Keeper Release Notes
152 release notes curated from 156 sources by the Releasebot Team. Last updated: Sep 29, 2026
- Sep 29, 2026
- Date parsed from source:Sep 29, 2026
- First seen by Releasebot:Sep 29, 2026
SSO Connect On-Prem 17.1.4
Keeper releases SSO Connect On-Prem 17.1.4 with critical security hardening, stronger Windows access controls, trusted SAML endpoint checks, and updated third-party libraries to improve stability and reduce risk.
Keeper SSO Connect On-Prem version 17.1.4 delivers critical security enhancements, administrative interface hardening, Windows environment access control improvements, and third-party library updates.
All administrators operating SSO Connect On-Prem instances are encouraged to upgrade to version 17.1.4.
Improvements
- KSC-535: Administrative Interface Security Hardening
Implemented comprehensive protections across all management endpoints to protect administrative configuration. - KSC-556: SAML Endpoint Hardening
Strengthened verifications on SAML authentication callbacks with trusted endpoints. - KSC-539: Windows File System Access Lockdown
Restricted file system permissions (ACLs) on Windows installations for SSO Connect configuration, log, and keystore directories to administrative and system service accounts only. - KSC-557: Third-Party Component & Dependency Updates
Upgraded underlying third-party dependencies to remediate reported component vulnerabilities and maintain a secure software supply chain. - Code Quality & Static Analysis Remediation
Addressed CodeQL security findings and performed code-level optimizations to improve stability and maintainability. - Information Disclosure Mitigation
Suppressed runtime server version banners from HTTP response headers.
Compatibility & Upgrade Notes
- Configuration Changes: No administrative configuration or IdP schema changes are required.
- Automatic ACL Updates (Windows): Upgrading on Windows automatically updates directory permissions on existing data and log folders.
- Deployment Validation: It is recommended to perform a test sign-in with your Identity Provider (e.g., Microsoft Entra ID / ADFS, Okta, PingFederate, Keycloak) after upgrading.
- Supported OS: Windows Server 2022/2025, Red Hat Enterprise Linux 6.8+, Ubuntu 16.04+, openSUSE 15.0+
- Java Runtime: Java 17 LTS
Update Instructions
If you are performing a regular update of SSO Connect On-Prem (from a recent version):
- Open the Admin Console and visit the privisioning tab of the node
- Download, unzip and run the installer
- Sep 28, 2026
- Date parsed from source:Sep 28, 2026
- First seen by Releasebot:Sep 28, 2026
Admin Console 17.11.0
Keeper releases Admin Console 17.11.0 with a new Integration Center and API Key Management for enterprise admins, plus richer reporting for KeeperAI and nodes, a new enforcement policy for personal and work email use, and UI, performance, localization, and bug fixes.
Integration Center & API Keys
Integration Center Hub
Added a dedicated Integration Center tab to the Admin Console, enabling administrators to discover, and search for enterprise connections across AI, SSO, SCIM, SIEM, IGA, SPM, ITSM, Developer Tools Keeper Services, and other key categories.
The new Integration Center displaying popular integrations categorized by service type.
Integration API Key Management
Introduced an API Keys sub-tab within the Integration Center, allowing administrators to generate, view, sort, and manage API keys for enterprise integrations directly within the Admin Console.
The API Keys tab displaying generated integration tokens with expiration dates and status indicators.
Enhancements to Advanced Reporting & Alerts Module (ARAM)
Parent Category Folders
The "Event Types" search filter now includes parent category folders, making it easier to find and select events for audit reporting.
Event Types search dropdown displaying parent category folders and filtered session event results.
Added "KeeperAI" Event Types
Added KeeperAI event type filters for granular Reporting to track: session recording status changes, session termination, threat-level session locking, and session unlocking.
Nodes and Reporting
Reporting now includes Node details for improved user activity tracking across enterprise nodes.
Improvements
- EM-7788: Added new Enforcement Policy within "Account Settings" to warn or block users from saving records with personal emails in business vaults, or work emails in personal vaults.
Bug Fixes
- EM-8003: Resolved an issue where long node names were truncated incorrectly in administrative selection views.
- EM-8512: Corrected an issue where team member lists failed to refresh automatically upon adding or removing users.
- EM-8721: Fixed a bug causing policy date range pickers to accept improperly formatted manual entries.
- EM-8930: Resolved display borders appearing incorrectly inside dropdown selector menus.
- EM-9092: Fixed missing toast notifications when performing bulk updates across user rows.
- EM-9102: Corrected an issue preventing proper error messages from displaying on failed invitation updates.
