Skip to main content
Tools Reference

Keeper Security Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Keeper Security Tools

keeper_ · 30 tools · Free 14 · Pro 16 Password and secrets management for MSPs. Three separately-authenticated surfaces share one host and are chosen by the path: provisioning, which identifies you by a partner name and a per-email hash in the query string; MSP account management, which uses a signed token and a vendor header; and SCIM 2.0, which uses a bearer token and pages on start index and count, capped at 500. The region can be overridden in the instance address. Nothing is cached and there is no refresh. Note that creating a license is a GET that really does write.

All connector tools · Keeper Security setup guide

Keeper Security tool groups

Provisioning

ToolPlanAccessSummary
keeper_provision_family_licenseProDestructiveProvision a 1-year Keeper Family plan license (Keeper Family + BreachWatch dark-web monitoring + 10GB encrypted file storage) for an end user's personal vault.
keeper_provision_student_licenseProDestructiveProvision a 1-year Keeper Unlimited student plan license (full password manager + BreachWatch + 10GB encrypted file storage) for a student's personal vault (product_type=4 is applied automatically).

[Keeper Security] Provision a 1-year Keeper Family plan license (Keeper Family + BreachWatch dark-web monitoring + 10GB encrypted file storage) for an end user's personal vault. NOTE: despite using the GET verb upstream, this CREATES a real, billable license — it is a write, not a read. On success the response contains success, order_number, and a vault_url the account owner uses to activate and set their own Master Password; your enterprise does not manage the resulting personal vault. Requires Keeper Partner Name + Partner Secret credentials (issued out-of-band by your Keeper representative and stored on the Keeper connector). See keeper_provision_student_license for the student (Keeper Unlimited) variant.

ParamTypeRequiredDefaultDescription
emailstringyesThe account owner's email address. This becomes the Keeper account login and is hashed with your Partner Secret for authentication. Required.
firstNamestringyesThe account owner's first name. Required.
lastNamestringnonullThe account owner's last name. Optional.
transactionIdstringyesA unique transaction id you assign per request, for your own reconciliation/records (e.g. "ORD-2026-00123"). Required.

[Keeper Security] Provision a 1-year Keeper Unlimited student plan license (full password manager + BreachWatch + 10GB encrypted file storage) for a student's personal vault (product_type=4 is applied automatically). NOTE: despite using the GET verb upstream, this CREATES a real, billable license — it is a write, not a read. The student email MUST use a secondary/alias domain (e.g. students.university.edu), NEVER your enterprise's primary domain — Keeper rejects primary-domain addresses to keep student accounts independent of the enterprise. On success the response contains success, order_number, and a vault_url the student uses to activate and set their own Master Password; the student owns the account and your enterprise cannot enforce 2FA, audit, or reset it. Requires Keeper Partner Name + Partner Secret credentials and an active Keeper Enterprise license. See keeper_provision_family_license for the Family variant.

ParamTypeRequiredDefaultDescription
emailstringyesThe student's email address — MUST use a secondary/alias domain (e.g. student@students.university.edu), not the enterprise's primary domain. Hashed with your Partner Secret for authentication. Required.
firstNamestringyesThe student's first name. Required.
lastNamestringnonullThe student's last name. Optional.
transactionIdstringyesA unique transaction id you assign per request, for your own reconciliation/records (e.g. "UNIV-2026-00123"). Required.

MSP Account Management

ToolPlanAccessSummary
keeper_msp_activate_expiredProDestructiveReactivate an expired MSP managed account, returning it to an active paid state.
keeper_msp_cancel_paid_accountProDestructiveCancel the paid subscription for an MSP managed account.
keeper_msp_convert_to_paidProDestructiveConvert an MSP managed account from trial to a paid subscription.
keeper_msp_create_trial_accountProWriteCreate a new trial MSP managed account under this vendor.
keeper_msp_get_current_usageFreeRead-onlyGet the CURRENT seat/license usage for MSP managed accounts.
keeper_msp_get_monthly_usageFreeRead-onlyGet HISTORICAL monthly seat/license usage for an MSP managed account.
keeper_msp_list_accountsFreeRead-onlyList the managed accounts under this MSP/distributor vendor.
keeper_msp_list_productsFreeRead-onlyList the MSP products/plans available to this vendor (the license SKUs you can allocate to managed accounts).
keeper_msp_remove_accountProDestructiveRemove a pending or conflicting MSP managed account.

[Keeper Security] Reactivate an expired MSP managed account, returning it to an active paid state. Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. Returns raw Keeper JSON.

