The add-ons page shows Custom Pricing and Request a Quote for it, so there is no public figure. A 14-day business trial needs no credit card and can enable Secrets Manager, so an agent's owner can start without a contract. Base plan prices are drawn by script and were blank to our reader (https://www.keepersecurity.com/pricing/business-add-ons/, https://www.keepersecurity.com/trial/keeper-free-trial/, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the Secrets Manager docs, the SDK repository or the pricing pages (checked 2026-10-08). |\n| Licence | Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT |\n| Tools exposed | 19 |\n| Packages | pypi: `keeper-secrets-manager-core`; pypi: `keeper-secrets-manager-cli`; npm: `@keeper-security/secrets-manager-core` |\n| Source | https://github.com/Keeper-Security/secrets-manager |\n| Docs | https://docs.keeper.io/en/keeperpam/secrets-manager/overview |\n| llms.txt | https://docs.keeper.io/llms.txt |\n| Last release | 2026-10-06 |\n| GitHub stars | 117 (as of 2026-10-08) |\n| npm downloads / week | 52,332 |\n| PyPI downloads / week | 45,154 |\n| Interfaces | SDKs for Python, Java and Kotlin, JavaScript, .NET, Go, Ruby and Rust, a PowerShell plugin, the `ksm` CLI (binary or `pip3 install keeper-secrets-manager-cli`), and a stdio MCP server as a Docker image or Go binary |\n| Credentials | One-time access token (region prefix plus 43 characters) redeemed once for a device configuration holding an ECC secp256r1 private key and the AES-256 application key. Requests are ECDSA-signed |\n| Scoping | An application is shared individual records or shared folders, read-only unless `--editable`. Devices are IP-locked by default and can carry an access expiry |\n| MCP server | `keeper/keeper-mcp-server` on Docker Hub, source in Keeper-Security/keeper-mcp-golang-docker, v2.5.0 of 16 July 2026, 19 tools. Confirmation for writes, deletes and unmasking, `--auto-approve` to skip it |\n| Agent kit | Keeper-Security/keeper-agent-kit 1.2.0 (10 June 2026) with three skills, keeper-secrets, keeper-admin and keeper-setup, for Claude Code, Cursor, Codex and GitHub Copilot |\n| Throttling | HTTP 403 with `{\"error\":\"throttled\"}`. The Python SDK retries five times at 11, 22, 44, 88 and 176 seconds with jitter and honours `retry_after`. No published limits found |\n| Offline cache | Optional encrypted local cache in every SDK, read when the Keeper endpoint is unreachable |\n| Audit events | `app_client_connected`, `app_client_access`, `app_client_record_update`, blocked-IP denials and share changes, in the Advanced Reporting and Alerts module, with SIEM export and webhooks |\n| Regions | US, EU, AU, CA, JP and US GovCloud on AWS, fixed per tenant |\n| Service levels | 99.9 per cent monthly availability in the Service Level Objectives, recovery time objective 8 hours, remedy limited to termination |\n| Certifications | SOC 2 Type 2, ISO 27001, FedRAMP High and StateRAMP High per the docs. Reports on request through trust.keeper.io |\n| Rotation | Through KeeperPAM, which needs its own licence and a Keeper Gateway. SDK record updates accept a rotation transaction type |\n| Capabilities | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate |\n| Tags | hosted, enterprise, zero-knowledge, mcp, cli, python, javascript, java, go, dotnet, ruby, rust, llms-txt, sales-led, status-page, bug-bounty, soc2, fedramp |\n| JSON | https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 76 | 15.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 71 | 11.5 |\n| Agent ergonomics | 13% | 16.2 | 63 | 10.2 |\n| Security \u0026 auth | 14% | 17.5 | 86 | 15.1 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 92 | 8.1 |\n| Transparency \u0026 trust (editorial 58, provenance 98) | 7% | 8.8 | 78 | 6.8 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **69.4 → B** |\n\n### Why each score\n\n- Reliability 76: Graded with the hosted lines, because the vault is Keeper's cloud and the SDKs, CLI and MCP server are clients of it. Statuspage at statuspage.keeper.io with a Keeper Secrets Manager component and regional infrastructure components (20). Since 10 July 2026 it lists one minor incident, SMS two-factor messages on 9 September for about three hours, and one notice on EU KeeperPAM connections on 30 July, with nothing posted against Secrets Manager (28 of 30). No request limits with numbers were found in the reviewed documentation (0). The Python SDK retries a throttled call (HTTP 403 with `{\"error\":\"throttled\"}`) five times with backoff from 