All of your release notes in one feed
Join Releasebot and get updates from Keeper and hundreds of other software products.
- Sep 24, 2026
- Date parsed from source:Sep 24, 2026
- First seen by Releasebot:Sep 25, 2026
Android Version 18.1
Keeper adds a major Android open beta with a new Session Management UI, JIT access approvals in notifications, passkey and password import, easier account switching, smarter password strength checks, stricter passkey validation, privacy-friendly sharing, and nested shared folder moves.
Available in Open Beta
Enhancements
AN-7922: Introduces a new Session Management UI that allows you to view and manage all devices connected to your account. From this new interface, you can see detailed information for each registered device, such as the specific model name, operating system, and last login time. You now have the power to remotely lock a device, log out active sessions, or completely remove old devices to keep your vault secure.
AN-9118: You can now respond to Just-in-Time access requests directly from your Android notification center. When a team member requests temporary privileged access, approvers see the requester's name, their justification, the related ticket number, and the requested duration, and can approve or deny the request without opening the app.
AN-9121: Easily import your passwords and passkeys directly into Keeper when transferring from another password manager app that supports Android's built-in credential transfer feature. This makes switching to Keeper faster and easier, since you no longer have to re-enter your saved logins by hand.
AN-9216: Implements the ability to switch accounts right from the Autofill window, without leaving the app you're filling in. Just tap the avatar icon, the same as in the main app and you’ll be presented with your account options. If account switching is restricted by your organization, you'll see a clear message along with the option to log out.
AN-8862: Payment cards, addresses, and phone numbers you save in your vault now use a newer, more flexible record format. Allowing for improvements when autofilling this important information.
AN-7840: The password strength meter shown when you create, edit, or view a record now uses a smarter scoring method that better reflects how easily a password could actually be guessed or cracked, rather than just counting character types. This gives you a more accurate picture of how strong your passwords really are.
AN-9327: The updated password strength meter also checks whether your password contains information already stored in that record, such as the title, website, username, or email address. If it does, your strength score is lowered, since reusing details like your account name or site name makes a password easier to guess.
AN-8111: Your Master Password strength meter now uses the same smarter scoring method used for record passwords, giving you a more accurate strength rating as you type. If your account administrator requires a minimum password strength, you'll see that requirement clearly.
AN-9179: A new setting lets you enable stricter validation when creating or using passkeys. Turning it on adds an extra layer of assurance that your passkeys meet a higher security bar.
AN-9328: To better protect your privacy, sharing screens now use your device's built-in contact picker instead of requesting ongoing access to your full contacts list. When adding people to a shared folder or record, you'll see a picker you can use to choose contacts on demand.
AN-9426: You can now move folders and records to a different location within your shared folder structure in the latest Nested Shared Folders update. This makes it easier to reorganize your vault as your sharing needs change.
Bugs
AN-8881: Addressed issues with privileged access records appearing incorrectly in Deleted Items.
AN-9436: Corrected an issue that allowed a privileged access record to be duplicated into a new record when you shouldn't have had permission to do so.
AN-9187: Fixed an issue where creating a passkey for Keeper from within WhatsApp did not work.
AN-9247: Addressed an Autofill compatibility issue affecting certain versions of the Brave browser.
AN-9278: Resolved an issue where Autofill incorrectly offered suggestions from the Samsung Contacts app, reducing unwanted or incorrect Autofill prompts.
AN-8938: Fixed an issue where Autofill prompted you to save a one-time Duo authentication code as if it were a password.
AN-9388: Corrected an issue on Samsung Browser where Autofill would activate but not actually fill in your saved information.
AN-9090: Addressed an issue where fields labeled "email or mobile number" did not trigger Autofill suggestions.
AN-9443: Fixed a crash that could occur on Xiaomi devices immediately after logging in through Autofill.
AN-9184: Addressed issues with how master password expiration was handled after upgrading the app.
AN-9292: Fixed an issue where the Reset Master Password screen did not limit the number of incorrect password attempts, and added clear messaging if you're temporarily blocked after too many failed tries.
AN-9072: Resolved a crash that could occur when rotating your screen during a password import and then returning to Keeper.
AN-9259: Fixed a crash that occurred when tapping the two-factor authentication screen while offline.
AN-7765: Corrected issues with how the duration of a two-factor authentication requirement was calculated and enforced.
AN-9321: Addressed an issue where canceling the authentication prompt on a one-time share link prevented the prompt from reappearing.
AN-9155: Resolved an issue where entering an incorrect password during password reset showed the wrong dialog message.
