Skip to main content
Connector guides

Connect Keeper Security

Keeper Security is a zero-knowledge password manager and privileged-access platform. StackJack connects to Keeper's hosted REST surfaces so your AI assistant can provision personal-vault licenses,…

Written By Christopher Scaminaci

Last updated 6 days ago

Keeper Security is a zero-knowledge password manager and privileged-access platform. StackJack connects to Keeper's hosted REST surfaces so your AI assistant can provision personal-vault licenses, manage MSP customer accounts, and provision users and teams.

Because Keeper's vault contents are zero-knowledge (encrypted so that not even Keeper can read them), StackJack does not touch vault records, secrets, or passwords. Instead it drives the three administrative REST surfaces Keeper exposes to partners:

  • Provisioning — issue Keeper Family and Student personal-vault licenses to end users.
  • MSP Account Management — for Keeper MSP/distributor partners: list managed accounts and products, read seat usage, and move accounts through the trial → paid → cancel lifecycle.
  • SCIM 2.0 — provision, update, enable/disable, and deprovision users, and manage Teams (SCIM Groups) in a Keeper enterprise node.

Connecting Keeper to StackJack gives your AI assistant a focused family of keeper_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack.

Three independent credential sets

Keeper's three surfaces authenticate separately, and each is optional — configure only the ones you use. A tenant that only issues Family plans needs the Provisioning credentials alone; the MSP and SCIM tools will report that they are "not configured" and take no action.

SurfaceWhat you provideWhere it comes from
ProvisioningPartner Name + Partner SecretIssued out-of-band by your Keeper account representative through a shared Keeper record. There is no self-serve key page.
MSP Account ManagementMSP Consumer Key + MSP SecretProvided by Keeper for MSP/distributor partners. Separate from the Partner Name/Secret.
SCIM 2.0SCIM token + node idGenerated for an enterprise node in the Keeper Admin Console under Provisioning → Add Method → SCIM. The node id is the final segment of the generated SCIM URL.

Each credential set only unlocks its own tools. If a tool reports the surface is not configured, add that surface's credentials on the Keeper connector — the others keep working unchanged.

Regions and custom hosts

Most tenants use the default US host (https://keepersecurity.com). StackJack shows a Region selector; choose a non-US region only if your Keeper tenant is hosted in the EU, Australia, Canada, Japan, or the US Government Cloud. Keeper publishes the matching Admin Console addresses for its data centers. StackJack's US route is verified end to end; the other choices follow those published hosts but have not all been exercised with live tenant credentials.

If Keeper supplied a custom, self-hosted, or on-prem endpoint that is not one of the listed data-center hosts, choose Other (custom host) and enter its full host URL. StackJack accepts a well-formed https:// origin with no path, query, fragment, or embedded username/password. This is a StackJack routing capability, not a claim that every Keeper customer can deploy Keeper that way; use only the endpoint Keeper provided for your deployment. Changing the host later requires re-entering the credentials for each configured surface.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In Keeper: gather the credential set(s) for the surfaces you plan to use — a Partner Name/Secret from your Keeper rep, an MSP Consumer Key/Secret for MSP tools, and/or a SCIM token + node id from the Admin Console.
  • Know your region if your Keeper tenant is not on the default US host.

Step 1 — Gather your Keeper credentials

  1. Provisioning: ask your Keeper account representative to issue a Partner Name and Partner Secret for API license provisioning. These arrive out-of-band through a Keeper record.
  2. MSP (optional): if you manage customer accounts as a Keeper MSP/distributor, ask Keeper for your MSP Consumer Key and MSP Secret.
  3. SCIM (optional): in the Keeper Admin Console, select the enterprise node StackJack should manage. Open Provisioning → Add Method → SCIM, choose Create Provisioning Token, and copy the generated URL and token. The node id is the final segment of the URL (.../api/rest/scim/v2/<node_id>). Keeper's current provisioning flow creates a node-scoped SCIM URL and token for this connection.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Select the Keeper Security tile to open its details drawer. Use How To Connect for the inline checklist, then choose Configure in the drawer footer.
  3. Choose your Region (leave the default US host unless your Keeper tenant is hosted elsewhere).
  4. Fill in the credential set(s) you use — Provisioning, MSP, and/or SCIM. Leave the fields for surfaces you don't use blank.
  5. Click Save.

