Keeper Security Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Keeper Security Tools
keeper_ · 30 tools · Free 14 · Pro 16
Password and secrets management for MSPs. Three separately-authenticated surfaces share one host and are chosen by the path: provisioning, which identifies you by a partner name and a per-email hash in the query string; MSP account management, which uses a signed token and a vendor header; and SCIM 2.0, which uses a bearer token and pages on start index and count, capped at 500. The region can be overridden in the instance address. Nothing is cached and there is no refresh. Note that creating a license is a GET that really does write.
All connector tools · Keeper Security setup guide
Keeper Security tool groups
- Provisioning — 2 tools
- MSP Account Management — 9 tools
- SCIM 2.0 (Users & Teams) — 19 tools
Provisioning
keeper_provision_family_license details
keeper_provision_family_license details
[Keeper Security] Provision a 1-year Keeper Family plan license (Keeper Family + BreachWatch dark-web monitoring + 10GB encrypted file storage) for an end user's personal vault. NOTE: despite using the GET verb upstream, this CREATES a real, billable license — it is a write, not a read. On success the response contains success, order_number, and a vault_url the account owner uses to activate and set their own Master Password; your enterprise does not manage the resulting personal vault. Requires Keeper Partner Name + Partner Secret credentials (issued out-of-band by your Keeper representative and stored on the Keeper connector). See keeper_provision_student_license for the student (Keeper Unlimited) variant.
keeper_provision_student_license details
keeper_provision_student_license details
[Keeper Security] Provision a 1-year Keeper Unlimited student plan license (full password manager + BreachWatch + 10GB encrypted file storage) for a student's personal vault (product_type=4 is applied automatically). NOTE: despite using the GET verb upstream, this CREATES a real, billable license — it is a write, not a read. The student email MUST use a secondary/alias domain (e.g. students.university.edu), NEVER your enterprise's primary domain — Keeper rejects primary-domain addresses to keep student accounts independent of the enterprise. On success the response contains success, order_number, and a vault_url the student uses to activate and set their own Master Password; the student owns the account and your enterprise cannot enforce 2FA, audit, or reset it. Requires Keeper Partner Name + Partner Secret credentials and an active Keeper Enterprise license. See keeper_provision_family_license for the Family variant.
MSP Account Management
keeper_msp_activate_expired details
keeper_msp_activate_expired details
[Keeper Security] Reactivate an expired MSP managed account, returning it to an active paid state. Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. Returns raw Keeper JSON.
keeper_msp_cancel_paid_account details
keeper_msp_cancel_paid_account details
[Keeper Security] Cancel the paid subscription for an MSP managed account. DESTRUCTIVE: this ends the account's paid subscription and stops its billing. Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. Reactivate later with keeper_msp_activate_expired. Returns raw Keeper JSON.
keeper_msp_convert_to_paid details
keeper_msp_convert_to_paid details
[Keeper Security] Convert an MSP managed account from trial to a paid subscription. Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. This begins billing for the account. Returns raw Keeper JSON.
keeper_msp_create_trial_account details
keeper_msp_create_trial_account details
[Keeper Security] Create a new trial MSP managed account under this vendor. The account starts in trial state — promote it later with keeper_msp_convert_to_paid. vendorInternalId is your own unique id for the account (1-52 chars) and is how you address it in every subsequent lifecycle/usage call. Returns raw Keeper JSON.
keeper_msp_get_current_usage details
keeper_msp_get_current_usage details
[Keeper Security] Get the CURRENT seat/license usage for MSP managed accounts. This is a read — despite being an HTTP POST it only reports usage and changes nothing. Scope to one account by vendorInternalId or partnerId (from keeper_msp_list_accounts); omit both to report usage across all managed accounts. When both ids are given, vendorInternalId is used. Returns raw Keeper JSON.
keeper_msp_get_monthly_usage details
keeper_msp_get_monthly_usage details
[Keeper Security] Get HISTORICAL monthly seat/license usage for an MSP managed account. This is a read (HTTP POST that only reports usage). Scope to one account by vendorInternalId or partnerId (from keeper_msp_list_accounts); omit both for all accounts (vendorInternalId wins if both given). Optionally narrow to a specific billing period with month (2-digit, e.g. "03") and year (4-digit, e.g. "2026"); omit to return the most recent period. Returns raw Keeper JSON.
