# Keeper Secrets Manager > Keeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the ksm CLI or a local MCP server, decrypting on the client. - Canonical: https://www.anchorterminal.com/tools/keeper-secrets-manager - Markdown: https://www.anchorterminal.com/tools/keeper-secrets-manager.md (~8,350 tokens) - Slim: https://www.anchorterminal.com/tools/keeper-secrets-manager.min.md (~1,880 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/keeper-secrets-manager.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 69.4/100 · rank #159 of 722 · #9 in Secrets & credential vaults · not agent-ready · confidence medium** ## Assessment Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault. ## Facts | Field | Value | | --- | --- | | Vendor | Keeper Security, Inc. (https://www.keepersecurity.com/secrets-manager.html) | | Kind | HTTP API | | Category | Secrets & credential vaults (https://www.anchorterminal.com/categories/secrets) | | Transport | HTTP, stdio | | Auth | API key · Access is granted by a person. A vault user whose role allows it creates a Secrets Manager application, shares folders or records with it, and adds a client device, which yields a one-time access token or a Base64 configuration. The client redeems the token once, registers its own ECC public key and signs every later request with the private key, so no bearer secret is reused. Devices are IP-locked by default, can be given an access expiry and are revoked individually. | | Pricing | Paid (Paid) · Secrets Manager is an add-on to Keeper's business password manager plans, licensed per user per year, and included with KeeperPAM. The add-ons page shows Custom Pricing and Request a Quote for it, so there is no public figure. A 14-day business trial needs no credit card and can enable Secrets Manager, so an agent's owner can start without a contract. Base plan prices are drawn by script and were blank to our reader (https://www.keepersecurity.com/pricing/business-add-ons/, https://www.keepersecurity.com/trial/keeper-free-trial/, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the Secrets Manager docs, the SDK repository or the pricing pages (checked 2026-10-08). | | Licence | Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT | | Tools exposed | 19 | | Packages | pypi: `keeper-secrets-manager-core`; pypi: `keeper-secrets-manager-cli`; npm: `@keeper-security/secrets-manager-core` | | Source | https://github.com/Keeper-Security/secrets-manager | | Docs | https://docs.keeper.io/en/keeperpam/secrets-manager/overview | | llms.txt | https://docs.keeper.io/llms.txt | | Last release | 2026-10-06 | | GitHub stars | 117 (as of 2026-10-08) | | npm downloads / week | 52,332 | | PyPI downloads / week | 45,154 | | Interfaces | SDKs for Python, Java and Kotlin, JavaScript, .NET, Go, Ruby and Rust, a PowerShell plugin, the `ksm` CLI (binary or `pip3 install keeper-secrets-manager-cli`), and a stdio MCP server as a Docker image or Go binary | | Credentials | One-time access token (region prefix plus 43 characters) redeemed once for a device configuration holding an ECC secp256r1 private key and the AES-256 application key. Requests are ECDSA-signed | | Scoping | An application is shared individual records or shared folders, read-only unless `--editable`. Devices are IP-locked by default and can carry an access expiry | | MCP server | `keeper/keeper-mcp-server` on Docker Hub, source in Keeper-Security/keeper-mcp-golang-docker, v2.5.0 of 16 July 2026, 19 tools. Confirmation for writes, deletes and unmasking, `--auto-approve` to skip it | | Agent kit | Keeper-Security/keeper-agent-kit 1.2.0 (10 June 2026) with three skills, keeper-secrets, keeper-admin and keeper-setup, for Claude Code, Cursor, Codex and GitHub Copilot | | Throttling | HTTP 403 with `{"error":"throttled"}`. The Python SDK retries five times at 11, 22, 44, 88 and 176 seconds with jitter and honours `retry_after`. No published limits found | | Offline cache | Optional encrypted local cache in every SDK, read when the Keeper endpoint is unreachable | | Audit events | `app_client_connected`, `app_client_access`, `app_client_record_update`, blocked-IP denials and share changes, in the Advanced Reporting and Alerts module, with SIEM export and webhooks | | Regions | US, EU, AU, CA, JP and US GovCloud on AWS, fixed per tenant | | Service levels | 99.9 per cent monthly availability in the Service Level Objectives, recovery time objective 8 hours, remedy limited to termination | | Certifications | SOC 2 Type 2, ISO 27001, FedRAMP High and StateRAMP High per the docs. Reports on request through trust.keeper.io | | Rotation | Through KeeperPAM, which needs its own licence and a Keeper Gateway. SDK record updates accept a rotation transaction type | | Capabilities | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate | | Tags | hosted, enterprise, zero-knowledge, mcp, cli, python, javascript, java, go, dotnet, ruby, rust, llms-txt, sales-led, status-page, bug-bounty, soc2, fedramp | | JSON | https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 76 | 15.