What happens when you save

  • Every credential is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure Keeper Security, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack runs save-time validation without changing Keeper data: if SCIM is configured it reads the SCIM service-provider config; otherwise it reads MSP products. A provisioning-only setup is stored as unverified because its only meaningful probe would create a real license.
  • The form collapses but the drawer stays open. A successful probe shows Connected. A failed probe keeps the credential and shows Needs Attention with the upstream reason and a Re-test action.

Plans and available tools

  • Free includes reads for MSP accounts, products, current/monthly seat usage, users and groups, plus the SCIM service-provider config, resource types, and schemas.
  • Pro adds Family and Student license issuance; MSP account lifecycle actions (create trial, convert to paid, reactivate, cancel, remove); and SCIM writes for users, batch operations, and Teams.

See the generated Keeper Security tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Current pricing and quotas are shown in the portal's Billing page and at checkout.

Provisioning creates real, billable licenses. keeper_provision_family_license and keeper_provision_student_license issue genuine 1-year Keeper licenses on your account. Even though the underlying call is read-shaped, these are write actions — they're Pro-tier and flagged so a consent-gating AI client prompts before running them. The recipient owns the resulting personal vault and sets their own Master Password; your enterprise does not manage it. Student licenses must use a secondary/alias email domain, not your primary domain.

SCIM delete is a lock, not an erase. Deleting a SCIM user locks the account rather than permanently destroying the vault (Keeper retains it per its account-transfer policy). Deleting a SCIM Group removes the corresponding Keeper Team, but not its member users. Scope your AI's access to the delete and disable tools deliberately using the tool selections on the MCP Setup page and the Permissions page.

Rate limits

Keeper publishes no numeric quota for these APIs. StackJack applies a conservative per-tenant pace (about 60 requests per minute) and backs off on any 429, so a burst is slowed rather than sent all at once. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Rotating or replacing the credentials

Each surface's credentials are its recovery secret. If a Partner Secret, MSP Secret, or SCIM token is rotated or revoked in Keeper, the matching tools stop working until you update them. Select Keeper Security in Connectors, choose Update, enter the replacement for the affected surface, and save. Blank secret fields preserve their stored values, so the other surfaces are unaffected.

Disconnecting Keeper Security

Use Disconnect in the Keeper Security drawer to delete StackJack's stored credential sets and stop future Keeper API calls. Disconnecting does not revoke Partner, MSP, or SCIM credentials in Keeper and does not undo licenses or account changes already made. Revoke each credential in Keeper separately if it should no longer work anywhere.

For a Free subscription, the confirmation can also remove Keeper tools from tool lists. A paid connector plan remains separate billing state; use Manage on Billing on the connector card if you also want to end it — it opens this connector's removal dialog on the Billing page. A legacy website subscription reads Cancel Plan instead.

Several customers

Some MSPs need one Keeper Security connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.

Troubleshooting

SymptomLikely causeWhat to do
A tool reports the surface is "not configured"That credential set (Provisioning, MSP, or SCIM) hasn't been enteredAdd the missing surface's credentials in Connectors → Keeper Security → Configure
Every provisioning call is rejectedWrong Partner Secret — the per-recipient authorization is derived from itRe-check the Partner Name and Partner Secret issued by your Keeper representative
MSP tools fail while SCIM works (or vice-versa)The failing surface's credentials are wrong, expired, or for a different regionRe-enter that surface's credentials and confirm the selected region matches your Keeper tenant
SCIM tools return unauthorizedThe SCIM bearer token was rotated in the Admin ConsoleOn the same enterprise node, create a fresh token under Provisioning → Add Method → SCIM and update it in StackJack
Write or provisioning tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the Keeper Security connector plan and check your tool selections on the MCP Setup page
A student license was rejectedThe student email used your enterprise's primary domainRe-issue with a secondary/alias domain (for example students.university.edu)

Keeper Security tools

keeper_ · 30 tools · Free 14 · Pro 16

Provisioning

ToolWhat it does
keeper_provision_family_license
Pro · Destructive
Provision a 1-year Keeper Family plan license (Keeper Family + BreachWatch dark-web monitoring + 10GB encrypted file storage) for an end user's personal vault.
keeper_provision_student_license
Pro · Destructive
Provision a 1-year Keeper Unlimited student plan license (full password manager + BreachWatch + 10GB encrypted file storage) for a student's personal vault (product_type=4 is applied automatically).