keeper_msp_list_accounts details
keeper_msp_list_accounts details
[Keeper Security] List the managed accounts under this MSP/distributor vendor. Each account carries its vendorInternalId (your own external id) and partnerId (Keeper's internal id) — the two identifiers every other MSP lifecycle/usage tool accepts. Returns raw Keeper JSON. No parameters. Read a specific account's seat usage with keeper_msp_get_current_usage.
keeper_msp_list_products details
keeper_msp_list_products details
[Keeper Security] List the MSP products/plans available to this vendor (the license SKUs you can allocate to managed accounts). Returns raw Keeper JSON. No parameters.
keeper_msp_remove_account details
keeper_msp_remove_account details
[Keeper Security] Remove a pending or conflicting MSP managed account. DESTRUCTIVE: this deletes the account record (used to clear accounts stuck in a pending/conflict state). Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. Returns raw Keeper JSON.
SCIM 2.0 (Users & Teams)
keeper_scim_bulk details
keeper_scim_bulk details
[Keeper Security] Execute a SCIM 2.0 bulk request (POST /Bulk) against the Keeper enterprise node. operationsJson is a raw JSON ARRAY of bulk operations, each { method (POST|PUT|PATCH|DELETE), path (a resource path with leading slash such as /Users or /Users/ or /Groups), bulkId (required for POST — a later op can reference a just-created resource via "bulkId:<id>"), data (the resource for POST/PUT or the PatchOp for PATCH) }; optional failOnErrors caps how many errored ops the node tolerates before aborting the remainder. Before sending, this tool reads the node's ServiceProviderConfig and REJECTS the request if bulk is unsupported, the operation count exceeds bulk.maxOperations, or the UTF-8 payload exceeds bulk.maxPayloadSize (only limits the node actually advertises are enforced). Returns the raw SCIM BulkResponse — each result carries its OWN status object ({"code":"201"}), so inspect every Operations[].status.code and Operations[].response for PARTIAL failures (a bulk is NOT atomic across ops). Destructive: because a bulk can DELETE or disable users/Teams, the tool is gated at the most-privileged nested operation — always Pro + Destructive + edit:scim regardless of the individual ops it carries.
keeper_scim_create_group details
keeper_scim_create_group details
[Keeper Security] Create a SCIM Group — a Keeper Team — with the given displayName and, optionally, an initial set of member user ids (from keeper_scim_list_users). Returns the created Group resource including its assigned id. Adjust membership later with keeper_scim_update_group_members.
keeper_scim_create_user details
keeper_scim_create_user details
[Keeper Security] Provision (invite) a new user into the Keeper enterprise node. userName is required (typically the user's email/login). Optionally set the given/family name, a primary email, an externalId (your IdP's stable id), and the initial active state (default true). Returns the created SCIM User resource including its assigned id. Add the user to a team with keeper_scim_update_group_members.
keeper_scim_delete_group details
keeper_scim_delete_group details
[Keeper Security] Delete a SCIM Group — permanently removing the Keeper Team (its member users are not deleted, only the team and its shared-folder assignments). groupId from keeper_scim_list_groups.
keeper_scim_delete_user details
keeper_scim_delete_user details
[Keeper Security] Deprovision a SCIM user. Note: Keeper's SCIM DELETE LOCKS the account (blocks access) rather than permanently destroying the vault — the record and its data are retained per Keeper's account-transfer/retention policy. userId from keeper_scim_list_users.
keeper_scim_get_group details
keeper_scim_get_group details
[Keeper Security] Get a single SCIM Group (Keeper Team) by its id (from keeper_scim_list_groups), including its member list. Returns the raw SCIM Group resource.
keeper_scim_get_resource_type_group details
keeper_scim_get_resource_type_group details
[Keeper Security] Get the SCIM ResourceType definition for Group (GET /ResourceTypes/Group) — its endpoint (/Groups) and schema. SCIM Groups map to Keeper Teams. The by-name form of keeper_scim_get_resource_types. Single-fetch is RFC-optional; an unsupporting node may 404/405. No parameters.