AN-8696: Resolved an issue where shared results and unrecognized results could overlap on the sharing screen.
AN-8945: Fixed an issue where the clear (X) button on the Full Name field in identity and payment records did not work correctly.
AN-8996: Addressed an issue where pinching to zoom in on a password caused bottom sheets to overlap on screen.
AN-8866: Corrected an issue where numbers in the numbered list view appeared inaccurate after opening and closing a record's detail view.
AN-8972: Fixed an issue where the empty vault screen was cut off on small screens.
AN-9250: Resolved an issue where the list of actions in the record history info panel was cut off.
AN-9234: Addressed an issue where too many automatic save attempts on required fields could cause the field to lose focus and prevent typing.
AN-9223: Fixed an issue where the "Add Files" shortcut let you bypass your organization's record creation restrictions.
AN-9390: Corrected an issue where you could duplicate a record in a shared folder even without permission to manage records in that folder.
AN-9492: Resolved an issue that prevented some deleted records inside shared folders from being restored from Deleted Items.
AN-9386: Fixed an issue where records shared directly with you inside a shared folder did not automatically appear for you.
AN-9314: Addressed a data handling issue affecting how record revisions are tracked internally.
AN-9158: Corrected an issue where date fields were not masked as expected when your organization had masking enforcement turned on.
AN-9093: Fixed a dropdown display issue on the Family Plan invite screen.
AN-9224: Resolved an issue that showed an incorrect number of available slots when inviting someone to your Family Plan.
AN-9337: Addressed an issue on the Family Plan Manage Users screen where sharing suggestions appeared unexpectedly and could cause the screen to become unresponsive.
AN-9142: Fixed an issue where accepting an account transfer request did not add the account to Keeper as expected.
AN-8708: Corrected a brief flash of the vault screen that occurred when switching between the login and create account flows.
Original source - Sep 23, 2026
- Date parsed from source:Sep 23, 2026
- First seen by Releasebot:Sep 25, 2026
Browser Extension Version 18.2.0
Keeper releases a browser extension update with site-level Hide Keeper controls, an optional AI-powered phishing protection, a redesigned opt-in autofill prompt with inline suggestions, new enterprise setup reminders, clipboard policy support, and bug fixes.
Keeper Browser Extension version 18.2.0 introduces a Hide Keeper feature which allows you to pause Keeper for a specific site or domain, an opt-in approach to a redesigned autofill prompt and an AI-Powered Phishing Protection. This release also includes onboarding reminders for new Enterprise users and various bug fixes.
Hide Keeper
Sometimes you don't want the Keeper Browser Extension to autofill or show suggestions on a particular website — for example, when you're filling out a long form manually or browsing a site where autofill gets in the way. This feature allows you to effectively have a pause-for-a-visit / site-pause to temporarily silence the Keeper Browser Extension on any domain with a single click.
What it Does
- Hides all Keeper Browser Extension autofill popups, autofill suggestions, and KeeperLock icons on the paused site
- Keeps the extension toolbar icon active so you can still open your vault or resume at any time
- Works on sites already saved in your vault and sites you haven't saved yet
Hiding Keeper on a site applies to the entire domain (e.g., all pages on example.com), not just the current URL. Your hide/restore preferences are remembered locally in your browser until you change them.
How it Works
Click the Keeper lock icon and from the overflow menu (three vertical dots), select Hide Keeper on This Site.
Alternatively, right-click on any autofill field and select Hide Keeper on this Site from the Keeper context menu.
How to Restore Keeper
If you would like to resume Keeper's functionality on a site, click the Restore button at the top of the extension toolbar. Alternatively, within the extension Settings menu, select Hidden Sites > Restore next to the site's domain name. Keeper's autofill and suggestions functionally for that site will immediately return to normal.
AI-Powered Phishing Protection (Opt-In)
Keeper's AI-powered Phishing Protection uses a zero-knowledge local AI engine to protect you against potential phishing sites. If you encounter a suspicious site, you can block it. You retain full control of your blocked sites list and can restore access at any time. Keeper's Phishing Protection is entirely optional and disabled by default.
How to Enable & Manage Phishing Protection
Enable Phishing Protection from Settings > Blocked Sites and toggle "Phishing Protection" on. Here you can also view and add sites where Keeper autofill is disabled or restore previously blocked sites.
How it Works
When a suspicious website is detected, Keeper notifies you that the site may be trying to steal your credentials. You can view details about what Keeper detected, disable Keeper on that site, or dismiss the warning. If you dismiss it, Keeper won't alert you about that site again.