MSP Account Management

ToolWhat it does
keeper_msp_activate_expired
Pro · Destructive
Reactivate an expired MSP managed account, returning it to an active paid state.
keeper_msp_cancel_paid_account
Pro · Destructive
Cancel the paid subscription for an MSP managed account.
keeper_msp_convert_to_paid
Pro · Destructive
Convert an MSP managed account from trial to a paid subscription.
keeper_msp_create_trial_account
Pro · Write
Create a new trial MSP managed account under this vendor.
keeper_msp_get_current_usage
Free · Read-only
Get the CURRENT seat/license usage for MSP managed accounts.
keeper_msp_get_monthly_usage
Free · Read-only
Get HISTORICAL monthly seat/license usage for an MSP managed account.
keeper_msp_list_accounts
Free · Read-only
List the managed accounts under this MSP/distributor vendor.
keeper_msp_list_products
Free · Read-only
List the MSP products/plans available to this vendor (the license SKUs you can allocate to managed accounts).
keeper_msp_remove_account
Pro · Destructive
Remove a pending or conflicting MSP managed account.

SCIM 2.0 (Users & Teams)

ToolWhat it does
keeper_scim_bulk
Pro · Destructive
Execute a SCIM 2.0 bulk request (POST /Bulk) against the Keeper enterprise node.
keeper_scim_create_group
Pro · Write
Create a SCIM Group — a Keeper Team — with the given displayName and, optionally, an initial set of member user ids (from keeper_scim_list_users).
keeper_scim_create_user
Pro · Write
Provision (invite) a new user into the Keeper enterprise node.
keeper_scim_delete_group
Pro · Destructive
Delete a SCIM Group — permanently removing the Keeper Team (its member users are not deleted, only the team and its shared-folder assignments).
keeper_scim_delete_user
Pro · Destructive
Deprovision a SCIM user.
keeper_scim_get_group
Free · Read-only
Get a single SCIM Group (Keeper Team) by its id (from keeper_scim_list_groups), including its member list.
keeper_scim_get_resource_type_group
Free · Read-only
Get the SCIM ResourceType definition for Group (GET /ResourceTypes/Group) — its endpoint (/Groups) and schema.
keeper_scim_get_resource_type_user
Free · Read-only
Get the SCIM ResourceType definition for User (GET /ResourceTypes/User) — its endpoint (/Users), core schema, and any schema extensions.
keeper_scim_get_resource_types
Free · Read-only
Get the SCIM ResourceTypes exposed by the Keeper node (User, Group) and their endpoints and schemas.
keeper_scim_get_schema
Free · Read-only
Get a single SCIM schema definition by its URN (GET /Schemas/{id}), e.g. urn:ietf:params:scim:schemas:core:2.0:User.
keeper_scim_get_schemas
Free · Read-only
Get the SCIM Schemas advertised by the Keeper node — the attribute definitions for the User and Group resources.
keeper_scim_get_service_provider_config
Free · Read-only
Get the SCIM ServiceProviderConfig for the Keeper node — the SCIM features Keeper's endpoint supports (patch, bulk, filter, changePassword, sort, etc.).
keeper_scim_get_user
Free · Read-only
Get a single SCIM user by its Keeper user id (the SCIM resource id from keeper_scim_list_users).
keeper_scim_list_groups
Free · Read-only
List SCIM Groups (which map to Keeper Teams) in the enterprise node, optionally narrowed by a SCIM filter (e.g. displayName eq "Engineering").
keeper_scim_list_users
Free · Read-only
List SCIM-provisioned users in the Keeper enterprise node, optionally narrowed by a SCIM filter (e.g. userName eq "user@example.com").
keeper_scim_patch_user
Pro · Destructive
Apply an arbitrary SCIM 2.0 PatchOp (PATCH /Users/{id}) to a user — the general form of keeper_scim_set_user_active.
keeper_scim_set_user_active
Pro · Destructive
Enable or disable (lock) a SCIM user via a targeted PatchOp on the active attribute — the surgical alternative to keeper_scim_update_user.
keeper_scim_update_group_members
Pro · Destructive
Add or remove members of a SCIM Group (Keeper Team) with a PatchOp.
keeper_scim_update_user
Pro · Destructive
Full-replace (SCIM PUT) an existing user's attributes.