Ellipse Gradient for Header

Keeper Security Integration Guide

Keeper Security integrates with enterprise systems through product-specific REST APIs, provisioning interfaces, event reporting, Secrets Manager services, and identity protocols.

Keeper Security integration options at a glance

Keeper Security provides product-specific integration surfaces across Keeper Enterprise, Keeper Secrets Manager, Keeper Commander, and Keeper Connection Manager. REST APIs support administration, provisioning, reporting, and programmatic secret access. SCIM supports selected multi-user and group provisioning scenarios, while event and reporting interfaces can support audit and security synchronization; universal webhooks are not confirmed for every object. Record attachments are available in supported product and API contexts. Martini can consume these APIs, authenticate with environment-managed credentials or tokens, schedule polling workflows, map Keeper JSON data, retrieve secrets transiently, and expose controlled APIs for downstream applications.

Integration pointSupported by Keeper Security?Common use casesHow Martini supports it
REST APIsYesKeeper documents product-specific APIs for enterprise administration, provisioning, reporting, and Secrets Manager use cases.Martini can consume Keeper REST endpoints, map JSON responses, orchestrate dependent calls, and expose a controlled API to downstream systems.
Webhooks and outbound callbacksLimitedKeeper provides event and reporting capabilities, but universal push delivery for every user, team, role, record, or shared-folder change is not confirmed.Martini can receive a supported callback where available; otherwise it can poll the applicable event or reporting interface with a scheduler and durable cursor.
Bulk, asynchronous, and batch APIsLimitedSCIM and enterprise provisioning support multi-user and group operations, but a universal bulk API for all Keeper objects was not confirmed.Martini can process bounded batches, paginate requests, checkpoint progress, and retry safe operations without assuming a single full-enterprise export.
File and attachment APIsLimitedKeeper records may contain attachments, with access dependent on the product, SDK or endpoint, record permissions, and required operation.Martini can orchestrate supported metadata and file operations, transform associated data, and apply product-specific permission checks.
AuthenticationYesKeeper uses product-specific enterprise credentials, SCIM bearer tokens, Secrets Manager one-time tokens, encrypted configurations, and permission models.Martini stores credentials, tokens, and configuration in environment-level secrets and applies them through workflow API requests without embedding sensitive values.
SDKs and command-line toolingYesKeeper provides SDKs for supported Secrets Manager and administrative use cases, and Keeper Commander supports administrative automation.Martini should prefer documented HTTP APIs and can use custom JVM-compatible logic only when a supported API or protocol cannot meet the requirement.
Database accessNoKeeper does not expose a general-purpose customer database connection for integration.Martini can retrieve supported event, audit, reporting, and API data instead of connecting directly to a Keeper database.

How Keeper Security exposes data and business events

Keeper Security REST APIs

Keeper documents product-specific REST API surfaces for enterprise administration, provisioning, reporting, and Secrets Manager operations. The available resources and authentication model depend on the selected Keeper product.

Martini implementation pattern

Martini implementation pattern: Martini authenticates with the product-specific credential or configuration, invokes the relevant Keeper endpoint, parses the response, maps it into a canonical model, and orchestrates downstream writes or API responses. Credentials remain in environment-level secrets.

Implementation sequence

Load the product-specific Keeper configuration from secure environment secrets
Authenticate the Martini workflow using the applicable Keeper credential or token
Invoke the required Keeper REST operation
Validate the response and map Keeper JSON to the target model
Apply authorization, reconciliation, and business rules
Write the result and record an auditable integration outcome

Keeper Security event reporting

Keeper provides event and reporting capabilities for selected administrative, security, account, device, record, and Secrets Manager activity. Coverage and delivery model are product- and event-specific rather than a universal webhook stream.

Martini implementation pattern

Martini implementation pattern: A scheduled workflow polls the applicable event or reporting interface when push delivery is unavailable, stores a durable cursor or timestamp, enriches events with current object metadata when necessary, and advances the checkpoint only after downstream delivery succeeds.

