Connect Keeper Security
Keeper Security is a zero-knowledge password manager and privileged-access platform. StackJack connects to Keeper's hosted REST surfaces so your AI assistant can provision personal-vault licenses,…
Written By Christopher Scaminaci
Last updated 6 days ago
Keeper Security is a zero-knowledge password manager and privileged-access platform. StackJack connects to Keeper's hosted REST surfaces so your AI assistant can provision personal-vault licenses, manage MSP customer accounts, and provision users and teams.
Because Keeper's vault contents are zero-knowledge (encrypted so that not even Keeper can read them), StackJack does not touch vault records, secrets, or passwords. Instead it drives the three administrative REST surfaces Keeper exposes to partners:
- Provisioning — issue Keeper Family and Student personal-vault licenses to end users.
- MSP Account Management — for Keeper MSP/distributor partners: list managed accounts and products, read seat usage, and move accounts through the trial → paid → cancel lifecycle.
- SCIM 2.0 — provision, update, enable/disable, and deprovision users, and manage Teams (SCIM Groups) in a Keeper enterprise node.
Connecting Keeper to StackJack gives your AI assistant a focused family of keeper_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack.
Three independent credential sets
Keeper's three surfaces authenticate separately, and each is optional — configure only the ones you use. A tenant that only issues Family plans needs the Provisioning credentials alone; the MSP and SCIM tools will report that they are "not configured" and take no action.
Each credential set only unlocks its own tools. If a tool reports the surface is not configured, add that surface's credentials on the Keeper connector — the others keep working unchanged.
Regions and custom hosts
Most tenants use the default US host (https://keepersecurity.com). StackJack shows a Region selector; choose a non-US region only if your Keeper tenant is hosted in the EU, Australia, Canada, Japan, or the US Government Cloud. Keeper publishes the matching Admin Console addresses for its data centers. StackJack's US route is verified end to end; the other choices follow those published hosts but have not all been exercised with live tenant credentials.
If Keeper supplied a custom, self-hosted, or on-prem endpoint that is not one of the listed data-center hosts, choose Other (custom host) and enter its full host URL. StackJack accepts a well-formed https:// origin with no path, query, fragment, or embedded username/password. This is a StackJack routing capability, not a claim that every Keeper customer can deploy Keeper that way; use only the endpoint Keeper provided for your deployment. Changing the host later requires re-entering the credentials for each configured surface.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Keeper: gather the credential set(s) for the surfaces you plan to use — a Partner Name/Secret from your Keeper rep, an MSP Consumer Key/Secret for MSP tools, and/or a SCIM token + node id from the Admin Console.
- Know your region if your Keeper tenant is not on the default US host.
Step 1 — Gather your Keeper credentials
- Provisioning: ask your Keeper account representative to issue a Partner Name and Partner Secret for API license provisioning. These arrive out-of-band through a Keeper record.
- MSP (optional): if you manage customer accounts as a Keeper MSP/distributor, ask Keeper for your MSP Consumer Key and MSP Secret.
- SCIM (optional): in the Keeper Admin Console, select the enterprise node StackJack should manage. Open Provisioning → Add Method → SCIM, choose Create Provisioning Token, and copy the generated URL and token. The node id is the final segment of the URL (
.../api/rest/scim/v2/<node_id>). Keeper's current provisioning flow creates a node-scoped SCIM URL and token for this connection.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the Keeper Security tile to open its details drawer. Use How To Connect for the inline checklist, then choose Configure in the drawer footer.
- Choose your Region (leave the default US host unless your Keeper tenant is hosted elsewhere).
- Fill in the credential set(s) you use — Provisioning, MSP, and/or SCIM. Leave the fields for surfaces you don't use blank.
- Click Save.
What happens when you save
- Every credential is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure Keeper Security, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack runs save-time validation without changing Keeper data: if SCIM is configured it reads the SCIM service-provider config; otherwise it reads MSP products. A provisioning-only setup is stored as unverified because its only meaningful probe would create a real license.
- The form collapses but the drawer stays open. A successful probe shows Connected. A failed probe keeps the credential and shows Needs Attention with the upstream reason and a Re-test action.
Plans and available tools
- Free includes reads for MSP accounts, products, current/monthly seat usage, users and groups, plus the SCIM service-provider config, resource types, and schemas.
- Pro adds Family and Student license issuance; MSP account lifecycle actions (create trial, convert to paid, reactivate, cancel, remove); and SCIM writes for users, batch operations, and Teams.
See the generated Keeper Security tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Current pricing and quotas are shown in the portal's Billing page and at checkout.
Provisioning creates real, billable licenses.
keeper_provision_family_licenseandkeeper_provision_student_licenseissue genuine 1-year Keeper licenses on your account. Even though the underlying call is read-shaped, these are write actions — they're Pro-tier and flagged so a consent-gating AI client prompts before running them. The recipient owns the resulting personal vault and sets their own Master Password; your enterprise does not manage it. Student licenses must use a secondary/alias email domain, not your primary domain.
SCIM delete is a lock, not an erase. Deleting a SCIM user locks the account rather than permanently destroying the vault (Keeper retains it per its account-transfer policy). Deleting a SCIM Group removes the corresponding Keeper Team, but not its member users. Scope your AI's access to the delete and disable tools deliberately using the tool selections on the MCP Setup page and the Permissions page.
Rate limits
Keeper publishes no numeric quota for these APIs. StackJack applies a conservative per-tenant pace (about 60 requests per minute) and backs off on any 429, so a burst is slowed rather than sent all at once. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Rotating or replacing the credentials
Each surface's credentials are its recovery secret. If a Partner Secret, MSP Secret, or SCIM token is rotated or revoked in Keeper, the matching tools stop working until you update them. Select Keeper Security in Connectors, choose Update, enter the replacement for the affected surface, and save. Blank secret fields preserve their stored values, so the other surfaces are unaffected.
Disconnecting Keeper Security
Use Disconnect in the Keeper Security drawer to delete StackJack's stored credential sets and stop future Keeper API calls. Disconnecting does not revoke Partner, MSP, or SCIM credentials in Keeper and does not undo licenses or account changes already made. Revoke each credential in Keeper separately if it should no longer work anywhere.
For a Free subscription, the confirmation can also remove Keeper tools from tool lists. A paid connector plan remains separate billing state; use Manage on Billing on the connector card if you also want to end it — it opens this connector's removal dialog on the Billing page. A legacy website subscription reads Cancel Plan instead.
Several customers
Some MSPs need one Keeper Security connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.
Troubleshooting
Keeper Security tools
keeper_ · 30 tools · Free 14 · Pro 16
Provisioning
MSP Account Management
SCIM 2.0 (Users & Teams)
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team