ParamTypeRequiredDefaultDescription
partnerIdstringnonullKeeper's internal partner id for the account (from keeper_msp_list_accounts). Ignored when vendorInternalId is also supplied.
vendorInternalIdstringnonullThe MSP's own external account id (from keeper_msp_list_accounts). Preferred over partnerId when both are supplied.

[Keeper Security] Cancel the paid subscription for an MSP managed account. DESTRUCTIVE: this ends the account's paid subscription and stops its billing. Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. Reactivate later with keeper_msp_activate_expired. Returns raw Keeper JSON.

ParamTypeRequiredDefaultDescription
partnerIdstringnonullKeeper's internal partner id for the account (from keeper_msp_list_accounts). Ignored when vendorInternalId is also supplied.
vendorInternalIdstringnonullThe MSP's own external account id (from keeper_msp_list_accounts). Preferred over partnerId when both are supplied.

[Keeper Security] Convert an MSP managed account from trial to a paid subscription. Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. This begins billing for the account. Returns raw Keeper JSON.

ParamTypeRequiredDefaultDescription
partnerIdstringnonullKeeper's internal partner id for the account (from keeper_msp_list_accounts). Ignored when vendorInternalId is also supplied.
vendorInternalIdstringnonullThe MSP's own external account id (from keeper_msp_list_accounts). Preferred over partnerId when both are supplied.

[Keeper Security] Create a new trial MSP managed account under this vendor. The account starts in trial state — promote it later with keeper_msp_convert_to_paid. vendorInternalId is your own unique id for the account (1-52 chars) and is how you address it in every subsequent lifecycle/usage call. Returns raw Keeper JSON.

ParamTypeRequiredDefaultDescription
citystringnonullOptional city.
countrystringyesISO 3166-1 alpha-2 country code (2 chars), e.g. "US".
emailstringyesPrimary admin email for the new account.
namestringyesCompany/account display name (max 255 chars).
phonestringnonullOptional phone number (max 15 chars).
showPricingInMspConsolebooleannofalseWhether the Keeper MSP console should display pricing for this account. Defaults to false.
statestringnonullOptional state/province.
streetstringnonullOptional street address.
vendorInternalIdstringyesThe MSP's own unique external id for this account (1-52 chars) — used to address it in all later MSP tools.
zipCodestringyesPostal/ZIP code (max 12 chars).

[Keeper Security] Get the CURRENT seat/license usage for MSP managed accounts. This is a read — despite being an HTTP POST it only reports usage and changes nothing. Scope to one account by vendorInternalId or partnerId (from keeper_msp_list_accounts); omit both to report usage across all managed accounts. When both ids are given, vendorInternalId is used. Returns raw Keeper JSON.

ParamTypeRequiredDefaultDescription
partnerIdstringnonullOptional. Keeper's internal partner id for the account (from keeper_msp_list_accounts). Ignored when vendorInternalId is also supplied.
vendorInternalIdstringnonullOptional. The MSP's own external account id (from keeper_msp_list_accounts). Preferred over partnerId when both are supplied.

[Keeper Security] Get HISTORICAL monthly seat/license usage for an MSP managed account. This is a read (HTTP POST that only reports usage). Scope to one account by vendorInternalId or partnerId (from keeper_msp_list_accounts); omit both for all accounts (vendorInternalId wins if both given). Optionally narrow to a specific billing period with month (2-digit, e.g. "03") and year (4-digit, e.g. "2026"); omit to return the most recent period. Returns raw Keeper JSON.

ParamTypeRequiredDefaultDescription
monthstringnonullOptional 2-digit month as a string, e.g. "01"-"12". Omit to use the most recent period.
partnerIdstringnonullOptional. Keeper's internal partner id for the account (from keeper_msp_list_accounts). Ignored when vendorInternalId is also supplied.
vendorInternalIdstringnonullOptional. The MSP's own external account id (from keeper_msp_list_accounts). Preferred over partnerId when both are supplied.
yearstringnonullOptional 4-digit year as a string, e.g. "2026". Omit to use the most recent period.

[Keeper Security] List the managed accounts under this MSP/distributor vendor. Each account carries its vendorInternalId (your own external id) and partnerId (Keeper's internal id) — the two identifiers every other MSP lifecycle/usage tool accepts. Returns raw Keeper JSON. No parameters. Read a specific account's seat usage with keeper_msp_get_current_usage.

[Keeper Security] List the MSP products/plans available to this vendor (the license SKUs you can allocate to managed accounts). Returns raw Keeper JSON. No parameters.