Implementation sequence

Start the scheduled event-reporting workflow
Load the last successful event cursor or timestamp
Retrieve the next page of Keeper events
Normalize event types and identifiers
Enrich events with approved user, team, or node data
Deliver events to the monitoring or governance platform and commit the checkpoint

Keeper Security provisioning

Keeper supports SCIM and enterprise provisioning scenarios for selected multi-user and group operations. These interfaces are appropriate for lifecycle synchronization but do not represent a universal bulk API for every Keeper object.

Martini implementation pattern

Martini implementation pattern: Martini receives an upstream lifecycle change, resolves the target Keeper node, team, or role, invokes the supported provisioning operation, and records the external-to-Keeper identifier mapping. Dependent assignments are sequenced to account for eventual consistency.

Implementation sequence

Receive the upstream user or group lifecycle change
Normalize identifiers, email addresses, status, and organizational values
Resolve the Keeper node, team, and role scope
Submit the supported provisioning operation
Verify the resulting Keeper state where required
Store identifiers and retry only safe transient failures

Keeper Secrets Manager APIs and SDKs

Keeper Secrets Manager supports programmatic access to machine credentials and secrets through one-time bootstrap tokens, encrypted configuration, service APIs, and supported SDKs. Access remains subject to application and record permissions.

Martini implementation pattern

Martini implementation pattern: Martini initializes the approved Secrets Manager configuration, retrieves a specific secret for a downstream operation, prevents sensitive values from entering logs or responses, and returns only the business result. Custom JVM-compatible logic is reserved for cases not covered by a supported HTTP API or protocol.

Implementation sequence

Start the workflow from an API, schedule, or event trigger
Load the encrypted Keeper Secrets Manager configuration securely
Retrieve only the approved secret or record fields
Use the secret for the downstream API or database request
Suppress secret values from logs, errors, and response payloads
Complete the business operation and minimize sensitive workflow state

Common Keeper Security integration patterns

Pattern 1: Provision employees into Keeper

When to use this pattern

Use this pattern when an HR or identity platform is authoritative for employee lifecycle data and Keeper users, teams, or roles must be updated consistently. It supports onboarding, changes, and offboarding while preserving stable identifiers and explicit deprovisioning rules.

Integration direction
Workday
Martini
Keeper Security
Example Mapping
Keeper Security FieldCanonical FieldTarget Field
employeeIdexternalUserIdKeeper user identifier mapping
workEmailemailKeeper user email
employmentStatuslifecycleStatusKeeper user status
departmentorganizationalUnitKeeper node or team
Martini implementation pattern

Martini receives the lifecycle change, validates required identity attributes, resolves the target node and team, applies create, update, or deactivate rules, and stores the resulting Keeper identifier. Idempotency checks prevent duplicate users, while transient failures are retried and authorization or validation errors are routed for review.

Martini capabilities used
  • workflows
  • API consumption
  • data mapping
  • business rules
  • error handling

Pattern 2: Reconcile Keeper users and teams with a directory

When to use this pattern

Use this pattern when Keeper administration must be compared with an authoritative directory or identity platform. It is suitable for periodic reconciliation, membership drift detection, and controlled remediation without removing manually managed assignments unintentionally.

Integration direction
Keeper Security
Martini
Microsoft Entra ID
Example Mapping
Keeper Security FieldCanonical FieldTarget Field
userIdsourceUserIdid
teamIdgroupIdgroupId
statusaccountStatusaccountEnabled
teamMembershipsgroupMembershipsmemberOf
Martini implementation pattern

A scheduled Martini workflow retrieves paginated Keeper Users and Teams, compares them with directory state using stable identifiers, classifies additions, changes, and removals, and applies only approved corrections. Checkpoints, bounded batches, and reconciliation reports limit risk during large synchronizations.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination and checkpointing
  • data mapping
  • conditional routing

Pattern 3: Retrieve secrets for downstream application workflows

When to use this pattern

Use this pattern when an integration needs an API credential, database password, certificate, or other machine secret at runtime without hard-coding it in Martini source or passing it through business payloads.