11 seconds and honours `retry_after`, and every SDK has an optional encrypted local cache for when the endpoint is unreachable, but there are no idempotency keys (10 of 15). The SaaS terms carry Service Level Objectives of 99.9 per cent monthly availability, with termination as the only remedy (8 of 10). Generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 71: No OpenAPI or other published contract for the Secrets Manager endpoint at `/api/rest/sm/v1`. The official MCP server defines JSON Schema inputs on all 19 tools (15 of 25). docs.keeper.io has an `llms.txt` index and serves every page as Markdown (10). The docs explain applications, devices, tokens and Keeper notation well, while MCP tool descriptions are short, such as Get a secret by UID, and don't say when to choose one tool over another (11 of 20). SDKs have typed record and field classes, and MCP inputs mark required fields, with free-form objects for record fields (11 of 15). Each SDK page has worked examples and there's a troubleshooting page, but no error reference was found (9 of 15). Each SDK has its own version tags and dated release notes on docs.keeper.io (15).\n- Agent ergonomics 63: The MCP server has 19 tools, lists metadata only and masks sensitive fields unless asked (17 of 25). Secrets are fetched by UID, by title or by folder, and Keeper notation reads a single field, with no paging (13 of 20). Throttling is an HTTP 403 with a JSON body and the Python SDK raises a typed `KeeperThrottleError`, but no documented list of error codes was found (10 of 20). No idempotency keys, and the MCP tool definitions carry no `readOnlyHint` or `destructiveHint` annotations, though writes go through a confirmation step (8 of 20). SDKs in seven languages, and a client needs only its configuration to start (15).\n- Security \u0026 auth 86: A one-time token bootstraps each device, which then signs every request with its own ECC secp256r1 key. Devices are locked to an IP address by default, can be given an access expiry, and are revoked one at a time with `secrets-manager client revoke`. An application reaches only the shared folders and records assigned to it (27 of 30). Shares are read-only unless made with `--editable`, and the MCP server asks for confirmation before create, update, delete, upload and unmasking, with an `--auto-approve` flag that turns this off (17 of 20). Secrets aren't untrusted content, and the MCP guides warn that data passed to third-party AI tools falls under those tools' practices (10). Device connect, access, record update and blocked-IP events go to the Advanced Reporting and Alerts module, which is sold as a separate add-on, and the MCP server keeps local audit logs (12 of 15). A valid `security.txt` expiring 31 December 2026, a Bugcrowd programme, and SOC 2 Type 2, ISO 27001 and FedRAMP High per the docs (20).\n- Payments \u0026 pricing 20: No x402, MPP or L402 (0). The add-ons page shows Custom Pricing and Request a Quote for Secrets Manager, and the product page says it is licensed per user per year without a figure. Base plan prices are drawn by script and were blank to our reader (0). A 14-day business trial with no credit card, which the quick start says covers Secrets Manager (20). A person signs up, enables a role policy and creates the application and device in the vault or Commander (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 92: Newest tag is the JavaScript GCP KMS storage 1.1.0 on 6 October 2026, two days before this check (30). Five tags since 15 September, among them JavaScript SDK 17.6.0, Java SDK 17.4.0 and CLI 1.5.0 (20). Three open issues, each with a reply, and 21 open pull requests (20 of 25). Seven official SDKs are current, the newest Python core being 17.3.0 from 15 June 2026. The Node MCP repository linked from the docs returned 404, and we didn't check the MCP registry (13 of 15). The 30 most recent workflow runs on master all succeeded, with dependency update runs among them (9 of 10).\n- Transparency \u0026 trust 78: The SDKs, CLI, MCP server and agent kit are MIT on GitHub. The service is closed, under published SaaS terms that replaced the previous terms on 9 March 2026 (20 of 30). A privacy policy and a DPA are published and agree with the zero-knowledge model, where Keeper holds ciphertext. Retention is stated as for as long as an account is active, without periods (20 of 30). No deprecation policy for the SDKs or API was found. The legal pages keep an archive of earlier terms and a change summary (4 of 20). Hosting is on AWS in the US, US GovCloud, EU, Australia, Canada and Japan with the tenant fixed to its region. The DPA points to a sub-processor list in the trust centre, which is drawn by script and was unread (14 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/keeper-secrets-manager.md (JSON https://www.anchorterminal.com/fixes/keeper-secrets-manager.json)\n\n### What we couldn't check\n\n- unchecked: base plan prices on the business pricing page, which are drawn by script and were blank to our reader. Secrets Manager's own price is by quote.