[Keeper Security] Remove a pending or conflicting MSP managed account. DESTRUCTIVE: this deletes the account record (used to clear accounts stuck in a pending/conflict state). Identify the account by vendorInternalId or partnerId (from keeper_msp_list_accounts); vendorInternalId is used when both are given. Returns raw Keeper JSON.

ParamTypeRequiredDefaultDescription
partnerIdstringnonullKeeper's internal partner id for the account (from keeper_msp_list_accounts). Ignored when vendorInternalId is also supplied.
vendorInternalIdstringnonullThe MSP's own external account id (from keeper_msp_list_accounts). Preferred over partnerId when both are supplied.

SCIM 2.0 (Users & Teams)

ToolPlanAccessSummary
keeper_scim_bulkProDestructiveExecute a SCIM 2.0 bulk request (POST /Bulk) against the Keeper enterprise node.
keeper_scim_create_groupProWriteCreate a SCIM Group — a Keeper Team — with the given displayName and, optionally, an initial set of member user ids (from keeper_scim_list_users).
keeper_scim_create_userProWriteProvision (invite) a new user into the Keeper enterprise node.
keeper_scim_delete_groupProDestructiveDelete a SCIM Group — permanently removing the Keeper Team (its member users are not deleted, only the team and its shared-folder assignments).
keeper_scim_delete_userProDestructiveDeprovision a SCIM user.
keeper_scim_get_groupFreeRead-onlyGet a single SCIM Group (Keeper Team) by its id (from keeper_scim_list_groups), including its member list.
keeper_scim_get_resource_type_groupFreeRead-onlyGet the SCIM ResourceType definition for Group (GET /ResourceTypes/Group) — its endpoint (/Groups) and schema.
keeper_scim_get_resource_type_userFreeRead-onlyGet the SCIM ResourceType definition for User (GET /ResourceTypes/User) — its endpoint (/Users), core schema, and any schema extensions.
keeper_scim_get_resource_typesFreeRead-onlyGet the SCIM ResourceTypes exposed by the Keeper node (User, Group) and their endpoints and schemas.
keeper_scim_get_schemaFreeRead-onlyGet a single SCIM schema definition by its URN (GET /Schemas/), e.g. urn:ietf:params:scim:schemas:core:2.0:User.
keeper_scim_get_schemasFreeRead-onlyGet the SCIM Schemas advertised by the Keeper node — the attribute definitions for the User and Group resources.
keeper_scim_get_service_provider_configFreeRead-onlyGet the SCIM ServiceProviderConfig for the Keeper node — the SCIM features Keeper's endpoint supports (patch, bulk, filter, changePassword, sort, etc.).
keeper_scim_get_userFreeRead-onlyGet a single SCIM user by its Keeper user id (the SCIM resource id from keeper_scim_list_users).
keeper_scim_list_groupsFreeRead-onlyList SCIM Groups (which map to Keeper Teams) in the enterprise node, optionally narrowed by a SCIM filter (e.g. displayName eq "Engineering").
keeper_scim_list_usersFreeRead-onlyList SCIM-provisioned users in the Keeper enterprise node, optionally narrowed by a SCIM filter (e.g. userName eq "user@example.com").
keeper_scim_patch_userProDestructiveApply an arbitrary SCIM 2.0 PatchOp (PATCH /Users/) to a user — the general form of keeper_scim_set_user_active.
keeper_scim_set_user_activeProDestructiveEnable or disable (lock) a SCIM user via a targeted PatchOp on the active attribute — the surgical alternative to keeper_scim_update_user.
keeper_scim_update_group_membersProDestructiveAdd or remove members of a SCIM Group (Keeper Team) with a PatchOp.
keeper_scim_update_userProDestructiveFull-replace (SCIM PUT) an existing user's attributes.

[Keeper Security] Execute a SCIM 2.0 bulk request (POST /Bulk) against the Keeper enterprise node. operationsJson is a raw JSON ARRAY of bulk operations, each { method (POST|PUT|PATCH|DELETE), path (a resource path with leading slash such as /Users or /Users/ or /Groups), bulkId (required for POST — a later op can reference a just-created resource via "bulkId:<id>"), data (the resource for POST/PUT or the PatchOp for PATCH) }; optional failOnErrors caps how many errored ops the node tolerates before aborting the remainder. Before sending, this tool reads the node's ServiceProviderConfig and REJECTS the request if bulk is unsupported, the operation count exceeds bulk.maxOperations, or the UTF-8 payload exceeds bulk.maxPayloadSize (only limits the node actually advertises are enforced). Returns the raw SCIM BulkResponse — each result carries its OWN status object ({"code":"201"}), so inspect every Operations[].status.code and Operations[].response for PARTIAL failures (a bulk is NOT atomic across ops). Destructive: because a bulk can DELETE or disable users/Teams, the tool is gated at the most-privileged nested operation — always Pro + Destructive + edit:scim regardless of the individual ops it carries.