Integration direction
Keeper Security
Martini
Application API
Example Mapping
Keeper Security FieldCanonical FieldTarget Field
recordUidsecretReferencecredentialReference
loginclientIdauthorization.clientId
passwordclientSecretauthorization.clientSecret
customFieldsconnectionPropertiesrequest configuration
Martini implementation pattern

Martini loads the approved Secrets Manager configuration, retrieves only the necessary record fields, calls the downstream API, and suppresses the secret from logs, responses, and error messages. Permission failures are distinguished from transient service failures, and the workflow returns only the business result.

Martini capabilities used
  • workflows
  • secrets management
  • API consumption
  • data mapping
  • security controls
  • error handling

Pattern 4: Route Keeper security events to Splunk

When to use this pattern

Use this pattern when security, authentication, administrative, or vault activity must be centralized for monitoring, investigation, or compliance reporting. It uses polling when the required Keeper event type does not provide a supported push callback.

Integration direction
Keeper Security
Martini
Splunk
Example Mapping
Keeper Security FieldCanonical FieldTarget Field
eventTypeauditActionevent.action
usernameactorIdentityuser.name
timestampeventTimeevent.created
objectUidresourceIdresource.id
Martini implementation pattern

Martini polls the selected Keeper event or reporting interface with a durable cursor, normalizes and enriches each event, and forwards it to Splunk. The cursor advances only after successful delivery, while duplicate detection and retry handling accommodate repeated or out-of-order events.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • data transformation
  • checkpointing
  • error handling
  • monitoring

Applications commonly integrated with Keeper Security

Keeper Security can participate in identity lifecycle, security reporting, service management, and privileged-access workflows. The exact direction and object coverage depend on the deployed Keeper product, permissions, and the selected API or provisioning interface.

Application Scenario Direction Martini Pattern
Microsoft Entra ID Synchronize users and groups, support identity workflows, and automate onboarding and offboarding. Microsoft Entra ID → Martini → Keeper Security Martini receives lifecycle changes, normalizes identity attributes, resolves the Keeper node, team, or role, and invokes the applicable provisioning interface with retry and duplicate protection.
Active Directory Align Keeper users and group membership with the corporate directory structure. Active Directory → Martini → Keeper Security A scheduled or event-triggered Martini workflow retrieves directory changes, maps stable identifiers and status values, and applies controlled Keeper provisioning operations.
Okta Coordinate centralized identity, SSO, and lifecycle-management processes for Keeper users. Okta → Martini → Keeper Security Martini consumes Okta lifecycle or provisioning data, maps it to Keeper user and team operations, and records the resulting Keeper identifiers and status.
Splunk Centralize Keeper security and administrative events for detection, investigation, and compliance reporting. Keeper Security → Martini → Splunk Martini polls the applicable Keeper event or reporting interface using a durable cursor, normalizes event data, enriches it with metadata, and forwards it after successful checkpoint handling.
ServiceNow Connect access requests, privileged-credential workflows, and operational status with Keeper-managed secrets and permissions. ServiceNow → Martini → Keeper Security Martini receives an approved ServiceNow request, validates authorization and scope, invokes Keeper APIs, and returns status and audit information to the originating workflow.
Jira Associate security or access-management work items with Keeper provisioning and exception workflows. Jira → Martini → Keeper Security Martini processes approved Jira changes, applies business rules, performs the corresponding Keeper operation, and updates the issue with a controlled result or exception.
Workday Use authoritative employee data to drive joiner, mover, and leaver processes. Workday → Martini → Keeper Security Martini consumes Workday employee changes, maps employment status and organizational attributes, resolves Keeper assignments, and sequences dependent provisioning operations.

How to build a Keeper Security integration in Martini

Objective

Choose the Keeper product and API surface, then configure its credentials, tokens, or encrypted Secrets Manager configuration in Martini environment secrets.

Instructions in Martini

  • Identify whether the workflow targets Keeper Enterprise, Keeper Secrets Manager, provisioning, reporting, or another product surface.
  • Store credentials, SCIM bearer tokens, one-time tokens, and configuration data outside workflow source.
  • Confirm node, role, team, shared-folder, record, and application permissions.