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 71 | 11.5 | | Agent ergonomics | 13% | 16.2 | 63 | 10.2 | | Security & auth | 14% | 17.5 | 86 | 15.1 | | Payments & pricing | 10% | 12.5 | 20 | 2.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 92 | 8.1 | | Transparency & trust (editorial 58, provenance 98) | 7% | 8.8 | 78 | 6.8 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **69.4 → B** | ### Why each score - Reliability 76: Graded with the hosted lines, because the vault is Keeper's cloud and the SDKs, CLI and MCP server are clients of it. Statuspage at statuspage.keeper.io with a Keeper Secrets Manager component and regional infrastructure components (20). Since 10 July 2026 it lists one minor incident, SMS two-factor messages on 9 September for about three hours, and one notice on EU KeeperPAM connections on 30 July, with nothing posted against Secrets Manager (28 of 30). No request limits with numbers were found in the reviewed documentation (0). The Python SDK retries a throttled call (HTTP 403 with `{"error":"throttled"}`) five times with backoff from 11 seconds and honours `retry_after`, and every SDK has an optional encrypted local cache for when the endpoint is unreachable, but there are no idempotency keys (10 of 15). The SaaS terms carry Service Level Objectives of 99.9 per cent monthly availability, with termination as the only remedy (8 of 10). Generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 71: No OpenAPI or other published contract for the Secrets Manager endpoint at `/api/rest/sm/v1`. The official MCP server defines JSON Schema inputs on all 19 tools (15 of 25). docs.keeper.io has an `llms.txt` index and serves every page as Markdown (10). The docs explain applications, devices, tokens and Keeper notation well, while MCP tool descriptions are short, such as Get a secret by UID, and don't say when to choose one tool over another (11 of 20). SDKs have typed record and field classes, and MCP inputs mark required fields, with free-form objects for record fields (11 of 15). Each SDK page has worked examples and there's a troubleshooting page, but no error reference was found (9 of 15). Each SDK has its own version tags and dated release notes on docs.keeper.io (15). - Agent ergonomics 63: The MCP server has 19 tools, lists metadata only and masks sensitive fields unless asked (17 of 25). Secrets are fetched by UID, by title or by folder, and Keeper notation reads a single field, with no paging (13 of 20). Throttling is an HTTP 403 with a JSON body and the Python SDK raises a typed `KeeperThrottleError`, but no documented list of error codes was found (10 of 20). No idempotency keys, and the MCP tool definitions carry no `readOnlyHint` or `destructiveHint` annotations, though writes go through a confirmation step (8 of 20). SDKs in seven languages, and a client needs only its configuration to start (15). - Security & auth 86: A one-time token bootstraps each device, which then signs every request with its own ECC secp256r1 key. Devices are locked to an IP address by default, can be given an access expiry, and are revoked one at a time with `secrets-manager client revoke`. An application reaches only the shared folders and records assigned to it (27 of 30). Shares are read-only unless made with `--editable`, and the MCP server asks for confirmation before create, update, delete, upload and unmasking, with an `--auto-approve` flag that turns this off (17 of 20). Secrets aren't untrusted content, and the MCP guides warn that data passed to third-party AI tools falls under those tools' practices (10). Device connect, access, record update and blocked-IP events go to the Advanced Reporting and Alerts module, which is sold as a separate add-on, and the MCP server keeps local audit logs (12 of 15). A valid `security.txt` expiring 31 December 2026, a Bugcrowd programme, and SOC 2 Type 2, ISO 27001 and FedRAMP High per the docs (20). - Payments & pricing 20: No x402, MPP or L402 (0). The add-ons page shows Custom Pricing and Request a Quote for Secrets Manager, and the product page says it is licensed per user per year without a figure. Base plan prices are drawn by script and were blank to our reader (0). A 14-day business trial with no credit card, which the quick start says covers Secrets Manager (20). A person signs up, enables a role policy and creates the application and device in the vault or Commander (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 92: Newest tag is the JavaScript GCP KMS storage 1.1.0 on 6 October 2026, two days before this check (30). Five tags since 15 September, among them JavaScript SDK 17.6.0, Java SDK 17.4.0 and CLI 1.5.0 (20). Three open issues, each with a reply, and 21 open pull requests (20 of 25). Seven official SDKs are current, the newest Python core being 17.3.0 from 15 June 2026. The Node MCP repository linked from the docs returned 404, and we didn't check