\n- unchecked: the sub-processor list, which the DPA places in the trust centre at trust.keeper.io. That page is drawn by script.\n- unchecked: whether the MCP server is in the official MCP registry, and the Docker Hub page for `keeper/keeper-mcp-server`.\n- unchecked: the troubleshooting page, so an error reference may exist that we didn't read.\n- No request limits with numbers were found. The only evidence of throttling is the SDK's retry code and release note.\n- The Node MCP repository linked from the docs returned 404, so the Node server could not be read. The Go and Docker server was graded instead.\n- Whether a trial account can keep Secrets Manager after 14 days without a quote.\n- The category's `secrets.rotate` capability is listed because Keeper sells rotation with Secrets Manager, but it runs through KeeperPAM with a gateway and its own licence.\n\n### Sources\n\n- Secrets Manager overview: \u003chttps://docs.keeper.io/en/keeperpam/secrets-manager/overview\u003e (seen 2026-10-08)\n- docs index (`llms.txt`): \u003chttps://docs.keeper.io/llms.txt\u003e (seen 2026-10-08)\n- architecture and local cache: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/about/architecture\u003e (seen 2026-10-08)\n- security and encryption model, IP lock, revocation, certifications: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/about/security-encryption-model\u003e (seen 2026-10-08)\n- one-time access token and application sharing: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/about/one-time-token\u003e (seen 2026-10-08)\n- Secrets Manager events: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/about/event-reporting\u003e (seen 2026-10-08)\n- quick start and trial: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/quick-start-guide\u003e (seen 2026-10-08)\n- SDK library and configuration keys: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/developer-sdk-library\u003e (seen 2026-10-08)\n- Python SDK docs: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/developer-sdk-library/python-sdk\u003e (seen 2026-10-08)\n- CLI install and commands: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/secrets-manager-command-line-interface\u003e (seen 2026-10-08)\n- MCP guide (Docker): \u003chttps://docs.keeper.io/keeperpam/secrets-manager/integrations/model-context-protocol-mcp-for-ai-agents-docker\u003e (seen 2026-10-08)\n- MCP guide (Node), whose repository link returned 404: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/integrations/model-context-protocol-mcp-for-ai-agents-node\u003e (seen 2026-10-08)\n- AI agents page and agent kit: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/integrations/ai-agents\u003e (seen 2026-10-08)\n- rotation overview (KeeperPAM licence and gateway): \u003chttps://docs.keeper.io/keeperpam/privileged-access-manager/password-rotation/rotation-overview\u003e (seen 2026-10-08)\n- 2026 release notes: \u003chttps://docs.keeper.io/release-notes/enterprise/keeper-secrets-manager/2026\u003e (seen 2026-10-08)\n- SDK and CLI repository, tags, workflows, `LICENSE`, Python core `README.md` and `core.py`: \u003chttps://github.com/Keeper-Security/secrets-manager\u003e (seen 2026-10-08)\n- workflow runs on master: \u003chttps://api.github.com/repos/Keeper-Security/secrets-manager/actions/runs?branch=master\u0026per_page=30\u003e (seen 2026-10-08)\n- open issues and pull requests: \u003chttps://api.github.com/repos/Keeper-Security/secrets-manager/issues?state=open\u0026per_page=50\u003e (seen 2026-10-08)\n- MCP server source, `internal/mcp/tools.go` and `README.md`: \u003chttps://github.com/Keeper-Security/keeper-mcp-golang-docker\u003e (seen 2026-10-08)\n- agent kit repository: \u003chttps://github.com/Keeper-Security/keeper-agent-kit\u003e (seen 2026-10-08)\n- npm package: \u003chttps://registry.npmjs.org/@keeper-security/secrets-manager-core/latest\u003e (seen 2026-10-08)\n- PyPI core package: \u003chttps://pypi.org/pypi/keeper-secrets-manager-core/json\u003e (seen 2026-10-08)\n- PyPI