ParamTypeRequiredDefaultDescription
failOnErrorsintegernonullOptional: number of errored operations the node tolerates before aborting the remainder (SCIM failOnErrors). Omit to process every operation.
operationsJsonstringyesRaw JSON array of SCIM bulk operations, e.g. [{"method":"POST","path":"/Users","bulkId":"u1","data":}]. Must be a JSON array.

[Keeper Security] Create a SCIM Group — a Keeper Team — with the given displayName and, optionally, an initial set of member user ids (from keeper_scim_list_users). Returns the created Group resource including its assigned id. Adjust membership later with keeper_scim_update_group_members.

ParamTypeRequiredDefaultDescription
displayNamestringyesDisplay name of the new Team (SCIM Group displayName). Required.
memberIdsarraynonullOptional initial member user ids (from keeper_scim_list_users) to add to the team on creation.

[Keeper Security] Provision (invite) a new user into the Keeper enterprise node. userName is required (typically the user's email/login). Optionally set the given/family name, a primary email, an externalId (your IdP's stable id), and the initial active state (default true). Returns the created SCIM User resource including its assigned id. Add the user to a team with keeper_scim_update_group_members.

ParamTypeRequiredDefaultDescription
activebooleannotrueWhether the user is active on creation. Defaults to true.
emailstringnonullPrimary email address. Optional; defaults to userName in most Keeper setups.
externalIdstringnonullExternal id — your identity provider's stable id for this user. Optional.
firstNamestringnonullGiven (first) name. Optional.
lastNamestringnonullFamily (last) name. Optional.
userNamestringyesSCIM userName — the user's unique login, typically their email address. Required.

[Keeper Security] Delete a SCIM Group — permanently removing the Keeper Team (its member users are not deleted, only the team and its shared-folder assignments). groupId from keeper_scim_list_groups.

ParamTypeRequiredDefaultDescription
groupIdstringyesSCIM group id (resource id) of the Team to delete. From keeper_scim_list_groups.

[Keeper Security] Deprovision a SCIM user. Note: Keeper's SCIM DELETE LOCKS the account (blocks access) rather than permanently destroying the vault — the record and its data are retained per Keeper's account-transfer/retention policy. userId from keeper_scim_list_users.

ParamTypeRequiredDefaultDescription
userIdstringyesSCIM user id (resource id) to deprovision (lock). From keeper_scim_list_users.

[Keeper Security] Get a single SCIM Group (Keeper Team) by its id (from keeper_scim_list_groups), including its member list. Returns the raw SCIM Group resource.

ParamTypeRequiredDefaultDescription
groupIdstringyesSCIM group id (resource id) to retrieve. From keeper_scim_list_groups.

[Keeper Security] Get the SCIM ResourceType definition for Group (GET /ResourceTypes/Group) — its endpoint (/Groups) and schema. SCIM Groups map to Keeper Teams. The by-name form of keeper_scim_get_resource_types. Single-fetch is RFC-optional; an unsupporting node may 404/405. No parameters.

[Keeper Security] Get the SCIM ResourceType definition for User (GET /ResourceTypes/User) — its endpoint (/Users), core schema, and any schema extensions. The by-name form of keeper_scim_get_resource_types (which lists all). Single-fetch is RFC-optional; an unsupporting node may 404/405. No parameters.

[Keeper Security] Get the SCIM ResourceTypes exposed by the Keeper node (User, Group) and their endpoints and schemas. No parameters.

[Keeper Security] Get a single SCIM schema definition by its URN (GET /Schemas/), e.g. urn:ietf:params:scim:schemas:core:2.0:User. The by-id form of keeper_scim_get_schemas (which lists all). Returns the raw SCIM Schema resource. Single-schema fetch is RFC-optional and the URN carries colons — a node that does not support the by-id form (or wants the raw, non-%3A-encoded URN) may 404/405; use keeper_scim_get_schemas if so.

ParamTypeRequiredDefaultDescription
schemaIdstringyesSCIM schema URN to retrieve, e.g. urn:ietf:params:scim:schemas:core:2.0:User (from keeper_scim_get_schemas).

[Keeper Security] Get the SCIM Schemas advertised by the Keeper node — the attribute definitions for the User and Group resources. No parameters.

[Keeper Security] Get the SCIM ServiceProviderConfig for the Keeper node — the SCIM features Keeper's endpoint supports (patch, bulk, filter, changePassword, sort, etc.). No parameters.

