.png)
Keeper Security Integration Guide
Keeper Security integrates with enterprise systems through product-specific REST APIs, provisioning interfaces, event reporting, Secrets Manager services, and identity protocols.
Keeper Security integration options at a glance
Keeper Security provides product-specific integration surfaces across Keeper Enterprise, Keeper Secrets Manager, Keeper Commander, and Keeper Connection Manager. REST APIs support administration, provisioning, reporting, and programmatic secret access. SCIM supports selected multi-user and group provisioning scenarios, while event and reporting interfaces can support audit and security synchronization; universal webhooks are not confirmed for every object. Record attachments are available in supported product and API contexts. Martini can consume these APIs, authenticate with environment-managed credentials or tokens, schedule polling workflows, map Keeper JSON data, retrieve secrets transiently, and expose controlled APIs for downstream applications.
Common Keeper Security integration patterns
Common Keeper Security data objects used in integrations
Authentication and security considerations
Product-specific authentication
Keeper authentication varies by product and API. Enterprise APIs use provisioned administrative credentials or tokens, SCIM uses bearer tokens, and Keeper Secrets Manager uses one-time bootstrap tokens followed by encrypted configuration and service authentication.
Least-privilege authorization
Access depends on enterprise nodes, roles, teams, shared folders, record permissions, and Secrets Manager application scope. Martini workflows should request only the permissions required for the integration.
Secret handling
- Store Keeper credentials, tokens, and configuration in Martini environment secrets.
- Do not embed credentials in workflow source, mappings, static payloads, or logs.
- Mask sensitive fields in errors and return only business results from exposed APIs.
Operational considerations for Keeper Security integrations
Pagination and checkpoints
User, team, record, event, and audit collections may be paginated. Store a durable page cursor, event cursor, or timestamp and advance it only after downstream processing succeeds.
Rate limits and retries
Confirm limits for the selected Keeper API. Use bounded concurrency, exponential backoff, and Retry-After when provided. Separate authentication, authorization, validation, throttling, and transient errors.
Idempotency and consistency
Use Keeper user IDs, record UIDs, team IDs, or external directory IDs rather than display names alone. Sequence user, team, role, and shared-folder operations because administrative changes may become consistent asynchronously.
Schema and event changes
Record types, custom fields, permissions, and event payloads can vary. Validate required fields, tolerate duplicate or out-of-order events, and retrieve current object state when an event does not contain enough detail.
Testing and environments
Separate development, test, and production Keeper nodes, applications, tokens, and records where possible. Test permission failures, throttling, retries, duplicate events, deprovisioning, and attachment behavior before production deployment.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration across product surfaces
Keeper Enterprise, provisioning, event reporting, and Secrets Manager expose different capabilities. Martini provides a single workflow layer for coordinating these APIs with identity platforms, monitoring systems, service-management tools, and application endpoints.
Maintainable transformation and rules
Martini maps product-specific Keeper objects into canonical models, applies business rules, sequences dependent operations, and supports reusable integration logic instead of scattering behavior across scripts.
Operational control
Workflows can implement scheduling, checkpointing, bounded retries, exception handling, monitoring, and controlled API exposure. This makes synchronization and secret-retrieval processes easier to operate than isolated point-to-point scripts.
Secure integration boundaries
Environment-managed secrets, controlled API endpoints, least-privilege workflow design, and sensitive-field handling help keep Keeper credentials and vault data out of source code, logs, and downstream responses.