CLI package: \u003chttps://pypi.org/pypi/keeper-secrets-manager-cli/json\u003e (seen 2026-10-08)\n- product page: \u003chttps://www.keepersecurity.com/secrets-manager.html\u003e (seen 2026-10-08)\n- business pricing: \u003chttps://www.keepersecurity.com/pricing/business-and-enterprise.html\u003e (seen 2026-10-08)\n- add-ons pricing: \u003chttps://www.keepersecurity.com/pricing/business-add-ons/\u003e (seen 2026-10-08)\n- trial page: \u003chttps://www.keepersecurity.com/trial/keeper-free-trial/\u003e (seen 2026-10-08)\n- SaaS terms, Service Level Objectives and privacy policy: \u003chttps://www.keepersecurity.com/legal/terms-of-use/\u003e (seen 2026-10-08)\n- DPA: \u003chttps://www.keepersecurity.com/legal/dpa/\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.keepersecurity.com/security/\u003e (seen 2026-10-08)\n- `security.txt`: \u003chttps://www.keepersecurity.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- status incidents: \u003chttps://statuspage.keeper.io/api/v2/incidents.json\u003e (seen 2026-10-08)\n- status components: \u003chttps://statuspage.keeper.io/api/v2/components.json\u003e (seen 2026-10-08)\n- RDAP record: \u003chttps://rdap.verisign.com/com/v1/domain/keepersecurity.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 98/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Keeper Security, Inc. | 20/20 |\n| Domain age | keepersecurity.com, registered 2007-04-12 (19 years) | 15/15 |\n| Endpoint on the vendor's domain | keepersecurity.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects | 9.1/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | statuspage.keeper.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nKeeper publishes its website terms, SaaS Terms of Use, partner terms, privacy policy and Service Level Objectives as sections of one page at www.keepersecurity.com/legal/terms-of-use/. The SaaS section governs the service and the `?s=privacy` view is the privacy policy. The old `/termsofuse.html` and `/privacypolicy.html` addresses redirect there.\n\nThe SaaS terms name Keeper Security, Inc., 311 W. Monroe Street, Suite 406, Chicago, IL 60606, with Keeper Security EMEA Limited and Keeper Security APAC KK for other regions. The page links legacy terms for the period before 9 March 2026.\n\nThe SaaS terms forbid a customer to perform penetration or load testing on the services, and the website terms prohibit scraping or automated data collection on the website.\n\nwww.keepersecurity.com/.well-known/security.txt answers with a Bugcrowd contact and Expires 2026-12-31T23:59:59Z.\n\nThe SDKs call https://\u003cregion host\u003e/api/rest/sm/v1, where the host is keepersecurity.com, keepersecurity.eu, keepersecurity.com.au, keepersecurity.ca, keepersecurity.jp or govcloud.keepersecurity.us.\n\nThe status page and the docs sit on keeper.io. statuspage.keeper.io is Atlassian Statuspage with a Keeper Secrets Manager component.\n\nRDAP for keepersecurity.com gives a registration date of 2007-04-12.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.keepersecurity.com/legal/terms-of-use/#saas-terms), read 2026-10-08, gives no date, states 6 of the 7 things a reader expects.\n\n- To know. Says access can be ended without notice or for any reason. \"In the event of a breach of any obligations in this section 6 by Customer, Keeper may immediately and without notice suspend or terminate Customer access to the Services.\"\n- To know. Requires arbitration or waives class actions. \"…ANY DISPUTE, CONTROVERSY OR CLAIM ARISING OUT OF OR RELATING TO THIS AGREEMENT SHALL BE RESOLVED BY BINDING ARBITRATION ADMINISTERED BY THE AMERICAN ARBITRATION ASSOCIATION (\"AAA\") IN ACCORDANCE WITH ITS COMMERCIAL ARBITRATION RULES THEN IN EFFECT.\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of Delaware.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Gives thirty days of notice before a change.\n- Refers to a service level or uptime commitment. Names 99.9% availability.\n- Also in the text (2026-10-08). Neither party may make Confidential Information received under the agreement available to AI tools, except for internal use in a secure, access-controlled environment with no model training. \"Except as expressly permitted in writing, neither party shall make any Confidential Information received hereunder available to any artificial intelligence tools (including generative AI or large language models)\"\n- Also in the text (2026-10-08). Keeper may delete vault records that contain files if a paid subscription expires and is not renewed within 90 days. \"If a paid subscription expires and is not renewed within ninety (90) days, Keeper Security reserves the right to delete any Keeper Records in the account that contain files (such as documents, photos or videos).