# Keeper Secrets Manager (slim) > Keeper Secrets Manager is a cloud vault for infrastructure secrets, sold as an add-on to Keeper Security's business password manager. Applications read secrets through SDKs in seven languages, the ksm CLI or a local MCP server, decrypting on the client. - Full: https://www.anchorterminal.com/tools/keeper-secrets-manager.md (~8,350 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/keeper-secrets-manager.json · canonical https://www.anchorterminal.com/tools/keeper-secrets-manager - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 69.4/100 · rank #159 of 722 · #9 in Secrets & credential vaults · not agent-ready · confidence medium** Assessment: Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault. ## Facts - Kind: HTTP API · vendor: Keeper Security, Inc. · category: Secrets & credential vaults · legal entity: Keeper Security, Inc. · provenance 98/100 - Local only (HTTP, stdio): pypi `keeper-secrets-manager-core`, pypi `keeper-secrets-manager-cli`, npm `@keeper-security/secrets-manager-core` - Auth: API key · pricing: Paid · x402: no · licence: Proprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - Interfaces: SDKs for Python, Java and Kotlin, JavaScript, .NET, Go, Ruby and Rust, a PowerShell plugin, the `ksm` CLI (binary or `pip3 install keeper-secrets-manager-cli`), and a stdio MCP server as a Docker image or Go binary - Credentials: One-time access token (region prefix plus 43 characters) redeemed once for a device configuration holding an ECC secp256r1 private key and the AES-256 application key. Requests are ECDSA-signed - Scoping: An application is shared individual records or shared folders, read-only unless `--editable`. Devices are IP-locked by default and can carry an access expiry - MCP server: `keeper/keeper-mcp-server` on Docker Hub, source in Keeper-Security/keeper-mcp-golang-docker, v2.5.0 of 16 July 2026, 19 tools. Confirmation for writes, deletes and unmasking, `--auto-approve` to skip it - Agent kit: Keeper-Security/keeper-agent-kit 1.2.0 (10 June 2026) with three skills, keeper-secrets, keeper-admin and keeper-setup, for Claude Code, Cursor, Codex and GitHub Copilot - Throttling: HTTP 403 with `{"error":"throttled"}`. The Python SDK retries five times at 11, 22, 44, 88 and 176 seconds with jitter and honours `retry_after`. No published limits found - Offline cache: Optional encrypted local cache in every SDK, read when the Keeper endpoint is unreachable - Audit events: `app_client_connected`, `app_client_access`, `app_client_record_update`, blocked-IP denials and share changes, in the Advanced Reporting and Alerts module, with SIEM export and webhooks - Regions: US, EU, AU, CA, JP and US GovCloud on AWS, fixed per tenant - Service levels: 99.9 per cent monthly availability in the Service Level Objectives, recovery time objective 8 hours, remedy limited to termination - Certifications: SOC 2 Type 2, ISO 27001, FedRAMP High and StateRAMP High per the docs. Reports on request through trust.keeper.io - Rotation: Through KeeperPAM, which needs its own licence and a Keeper Gateway. SDK record updates accept a rotation transaction type - Scores: Reliability 76, Performance pending, Schema & documentation 71, Agent ergonomics 63, Security & auth 86, Payments & pricing 20, Task success pending, Maintenance & community 92, Transparency & trust 78 · total over the 7 assessed categories - Why: Reliability, Graded with the hosted lines, because the vault is Keeper's cloud and the SDKs, CLI and MCP server are clients of it. · Schema & documentation, No OpenAPI or other published contract for the Secrets Manager endpoint at `/api/rest/sm/v1`. · Agent ergonomics, The MCP server has 19 tools, lists metadata only and masks sensitive fields unless asked (17 of 25). · Security & auth, A one-time token bootstraps each device, which then signs every request with its own ECC secp256r1 key. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Newest tag is the JavaScript GCP KMS storage 1.1.0 on 6 October 2026, two days before this check (30). · Transparency & trust, The SDKs, CLI, MCP server and agent kit are MIT on GitHub. - Sources: 34, open questions: 8, both in the full twin - Capabilities: secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate - JSON: https://www.anchorterminal.com/api/v1/tools/keeper-secrets-manager.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/keeper-secrets-manager.svg` or a link to https://www.anchorterminal.com/tools/keeper-secrets-manager from a page on keepersecurity.com or one of its subdomains, or the README of github.com/Keeper-Security/secrets-manager, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token 2. Run commands under `ksm exec` so secrets arrive as environment variables and stay out of the model's context 3. Expect HTTP 403 with `{"error":"throttled"}` under load. The Python SDK retries five times from 11 seconds, so allow for long waits 4. A device is locked to the IP address it first connects from unless it was created with `--unlock-ip`. Check this before running from a dynamic address 5. Leave `--auto-approve` off on the MCP server. It removes confirmation for deletes and for unmasking values ## Connect ```bash pip3 install keeper-secrets-manager-cli # or: pip3 install keeper-secrets-manager-core, npm install @keeper-security/secrets-manager-core ``` ```bash ksm profile init XX:XXXX # one-time access token from the vault ksm secret list # values decrypt on the client, so plain curl can't read them ``` ```bash /plugin marketplace add Keeper-Security/keeper-agent-kit /plugin install keeper-secrets@keeper-security ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/keeper-secrets-manager ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 83.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/infisical.min.md | | AWS Secrets Manager | BB | 77.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.5 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Azure Key Vault | BB | 74.7 | secrets.store, secrets.machine-identity, secrets.audit, secrets.rotate | https://www.anchorterminal.com/tools/azure-key-vault.min.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/akeyless.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)