keeper_scim_get_resource_type_user details
keeper_scim_get_resource_type_user details
[Keeper Security] Get the SCIM ResourceType definition for User (GET /ResourceTypes/User) — its endpoint (/Users), core schema, and any schema extensions. The by-name form of keeper_scim_get_resource_types (which lists all). Single-fetch is RFC-optional; an unsupporting node may 404/405. No parameters.
keeper_scim_get_resource_types details
keeper_scim_get_resource_types details
[Keeper Security] Get the SCIM ResourceTypes exposed by the Keeper node (User, Group) and their endpoints and schemas. No parameters.
keeper_scim_get_schema details
keeper_scim_get_schema details
[Keeper Security] Get a single SCIM schema definition by its URN (GET /Schemas/), e.g. urn:ietf:params:scim:schemas:core:2.0:User. The by-id form of keeper_scim_get_schemas (which lists all). Returns the raw SCIM Schema resource. Single-schema fetch is RFC-optional and the URN carries colons — a node that does not support the by-id form (or wants the raw, non-%3A-encoded URN) may 404/405; use keeper_scim_get_schemas if so.
keeper_scim_get_schemas details
keeper_scim_get_schemas details
[Keeper Security] Get the SCIM Schemas advertised by the Keeper node — the attribute definitions for the User and Group resources. No parameters.
keeper_scim_get_service_provider_config details
keeper_scim_get_service_provider_config details
[Keeper Security] Get the SCIM ServiceProviderConfig for the Keeper node — the SCIM features Keeper's endpoint supports (patch, bulk, filter, changePassword, sort, etc.). No parameters.
keeper_scim_get_user details
keeper_scim_get_user details
[Keeper Security] Get a single SCIM user by its Keeper user id (the SCIM resource id from keeper_scim_list_users). Returns the raw SCIM User resource.
keeper_scim_list_groups details
keeper_scim_list_groups details
[Keeper Security] List SCIM Groups (which map to Keeper Teams) in the enterprise node, optionally narrowed by a SCIM filter (e.g. displayName eq "Engineering"). Paginated via startIndex (1-based) and count (capped at 500). Returns the raw SCIM ListResponse. Fetch a single group with keeper_scim_get_group.
keeper_scim_list_users details
keeper_scim_list_users details
[Keeper Security] List SCIM-provisioned users in the Keeper enterprise node, optionally narrowed by a SCIM filter (e.g. userName eq "user@example.com"). Paginated via startIndex (1-based) and count (capped at 500). Returns the raw SCIM ListResponse {totalResults, startIndex, itemsPerPage, Resources:[...]}. Fetch a single user with keeper_scim_get_user.
keeper_scim_patch_user details
keeper_scim_patch_user details
[Keeper Security] Apply an arbitrary SCIM 2.0 PatchOp (PATCH /Users/) to a user — the general form of keeper_scim_set_user_active. operationsJson is a raw JSON ARRAY of patch operations, each { op (add|remove|replace), path (a BARE attribute path such as active or name.familyName; required for remove), value }. Returns the updated SCIM User resource. Destructive: a patch can disable/lock a user (replace active=false) or wipe attributes (remove). Prefer keeper_scim_set_user_active for the common enable/disable case. userId from keeper_scim_list_users.
keeper_scim_set_user_active details
keeper_scim_set_user_active details
[Keeper Security] Enable or disable (lock) a SCIM user via a targeted PatchOp on the active attribute — the surgical alternative to keeper_scim_update_user. Setting active=false LOCKS the user out of their Keeper vault; active=true re-enables them. userId from keeper_scim_list_users.
keeper_scim_update_group_members details
keeper_scim_update_group_members details
[Keeper Security] Add or remove members of a SCIM Group (Keeper Team) with a PatchOp. operation must be 'add' or 'remove'; memberIds is the list of user ids (from keeper_scim_list_users) to add to or remove from the team. groupId from keeper_scim_list_groups.
keeper_scim_update_user details
keeper_scim_update_user details
[Keeper Security] Full-replace (SCIM PUT) an existing user's attributes. userId (from keeper_scim_list_users) and userName are required; any omitted optional field is left unset on the replaced resource, so send the complete desired state. To only enable/disable a user without replacing other attributes, use keeper_scim_set_user_active instead.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team