[Keeper Security] Get a single SCIM user by its Keeper user id (the SCIM resource id from keeper_scim_list_users). Returns the raw SCIM User resource.

ParamTypeRequiredDefaultDescription
userIdstringyesSCIM user id (resource id) to retrieve. From keeper_scim_list_users.

[Keeper Security] List SCIM Groups (which map to Keeper Teams) in the enterprise node, optionally narrowed by a SCIM filter (e.g. displayName eq "Engineering"). Paginated via startIndex (1-based) and count (capped at 500). Returns the raw SCIM ListResponse. Fetch a single group with keeper_scim_get_group.

ParamTypeRequiredDefaultDescription
countintegernonullMax results per page (SCIM count). Capped server-side at 500. Omit for the SCIM endpoint default.
filterstringnonullOptional SCIM filter expression, e.g. displayName eq "Engineering". Omit for all groups.
startIndexintegernonull1-based index of the first result to return (SCIM startIndex). Omit for the first page.

[Keeper Security] List SCIM-provisioned users in the Keeper enterprise node, optionally narrowed by a SCIM filter (e.g. userName eq "user@example.com"). Paginated via startIndex (1-based) and count (capped at 500). Returns the raw SCIM ListResponse {totalResults, startIndex, itemsPerPage, Resources:[...]}. Fetch a single user with keeper_scim_get_user.

ParamTypeRequiredDefaultDescription
countintegernonullMax results per page (SCIM count). Capped server-side at 500. Omit for the SCIM endpoint default.
filterstringnonullOptional SCIM filter expression, e.g. userName eq "user@example.com" or active eq true. Omit for all users.
startIndexintegernonull1-based index of the first result to return (SCIM startIndex). Omit for the first page.

[Keeper Security] Apply an arbitrary SCIM 2.0 PatchOp (PATCH /Users/) to a user — the general form of keeper_scim_set_user_active. operationsJson is a raw JSON ARRAY of patch operations, each { op (add|remove|replace), path (a BARE attribute path such as active or name.familyName; required for remove), value }. Returns the updated SCIM User resource. Destructive: a patch can disable/lock a user (replace active=false) or wipe attributes (remove). Prefer keeper_scim_set_user_active for the common enable/disable case. userId from keeper_scim_list_users.

ParamTypeRequiredDefaultDescription
operationsJsonstringyesRaw JSON array of SCIM PatchOp operations, e.g. [{"op":"replace","path":"name.familyName","value":"Smith"}]. Must be a JSON array of {op,path?,value?}.
userIdstringyesSCIM user id (resource id) to patch. From keeper_scim_list_users.

[Keeper Security] Enable or disable (lock) a SCIM user via a targeted PatchOp on the active attribute — the surgical alternative to keeper_scim_update_user. Setting active=false LOCKS the user out of their Keeper vault; active=true re-enables them. userId from keeper_scim_list_users.

ParamTypeRequiredDefaultDescription
activebooleanyesTarget active state: true to enable, false to disable/lock the user.
userIdstringyesSCIM user id (resource id) to enable/disable. From keeper_scim_list_users.

[Keeper Security] Add or remove members of a SCIM Group (Keeper Team) with a PatchOp. operation must be 'add' or 'remove'; memberIds is the list of user ids (from keeper_scim_list_users) to add to or remove from the team. groupId from keeper_scim_list_groups.

ParamTypeRequiredDefaultDescription
groupIdstringyesSCIM group id (resource id) to modify. From keeper_scim_list_groups.
memberIdsarrayyesUser ids (from keeper_scim_list_users) to add to or remove from the team.
operationstringyesMembership operation: 'add' to add the given members, 'remove' to remove them.

[Keeper Security] Full-replace (SCIM PUT) an existing user's attributes. userId (from keeper_scim_list_users) and userName are required; any omitted optional field is left unset on the replaced resource, so send the complete desired state. To only enable/disable a user without replacing other attributes, use keeper_scim_set_user_active instead.

ParamTypeRequiredDefaultDescription
activebooleannonullWhether the user is active. Omit to leave the active state unchanged on the replaced resource.
emailstringnonullPrimary email address. Optional.
externalIdstringnonullExternal id — your identity provider's stable id for this user. Optional.
firstNamestringnonullGiven (first) name. Optional; omit to leave unset on the replaced resource.
lastNamestringnonullFamily (last) name. Optional; omit to leave unset on the replaced resource.
userIdstringyesSCIM user id (resource id) to replace. From keeper_scim_list_users.
userNamestringyesSCIM userName — the user's unique login, typically their email address. Required.