Objective

Select an event, supported callback, API trigger, or scheduled workflow based on the delivery model confirmed for the required Keeper operation.

Instructions in Martini

  • Use a supported callback only for event types that provide one.
  • Use a scheduler for event or reporting APIs when push delivery is unavailable.
  • Define the cursor, timestamp, or external lifecycle identifier used to resume processing.

Objective

Call the applicable Keeper REST, provisioning, reporting, or Secrets Manager interface and retrieve only the objects and fields required by the process.

Instructions in Martini

  • Authenticate with the product-specific mechanism.
  • Paginate collections and use bounded batches for larger synchronizations.
  • Avoid retrieving or logging sensitive record fields unless they are required.

Objective

Coordinate lookups, dependent Keeper operations, target-system calls, and checkpoint updates in a maintainable Martini workflow.

Instructions in Martini

  • Resolve nodes, teams, roles, record permissions, and stable identifiers before writes.
  • Sequence operations that may be eventually consistent.
  • Commit cursors only after downstream delivery succeeds.

Objective

Convert Keeper Users, Teams, Records, events, and other product-specific structures into canonical and target-system models.

Instructions in Martini

  • Map stable IDs rather than relying only on display names or email addresses.
  • Handle record types, custom fields, and attachments according to the selected API.
  • Validate required fields before provisioning or updating a target.

Objective

Enforce authorization boundaries, deprovisioning policy, secret-handling controls, and business decisions before changing Keeper or downstream systems.

Instructions in Martini

  • Protect manually managed assignments where required.
  • Reject unauthorized node, team, role, record, or shared-folder changes.
  • Mask sensitive values in exceptions and prevent them from entering responses.

Common Keeper Security data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
UsersProvision, update, deactivate, and reconcile Keeper user membership and attributes.Microsoft Entra ID, Active Directory, Okta, WorkdayMartini maps stable external identifiers, status, email, node, team, and role values, then applies idempotent provisioning and deprovisioning rules.
TeamsManage group membership, shared-folder access, and delegated administration.Microsoft Entra ID, Active Directory, Okta, ServiceNowMartini compares desired and actual membership, protects manually managed assignments where required, and processes changes in bounded batches.
NodesOrganize enterprise users and apply administrative scope and policies.Identity platforms, governance systems, internal directoriesMartini resolves node identifiers before provisioning and validates that the calling credential has the required scope.
RolesApply permissions, policies, and administrative responsibilities to users or teams.Identity governance platforms, ServiceNow, compliance systemsMartini maps approved role assignments, sequences dependent operations, and reports authorization or validation failures.
RecordsStore passwords, credentials, secure notes, and other secret fields in Keeper vaults.Application workflows, databases, APIs, service-management platformsMartini retrieves only approved records and fields, uses secrets transiently, masks sensitive values, and avoids logging or returning plaintext secrets.
Shared FoldersControl shared access to collections of Keeper records for users and teams.Identity platforms, access-request systems, governance platformsMartini validates team and permission scope, sequences assignments after prerequisite operations, and handles eventual consistency with controlled retries.

Authentication and security considerations

Product-specific authentication

Keeper authentication varies by product and API. Enterprise APIs use provisioned administrative credentials or tokens, SCIM uses bearer tokens, and Keeper Secrets Manager uses one-time bootstrap tokens followed by encrypted configuration and service authentication.

Least-privilege authorization

Access depends on enterprise nodes, roles, teams, shared folders, record permissions, and Secrets Manager application scope. Martini workflows should request only the permissions required for the integration.

Secret handling

  • Store Keeper credentials, tokens, and configuration in Martini environment secrets.
  • Do not embed credentials in workflow source, mappings, static payloads, or logs.
  • Mask sensitive fields in errors and return only business results from exposed APIs.

Operational considerations for Keeper Security integrations

Pagination and checkpoints

User, team, record, event, and audit collections may be paginated. Store a durable page cursor, event cursor, or timestamp and advance it only after downstream processing succeeds.