\"\n- Also in the text (2026-10-08). All subscription fees are non-refundable and treated as earned on receipt. \"Since the Software is delivered in full at the time of purchase and we cannot uninstall it from your device(s) all fees are nonrefundable and considered earned on receipt.\"\n\n**Privacy policy** (https://www.keepersecurity.com/legal/terms-of-use/?s=privacy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@keepersecurity.com.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). Keeper may display the company badge or logo of an active business customer on its website. \"For active business customers, Keeper may display your company badge or logo on our website.\"\n\n## Live (updated 2026-10-08 21:58 UTC)\n\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/keeper-secrets-manager.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone\n- Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page\n- An application sees only the shared folders and records assigned to it, read-only unless shared as editable\n- Official MIT MCP server with 19 typed tools, masked values by default and confirmation for writes, deletes and unmasking\n- SDKs for Python, Java, JavaScript, .NET, Go, Ruby and Rust in one MIT repository, with 5 tagged releases since 15 September 2026\n\n## Weaknesses\n\n- Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote\n- No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with `{\"error\":\"throttled\"}`\n- No OpenAPI or documented raw HTTP use for `/api/rest/sm/v1`. The SDKs are the only supported route\n- The Node MCP guide links a GitHub repository that returned 404 on 8 October 2026\n- Rotation needs a KeeperPAM licence and a Keeper Gateway, and access events are read in the separately sold reporting module\n\n## Before you call it (notes for agents)\n\n1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token\n2. Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context\n3. Expect HTTP 403 with `{\"error\":\"throttled\"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits\n4. A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address\n5. Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values\n\n## Connect\n\nInstall:\n\n```bash\npip3 install keeper-secrets-manager-cli   # or: pip3 install keeper-secrets-manager-core, npm install @keeper-security/secrets-manager-core\n```\n\nFirst request:\n\n```bash\nksm profile init XX:XXXX   # one-time access token from the vault\nksm secret list   # values decrypt on the client, so plain curl can't read them\n```\n\nClaude Code:\n\n```bash\n/plugin marketplace add Keeper-Security/keeper-agent-kit\n/plugin install keeper-secrets@keeper-security\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"ksm\": {\n      \"args\": [\n        \"run\",\n        \"-i\",\n        \"--rm\",\n        \"-e\",\n        \"KSM_CONFIG_BASE64=YOUR_BASE64_CONFIG_STRING_HERE\",\n        \"keeper/keeper-mcp-server:latest\"\n      ],\n      \"command\": \"docker\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/keeper-secrets-manager. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Infisical | A | 83.7 | 2 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/infisical.md |\n| AWS Secrets Manager | BB | 77.7 | 18 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/aws-secrets-manager.md |\n| Google Cloud Secret Manager | BB | 76.5 | 28 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/google-secret-manager.md |\n| Azure Key Vault | BB | 74.7 | 60 | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate | no | https://www.anchorterminal.com/tools/azure-key-vault.md |\n| Akeyless (SecretlessAI and MCP server) | BB | 73.6 | 74 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/akeyless.md |\n| Doppler | BB | 71.4 | 110 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/doppler.