Detected patterns commonly associated with fake sites designed to steal your information:
- Suspicious IP address
- Login details hidden in URL
- Look-alike characters in domain
- Brand name on unofficial domain
- Password requested by site
- Unusual link structure
Autofill Prompt Redesign (Opt-In)
The Keeper Browser Extension has been updated to make autofilling credentials faster and more intuitive, with smarter suggestions appearing inline as you interact with forms and greater control over how your saved information is applied.
Our new UI also includes a change in the detection model from 'page-level' to 'field-level'. To make the introduction gradual, we have provided an opt-in option, as we continue to refine field-level detection for even greater accuracy. By default, you'll still have the traditional UI and logic.
To turn on the new UI and logic, go to Settings > KeeperFill Tool and toggle "Enable New Autofill Prompt" on.
What's New
Inline Autofill RecommendationsThe Keeper Browser Extension now displays autofill suggestions directly beneath form fields as you interact with them — no more hunting through pop-ups or menus. When you click into or tab to a login, address, or payment field, Keeper shows matching credentials from your vault in a compact list positioned just below the field. Click any item to autofill the entire form instantly.
Smart Search as You TypeStart typing in a field and the suggestions list narrows in real-time, filtering your vault entries to match what you're entering.
Multiple Credential VisibilityIf you have more than one login saved for a site, all matching entries appear in a scrollable list sorted by favorites first, then recently used, then alphabetical. Use the inline search to find the right one quickly.
Granular Control of AutofillClick the expand arrow on any suggestion to see all fields in that record. From there you can:
- Autofill only specific fields
- Copy individual values (username, password, etc.) to your clipboard using the copy icon
New User Setup Reminders
Enterprise users now receive a prompt during sign-in to websites reminding them to activate Keeper and complete setup using their company email address.
Improvements
- BE-8018: Clipboard Settings — Add "Expire Immediately" option to reflect Admin Console Clipboard Expiration enforcement policy. This setting will effectively prevent your data from entering the clipboard at all (you can still use the autofill feature to manually or automatically autofill).
Bug Fixes
- BE-7855: Record disappears from autofill and extension after account switch
- BE-7852: Incorrect matching credit cards/addresses after re-logins in new form filler
- BE-7799: Incorrect Create New Record prompt
- BE-7794: Multiple confirmation modals appear when filling payment card and address records via new form-fill prompt redesign
- BE-7733: Shared folder is not removed from vault after owner deletion when no other folders exist
- BE-7711: Address, payment card, and secure note records not displaying as expected in landscape mode
- BE-7660: SSO Connect Duo 2FA method buttons gray out after selection
- BE-7576: Select Folder Location resets after clicking away from toolbar window
- BE-7565: "Report Issue" text for Snapshot Preview Page design issue
- BE-7344: Password generator history navigation with tab key stuck on eye icon
- BE-7340: Accessibility tab does not function as expected in default password manager flow
- BE-7264: Recent sort fails to update after viewing record in toolbar window
- BE-7955: Addressed security finding related to cross-origin navigation during checkout flows (payment and address records) while confirmation dialog is in a pending state
- BE-7956: During HTTP Basic Auth autofill scenarios, only offer credentials that match the origin of the request (e.g. http:// authorization only offered if the record URL uses http:// as opposed to https://)
- Sep 18, 2026
- Date parsed from source:Sep 18, 2026
- First seen by Releasebot:Sep 18, 2026
Forcefield 1.2.1
Keeper Forcefield 1.2.1 strengthens protection against code injection, tampering, and driver vulnerabilities, improves installer feedback, and fixes SYSTEM-context deployment startup issues after reboot.
Forcefield 1.2.1 strengthens protection against code injection, tampering, and driver vulnerabilities. It also improves installer feedback and ensures the service starts correctly after SYSTEM-context deployments.