Rate limits and retries

Confirm limits for the selected Keeper API. Use bounded concurrency, exponential backoff, and Retry-After when provided. Separate authentication, authorization, validation, throttling, and transient errors.

Idempotency and consistency

Use Keeper user IDs, record UIDs, team IDs, or external directory IDs rather than display names alone. Sequence user, team, role, and shared-folder operations because administrative changes may become consistent asynchronously.

Schema and event changes

Record types, custom fields, permissions, and event payloads can vary. Validate required fields, tolerate duplicate or out-of-order events, and retrieve current object state when an event does not contain enough detail.

Testing and environments

Separate development, test, and production Keeper nodes, applications, tokens, and records where possible. Test permission failures, throttling, retries, duplicate events, deprovisioning, and attachment behavior before production deployment.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration across product surfaces

Keeper Enterprise, provisioning, event reporting, and Secrets Manager expose different capabilities. Martini provides a single workflow layer for coordinating these APIs with identity platforms, monitoring systems, service-management tools, and application endpoints.

Maintainable transformation and rules

Martini maps product-specific Keeper objects into canonical models, applies business rules, sequences dependent operations, and supports reusable integration logic instead of scattering behavior across scripts.

Operational control

Workflows can implement scheduling, checkpointing, bounded retries, exception handling, monitoring, and controlled API exposure. This makes synchronization and secret-retrieval processes easier to operate than isolated point-to-point scripts.

Secure integration boundaries

Environment-managed secrets, controlled API endpoints, least-privilege workflow design, and sensitive-field handling help keep Keeper credentials and vault data out of source code, logs, and downstream responses.

Frequently asked questions

How can Keeper Security be integrated with enterprise systems?

Keeper Security can be integrated through product-specific REST APIs, enterprise provisioning interfaces such as SCIM for supported user and group operations, event and reporting interfaces, Secrets Manager APIs or SDKs, and selected identity and file protocols. The appropriate method depends on whether the target is Keeper Enterprise, Keeper Secrets Manager, Keeper Commander, or another product.

Can Martini integrate with Keeper Security?

Yes. Martini can consume Keeper’s documented REST and product APIs, orchestrate provisioning and reporting workflows, retrieve permitted Secrets Manager values, and synchronize selected event data. No native Martini Keeper Security connector is documented in the supplied research, so the integration uses confirmed Keeper endpoints and authentication methods.

Do I need a connector to integrate Keeper Security with Martini?

No. A dedicated Keeper Security connector is not required. Martini can integrate using Keeper’s native REST APIs, provisioning interfaces, event and reporting mechanisms, Secrets Manager services, supported file operations, and product-specific authentication methods.

Is there any extra Lonti cost to integrate Keeper Security with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Keeper Security. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Keeper, cloud infrastructure, identity providers, or other third-party systems depending on subscription, usage, and deployment model.

Which Keeper Security integration methods should architects use?

Use the REST API or the product-specific documented API for administration, reporting, and Secrets Manager operations. Use SCIM or supported provisioning interfaces for lifecycle and group synchronization. Use event reporting for audit and security data, but confirm coverage and delivery behavior for each event type before designing a push-based integration.

Can Keeper Security send events or webhooks to Martini?

Keeper provides event and reporting capabilities, but universal webhooks for every Keeper object are not confirmed. For supported push callbacks, Martini can receive and process the notification. Where push delivery is unavailable, a scheduled Martini workflow can poll the relevant event or reporting interface using a durable cursor.

How does Martini synchronize Keeper Security data?

Martini can retrieve paginated Users, Teams, Nodes, Roles, Records, Shared Folders, and event data where the selected product and permissions expose them. It maps stable identifiers to a canonical model, compares desired and actual state, applies approved changes, checkpoints progress, and handles deprovisioning and duplicate events explicitly.

How does Martini handle Keeper Security errors, retries, and sensitive data?

Martini can distinguish authentication, authorization, validation, throttling, and transient service failures; apply bounded retries and backoff; and route permanent exceptions for review. Implementations should use idempotent identifiers, respect rate limits, avoid logging secret fields, and prevent plaintext credentials from appearing in API responses or error messages.