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- A one-time access token is a provisioning credential. The client authenticates with an HMAC-SHA512 hash of it once, registers an ECC secp256r1 public key and signs later requests with the private key (source: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/about/security-encryption-model\u003e)\n- Client devices are IP-locked by default and `secrets-manager client add --unlock-ip` turns the lock off. `secrets-manager client revoke --client \u003cid\u003e` cuts off one device (source: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/about/security-encryption-model\u003e)\n- The official MCP server runs over stdio from the `keeper/keeper-mcp-server` Docker image with 19 tools. Sensitive fields are masked by default and writes, deletes and unmasking need confirmation (source: \u003chttps://github.com/Keeper-Security/keeper-mcp-golang-docker\u003e)\n- The Node MCP guide links https://github.com/Keeper-Security/keeper-mcp-node, which returned 404 on 8 October 2026 (source: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/integrations/model-context-protocol-mcp-for-ai-agents-node\u003e)\n- The Keeper Agent Kit installs three skills for Claude Code, Cursor, Codex and GitHub Copilot that drive the `ksm` and `keeper` CLIs (source: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/integrations/ai-agents\u003e)\n- The add-ons page lists Secrets Manager at Custom Pricing with Request a Quote, and the product page says it is licensed per user per year (source: \u003chttps://www.keepersecurity.com/pricing/business-add-ons/\u003e)\n- The Service Level Objectives state 99.9 per cent monthly availability, with termination as the sole remedy (source: \u003chttps://www.keepersecurity.com/legal/terms-of-use/#service-level-objectives\u003e)\n- Every docs page ends with a block headed Agent Instructions, placed by GitBook, that tells AI agents how to query the documentation. We read it as data and did not act on it (source: \u003chttps://docs.keeper.io/keeperpam/secrets-manager/about/architecture.md\u003e)\n\n## Compare\n\n- [1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager.md): B 69.7 vs B 69.4\n- [Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.md): BB 73.6 vs B 69.4\n- [AWS Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager.md): BB 77.7 vs B 69.4\n- [Azure Key Vault vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager.md): BB 74.7 vs B 69.4\n- [Bitwarden Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager.md): C 56.8 vs B 69.4\n- [Doppler vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager.md): BB 71.4 vs B 69.4\n- [Google Cloud Secret Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.md): BB 76.5 vs B 69.4\n- [HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.md): B 64.2 vs B 69.4\n- [Infisical vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager.md): A 83.7 vs B 69.4\n- [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md): B 69.4 vs B 68\n- [Keeper Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.md): B 69.4 vs BB 71.1\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on keepersecurity.com or one of its subdomains, or the README of github.com/Keeper-Security/secrets-manager. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"keeper-secrets-manager\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/keeper-secrets-manager\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/keeper-secrets-manager.svg\" alt=\"Keeper Secrets Manager on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Keeper Secrets Manager on Anchor Terminal](https://www.anchorterminal.com/badges/keeper-secrets-manager.svg)](https://www.anchorterminal.com/tools/keeper-secrets-manager)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/keeper-secrets-manager\"\u003eKeeper Secrets Manager on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Keeper Secrets Manager is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/keeper-secrets-manager-dark.png\n- Light: https://www.anchorterminal.com/assets/share/keeper-secrets-manager-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Secrets \u0026 credential vaults",
        "url": "https://www.anchorterminal.com/categories/secrets"
      },
      {
        "name": "Keeper Secrets Manager",
        "url": ""
      }
    ],
    "description": "Keeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the ksm CLI or a local MCP server, decrypting on the client.",
    "facts": [
      "rank #159 of 722",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Keeper Secrets Manager",
    "image": "https://www.anchorterminal.com/assets/og/tools-keeper-secrets-manager.png",
    "path": "/tools/keeper-secrets-manager",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Keeper Secrets Manager review for AI agents, grade B (69.4/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/keeper-secrets-manager"
  },
  "tokens": {
    "markdown": 8350,
    "slim": 1880
  },
  "version": 1
}