the MCP registry (13 of 15). The 30 most recent workflow runs on master all succeeded, with dependency update runs among them (9 of 10). - Transparency & trust 78: The SDKs, CLI, MCP server and agent kit are MIT on GitHub. The service is closed, under published SaaS terms that replaced the previous terms on 9 March 2026 (20 of 30). A privacy policy and a DPA are published and agree with the zero-knowledge model, where Keeper holds ciphertext. Retention is stated as for as long as an account is active, without periods (20 of 30). No deprecation policy for the SDKs or API was found. The legal pages keep an archive of earlier terms and a change summary (4 of 20). Hosting is on AWS in the US, US GovCloud, EU, Australia, Canada and Japan with the tenant fixed to its region. The DPA points to a sub-processor list in the trust centre, which is drawn by script and was unread (14 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/keeper-secrets-manager.md (JSON https://www.anchorterminal.com/fixes/keeper-secrets-manager.json) ### What we couldn't check - unchecked: base plan prices on the business pricing page, which are drawn by script and were blank to our reader. Secrets Manager's own price is by quote. - unchecked: the sub-processor list, which the DPA places in the trust centre at trust.keeper.io. That page is drawn by script. - unchecked: whether the MCP server is in the official MCP registry, and the Docker Hub page for `keeper/keeper-mcp-server`. - unchecked: the troubleshooting page, so an error reference may exist that we didn't read. - No request limits with numbers were found. The only evidence of throttling is the SDK's retry code and release note. - The Node MCP repository linked from the docs returned 404, so the Node server could not be read. The Go and Docker server was graded instead. - Whether a trial account can keep Secrets Manager after 14 days without a quote. - The category's `secrets.rotate` capability is listed because Keeper sells rotation with Secrets Manager, but it runs through KeeperPAM with a gateway and its own licence. ### Sources - Secrets Manager overview: (seen 2026-10-08) - docs index (`llms.txt`): (seen 2026-10-08) - architecture and local cache: (seen 2026-10-08) - security and encryption model, IP lock, revocation, certifications: (seen 2026-10-08) - one-time access token and application sharing: (seen 2026-10-08) - Secrets Manager events: (seen 2026-10-08) - quick start and trial: (seen 2026-10-08) - SDK library and configuration keys: (seen 2026-10-08) - Python SDK docs: (seen 2026-10-08) - CLI install and commands: (seen 2026-10-08) - MCP guide (Docker): (seen 2026-10-08) - MCP guide (Node), whose repository link returned 404: (seen 2026-10-08) - AI agents page and agent kit: (seen 2026-10-08) - rotation overview (KeeperPAM licence and gateway): (seen 2026-10-08) - 2026 release notes: (seen 2026-10-08) - SDK and CLI repository, tags, workflows, `LICENSE`, Python core `README.md` and `core.py`: (seen 2026-10-08) - workflow runs on master: (seen 2026-10-08) - open issues and pull requests: (seen 2026-10-08) - MCP server source, `internal/mcp/tools.go` and `README.md`: (seen 2026-10-08) - agent kit repository: (seen 2026-10-08) - npm package: (seen 2026-10-08) - PyPI core package: (seen 2026-10-08) - PyPI CLI package: (seen 2026-10-08) - product page: (seen 2026-10-08) - business pricing: (seen 2026-10-08) - add-ons pricing: (seen 2026-10-08) - trial page: (seen 2026-10-08) - SaaS terms, Service Level Objectives and privacy policy: (seen 2026-10-08) - DPA: (seen 2026-10-08) - security page: (seen 2026-10-08) - `security.txt`: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - status components: (seen 2026-10-08) - RDAP record: (seen 2026-10-08) ## Who's behind it (provenance 98/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Keeper Security, Inc. | 20/20 | | Domain age | keepersecurity.com, registered 2007-04-12 (19 years) | 15/15 | | Endpoint on the vendor's domain | keepersecurity.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects | 9.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | statuspage.keeper.io | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | Keeper publishes its website terms, SaaS Terms of Use, partner terms, privacy policy and Service Level Objectives as sections of one page at www.keepersecurity.com/legal/terms-of-use/. The SaaS section governs the service and the `?s=privacy` view is the privacy policy. The old `/termsofuse.html` and `/privacypolicy.html` addresses redirect there. The SaaS terms name Keeper Security, Inc., 311 W. Monroe Street, Suite 406, Chicago, IL 60606, with Keeper Security EMEA Limited and Keeper Security APAC KK for other regions. The page links legacy terms for the period before 9 March 2026. The SaaS terms forbid a customer to perform penetration or load testing on the services, and the website terms prohibit scraping or automated data collection on the website. www.keepersecurity.com/.well-known/security.txt answers with a Bugcrowd contact and Expires 2026-12-31T23:59:59Z. The SDKs call https:///api/rest/sm/v1, where the host is keepersecurity.com, keepersecurity.eu, keepersecurity.com.au, keepersecurity.ca, keepersecurity.jp or govcloud.keepersecurity.us. The status page and the docs sit on keeper.io. statuspage.keeper.io is Atlassian Statuspage with a Keeper Secrets Manager component. RDAP for keepersecurity.com gives a registration date of 2007-04-12. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.keepersecurity.com/legal/terms-of-use/#saas-terms), read 2026-10-08, gives no date, states 6 of the 7 things a reader expects. - To know. Says access can be ended without notice or for any reason. "In the event of a breach of any obligations in this section 6 by Customer, Keeper may immediately and without notice suspend or terminate Customer access to the Services." - To know. Requires arbitration or waives class actions. "…ANY DISPUTE, CONTROVERSY OR CLAIM ARISING OUT OF OR RELATING TO THIS AGREEMENT SHALL BE RESOLVED BY BINDING ARBITRATION ADMINISTERED BY THE AMERICAN ARBITRATION ASSOCIATION ("AAA") IN ACCORDANCE WITH ITS COMMERCIAL ARBITRATION RULES THEN IN EFFECT." - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of the State of Delaware. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Says how changes to the terms are announced. Gives thirty days of notice before a change. - Refers to a service level or uptime commitment. Names 99.9% availability. - Also in the text (2026-10-08). Neither party may make Confidential Information received under the agreement available to AI tools, except for internal use in a secure, access-controlled environment with no model training. "Except as expressly permitted in writing, neither party shall make any Confidential Information received hereunder available to any artificial intelligence tools (including generative AI or large language models)" - Also in the text (2026-10-08). Keeper may delete vault records that contain files if a paid subscription expires and is not renewed within 90 days. "If a paid subscription expires and is not renewed within ninety (90) days, Keeper Security reserves the right to delete any Keeper Records in the account that contain files (such as documents, photos or videos)." - Also in the text (2026-10-08). All subscription fees are non-refundable and treated as earned on receipt. "Since the Software is delivered in full at the time of purchase and we cannot uninstall it from your device(s) all fees are nonrefundable and considered earned on receipt." **Privacy policy** (https://www.keepersecurity.com/legal/terms-of-use/?s=privacy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - Not found in the text. Gives the date it was last updated. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@keepersecurity.com. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). Keeper may display the company badge or logo of an active business customer on its website. "For active business customers, Keeper may display your company badge or logo on our website." ## Live (updated 2026-10-08 21:58 UTC) - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/keeper-secrets-manager.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Each device registers its own ECC key from a one-time token, is IP-locked by default and can be revoked alone - Secrets decrypt on the client. Keeper's cloud stores and sends ciphertext only, per the encryption model page - An application sees only the shared folders and records assigned to it, read-only unless shared as editable - Official MIT MCP server with 19 typed tools, masked values by default and confirmation for writes, deletes and unmasking - SDKs for Python, Java, JavaScript, .NET, Go, Ruby and Rust in one MIT repository, with 5 tagged releases since 15 September 2026 ## Weaknesses - Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote - No request limits were found in the reviewed documentation. Throttling arrives as HTTP 403 with `{"error":"throttled"}` - No OpenAPI or documented raw HTTP use for `/api/rest/sm/v1`. The SDKs are the only supported route - The Node MCP guide links a GitHub repository that returned 404 on 8 October 2026 - Rotation needs a KeeperPAM licence and a Keeper Gateway, and access events are read in the separately sold reporting module ## Before you call it (notes for agents) 1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token 2. Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context 3. Expect HTTP 403 with `{"error":"throttled"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits 4. A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address 5. Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values ## Connect Install: ```bash pip3 install keeper-secrets-manager-cli # or: pip3 install keeper-secrets-manager-core, npm install @keeper-security/secrets-manager-core ``` First request: ```bash ksm profile init XX:XXXX # one-time access token from the vault ksm secret list # values decrypt on the client, so plain curl can't read them ``` Claude Code: ```bash /plugin marketplace add Keeper-Security/keeper-agent-kit /plugin install keeper-secrets@keeper-security ``` MCP client configuration: ```json { "mcpServers": { "ksm": { "args": [ "run", "-i", "--rm", "-e", "KSM_CONFIG_BASE64=YOUR_BASE64_CONFIG_STRING_HERE", "keeper/keeper-mcp-server:latest" ], "command": "docker" } } } ``` Through letme (picks today, calling later): https://letme.dev/keeper-secrets-manager. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Infisical | A | 83.7 | 2 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/infisical.md | | AWS Secrets Manager | BB | 77.7 | 18 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/aws-secrets-manager.md | | Google Cloud Secret Manager | BB | 76.5 | 28 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/google-secret-manager.md | | Azure Key Vault | BB | 74.7 | 60 | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate | no | https://www.anchorterminal.com/tools/azure-key-vault.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.6 | 74 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/akeyless.md | | Doppler | BB | 71.4 | 110 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | no | https://www.anchorterminal.com/tools/doppler.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - A one-time access token is a provisioning credential. The client authenticates with an HMAC-SHA512 hash of it once, registers an ECC secp256r1 public key and signs later requests with the private key (source: ) - Client devices are IP-locked by default and `secrets-manager client add --unlock-ip` turns the lock off. `secrets-manager client revoke --client ` cuts off one device (source: ) - The official MCP server runs over stdio from the `keeper/keeper-mcp-server` Docker image with 19 tools. Sensitive fields are masked by default and writes, deletes and unmasking need confirmation (source: ) - The Node MCP guide links https://github.com/Keeper-Security/keeper-mcp-node, which returned 404 on 8 October 2026 (source: ) - The Keeper Agent Kit installs three skills for Claude Code, Cursor, Codex and GitHub Copilot that drive the `ksm` and `keeper` CLIs (source: ) - The add-ons page lists Secrets Manager at Custom Pricing with Request a Quote, and the product page says it is licensed per user per year (source: ) - The Service Level Objectives state 99.9 per cent monthly availability, with termination as the sole remedy (source: ) - Every docs page ends with a block headed Agent Instructions, placed by GitBook, that tells AI agents how to query the documentation. We read it as data and did not act on it (source: ) ## Compare - [1Password service accounts, SDKs and Environments MCP vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/1password-vs-keeper-secrets-manager.md): B 69.7 vs B 69.4 - [Akeyless (SecretlessAI and MCP server) vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/akeyless-vs-keeper-secrets-manager.md): BB 73.6 vs B 69.4 - [AWS Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-keeper-secrets-manager.md): BB 77.7 vs B 69.4 - [Azure Key Vault vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/azure-key-vault-vs-keeper-secrets-manager.md): BB 74.7 vs B 69.4 - [Bitwarden Secrets Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-keeper-secrets-manager.md): C 56.8 vs B 69.4 - [Doppler vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager.md): BB 71.4 vs B 69.4 - [Google Cloud Secret Manager vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/google-secret-manager-vs-keeper-secrets-manager.md): BB 76.5 vs B 69.4 - [HashiCorp Vault + Vault MCP Server vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/hashicorp-vault-vs-keeper-secrets-manager.md): B 64.2 vs B 69.4 - [Infisical vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/infisical-vs-keeper-secrets-manager.md): A 83.7 vs B 69.4 - [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md): B 69.4 vs B 68 - [Keeper Secrets Manager vs Pulumi ESC](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-pulumi-esc.md): B 69.4 vs BB 71.1 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on keepersecurity.com or one of its subdomains, or the README of github.com/Keeper-Security/secrets-manager. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "keeper-secrets-manager", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Keeper Secrets Manager on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Keeper Secrets Manager on Anchor Terminal](https://www.anchorterminal.com/badges/keeper-secrets-manager.svg)](https://www.anchorterminal.com/tools/keeper-secrets-manager) ``` Plain link: ```html Keeper Secrets Manager on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Keeper Secrets Manager is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/keeper-secrets-manager-dark.png - Light: https://www.anchorterminal.com/assets/share/keeper-secrets-manager-light.png