Keeper Secrets Manager
Keeper Secrets Manager is a cloud secrets manager for DevOps and development teams, developed by Keeper Security, that removes API keys, database passwords, certificates and SSH keys source code and delivers them to applications and pipelines through SDKs and integrations with GitHub Actions, Jenkins, Terraform and Kubernetes. It uses zero-knowledge encryption and is licensed per user on an annual subscription, as an add-on to Keeper Business or Enterprise, or included in KeeperPAM.
What is Keeper Secrets Manager?
Keeper Secrets Manager is a cloud secrets manager for DevOps, security and development teams, developed by Keeper Security, that stores API keys, database passwords, certificates, SSH keys and service account credentials and delivers them to applications, scripts and CI/CD pipelines without writing them into source code. It is a fully managed service with the same zero-knowledge encryption as the Keeper vault: secrets are decrypted only on authorized devices and applications.
Keeper Secrets Manager works as a component of the Keeper Enterprise platform: the administrator enables it through a role policy in the console, and authorized users see a "Secrets Manager" tab in the vault, where they link shared folders to applications. There is no software to host, no VPC peering to configure and no additional infrastructure. The product solves secrets sprawl — credentials copied into configuration files, environment variables and Git repositories, with no owner, no rotation and no record of who accessed them.
Key features of Keeper Secrets Manager
Keeper Secrets Manager combines a secrets vault, DevOps integrations and access control:
- Native SDKs: libraries for Python, Java and Kotlin, JavaScript, .NET and Go read secrets at runtime, with no credential written into the application.
- CI/CD integrations: plugins and extensions for GitHub Actions, GitLab, Jenkins, Azure DevOps, Bitbucket, Octopus Deploy and Puppet inject secrets into the pipeline.
- Infrastructure as code and containers: a Terraform provider, an Ansible collection, a Docker image and runtime, and Kubernetes integration.
- CLI and PowerShell: the KSM CLI and the PowerShell module access secrets terminals, shell scripts and scheduled tasks.
- AI agents and IDEs: MCP integration for AI agents and plugins for VS Code, Cursor and JetBrains to access secrets directly the editor.
- Credential rotation: changes SSH keys, service accounts, API tokens and database passwords on a schedule or on an event, in the cloud and on-premises.
- Configuration storage: in the Python SDK, the client configuration can be kept in an Entrust HSM instead of a local file.
Benefits of Keeper Secrets Manager
Keeper Secrets Manager reduces the risk of repository leaks because the application fetches the secret at runtime: code and configuration files no longer contain the password, and an exposed Git commit reveals no credentials.
Changing credentials no longer breaks systems because the secret is updated in a single vault record, and every application and pipeline that consumes that record reads the new value on its next call.
Auditing is centralized because the console logs every secret access under role-based policies (RBAC), and events can flow to SIEM platforms, showing which application read which credential and when.
Who Keeper Secrets Manager is for
Keeper Secrets Manager serves DevOps and SRE engineers, developers, cloud architects and AppSec teams that need to remove credentials code. Typical scenarios: a team using GitHub Actions and Terraform to deploy to AWS that keeps access keys in repository variables; a company running applications on Kubernetes with database passwords in ConfigMaps; and an operation that already uses the Keeper password vault and wants PowerShell scripts and Jenkins jobs to read credentials the same vault.
What sets Keeper Secrets Manager apart
Keeper Secrets Manager uses the same vault and the same console as the enterprise password manager: machine secrets and people's passwords fall under the same policies, the same audit trail and the same SSO and SCIM provisioning. Encryption is zero-knowledge, and the service inherits the platform's certifications — SOC 2 Type 2, ISO 27001, 27017 and 27018 and FIPS 140-3. The product supports multi-cloud environments with AWS, Azure and Google Cloud and is already included in KeeperPAM, so you can start with secrets and move on to rotation, privileged sessions and VPN-less access without switching tools.
System requirements
Keeper Secrets Manager is SaaS and requires a Keeper Business or Enterprise license with the add-on, or a KeeperPAM license. Applications access secrets through the SDKs (Python, Java/Kotlin, JavaScript, .NET and Go), the KSM CLI, the PowerShell module or the REST API, Linux and Windows servers, Docker containers and Kubernetes clusters. Administrative access is through the web vault and the desktop app for Windows, macOS and Linux.
Keeper Secrets Manager editions and licenses
Keeper Secrets Manager is sold in two ways: as an add-on to Keeper Business and Keeper Enterprise licenses, purchased for the users who will manage secrets, or already included in the KeeperPAM license. Customers with the Secrets Manager add-on can move to the Privileged Access Manager add-on, which adds PAM features and, according to Keeper's documentation, unlimited API calls.
How much does Keeper Secrets Manager cost?
Keeper Secrets Manager is licensed per user, on an annual subscription, as an add-on to Keeper Business or Enterprise: what counts is the people enabled to use Secrets Manager through the role policy, not each application, server or pipeline that reads secrets. There is no single list price because the investment depends on sizing: number of Secrets Manager users, the existing base license (Business or Enterprise), the API call volume of your applications, a possible move to KeeperPAM and whether it is a new purchase, a renewal or an expansion.
Anyone who already has or plans to buy KeeperPAM does not need to buy Secrets Manager separately, because it is included. To buy Keeper Secrets Manager in Brazil, OSB Software scopes this with you, sends the commercial proposal, issues the invoice and delivers the licenses — request a quote to get the exact figure for your scenario.
Frequently asked questions
What is the difference between Keeper Secrets Manager and Keeper Password Manager? Keeper Password Manager stores credentials used by people; Keeper Secrets Manager delivers secrets to non-human identities such as applications, scripts, containers and CI/CD pipelines through SDKs and integrations.
Does Keeper Secrets Manager work with Terraform and Kubernetes? Yes. There is an official Terraform provider and Kubernetes integration, plus support for Docker, Ansible and the main CI/CD tools.
Is Keeper Secrets Manager installed on-premises? No. It is a fully managed cloud service, but the SDKs and the CLI run on on-premises servers and in any cloud, so it covers hybrid environments.
Do I need a Keeper license to use Secrets Manager? Yes. It is an add-on to Keeper Business or Enterprise, or it comes included in KeeperPAM.
Why buy Keeper Secrets Manager OSB Software?
OSB Software is an official Keeper Security partner in Brazil and supplies 100% genuine Keeper Secrets Manager licenses to companies, with Brazilian invoicing, local contracting in Portuguese and full legal compliance — the safe way to buy imported software under a Brazilian corporate entity, with no risk of irregular licensing.
When you buy Keeper Secrets Manager OSB Software, you get:
- Consultative, specialist support — specialists who size your per-user licensing to your actual operation, avoiding over- or under-buying.
- Fast, secure processes — purchase order to delivery of genuine licenses, traceable at every step.
- Dedicated commercial follow-up — quote to delivery and renewal, with advance notice before your license expires.
- Invoicing that fits your company — Brazilian invoicing and terms adapted to your corporate procurement process.
- Proven track record — thousands of customers served across Brazil.
If you are looking for where to buy Keeper Secrets Manager in Brazil with legal certainty and properly licensed imported software, request a quote: OSB Software delivers reliable technology, qualified support and a simple, transparent purchase.
Not sure which software
you need?
Tell us about your need and our team helps you choose the ideal solution — from over 10,000 options in our catalog.