Changes
FF-19: Installer fails explicitly with an error message instead of failing silently on incompatible host architecture
FF-22: Resolves issue with SYSTEM-context deployments (e.g., Intune) so Forcefield service properly auto-starts on login after reboot
FF-25: Fixes denial-of-service / buffer overflow vulnerability in keeperforcefield.sys during Authenticode hash calculation
FF-26: Fixes vulnerability allowing bypass of Forcefield protections via thread manipulation
FF-27: Adds keeperdb-desktop.exe (KeeperDB) to the driver's list of protected processes
FF-28: Resolves bypass vulnerability involving DLL injection into trusted sihost.exe process
FF-29: Adds keeperforcefield.exe to driver protected process list for self-protection against tampering
FF-30: Updates handle stripping to remove PROCESS_VM_WRITE and PROCESS_VM_OPERATION to prevent code injection
FF-31: Corrects driver process name from keeper-gateway-service.exe to keeper-gateway.exe
VM-1367: Bugcrowd vulnerability report for keeperforcefield.sys kernel pool buffer overflow
Original source Similar to Keeper with recent updates:
- 1Password release notes225 release notes · Latest Sep 29, 2026
- Grammarly release notes12 release notes · Latest Aug 13, 2026
- Ubiquiti release notes978 release notes · Latest Oct 2, 2026
- n8n release notes70 release notes · Latest Sep 29, 2026
- Obsidian release notes117 release notes · Latest Oct 1, 2026
- Perplexity release notes31 release notes · Latest Sep 21, 2026
- Sep 17, 2026
- Date parsed from source:Sep 17, 2026
- First seen by Releasebot:Sep 18, 2026
JavaScript SDK 17.6.0
Keeper ships a major Secrets Manager update with a Node-only caching API change, encrypted cache storage, configurable request timeouts, and a long list of reliability fixes for folders, downloads, retries, storage, and key handling.
Breaking changes
cachingPostFunction removed (Node): Replaced by createCachingFunction(storage, options?). If you called cachingPostFunction directly, switch to the new function and delete the old plaintext cache file in your working directory.
Updates
- KSM-1209: Added a bounded, configurable request timeout to all network calls (queries, file upload, file download). Set requestTimeoutMs on SecretManagerOptions (default 30s); downloadFile, downloadThumbnail, and uploadFile each also accept an optional per-call timeoutMs that overrides it. On timeout, the call rejects with a KeeperError naming the applied value.
- KSM-1073: Fixed pamSettings.connection missing the dbConnectionMethod field on pamDatabase records.
- KSM-1079: Fixed getFolders() crashing when a folder in the response has a corrupted or missing key; undecryptable folders are now skipped instead.
- KSM-1084: Fixed deleteSecret() and deleteFolder() silently reporting success when the server rejected some UIDs; per-item server error messages now surface to the caller.
- KSM-748: Fixed getSecrets() silently dropping records created by Commander or the Vault UI inside shared folders.
- KSM-1035: Throttle retry jitter is now one-sided (0 to +25%) instead of two-sided, and a server-supplied retry_after is capped at 176s.
- KSM-1128: Bounded the server key-rotation retry in postQuery to 3 attempts instead of retrying forever; a server-suggested key ID is now validated before being persisted.
- KSM-1254: Fixed the Node platform's hash() ignoring its tag parameter.
- KSM-1332: Fixed browser IndexedDB storage hanging forever on a storage failure instead of rejecting.
- KSM-1251: Fixed throttle and key-rotation detection failing to parse a response body over 1000 bytes, which silently disabled the retry for that response.
- KSM-1297: Fixed getSharedFolderUid() hanging forever, and blocking the whole event loop or browser tab, on a cycle in server-supplied folder parent data. It now throws a descriptive error naming the folder where the cycle closes.
- KSM-1342: Fixed large file downloads (roughly 75MB and up) failing with a spurious timeout, caused by the new request-timeout tracking re-copying the entire response buffer on every network chunk. Chunks are now concatenated once, when the response ends.
- KSM-1351: Fixed hasEncryptedData() and hasReadableData() misclassifying real encrypted data as unencrypted roughly 1 in 128 times. Both now require an actual JSON parse instead of checking only the first decoded character.
- KSM-1395: Fixed throttle retry never firing against the live backend: the retry gate checked only for HTTP 403, but the backend has returned 429 for a throttled Secrets Manager request since 2026-06-15. The gate now accepts both.
- KSM-1265: BREAKING (Node only): Replaced cachingPostFunction, which stored its cache key in plaintext beside the data it protected, with createCachingFunction(storage, options?). The cache is now encrypted with a key derived from the app key, authenticated against tampering, and stored at ~/.keeper/ksm-cache.dat by default. See Breaking Changes.
- KSM-1266: Fixed localConfigStorage silently treating a corrupt, unreadable, or malformed config file as "no config yet." These cases now throw a typed KeeperStorageError (carrying the filesystem error code when available), and config writes are now atomic.
- KSM-1267: getFolders() now classifies why an undecryptable folder was skipped and logs a summary line naming the affected folders. A new optional onDecryptionError callback on SecretManagerOptions lets callers react to, or fail closed on, a partial result.
- KSM-1263: Config and cache file permissions are now re-applied on every write, not just on file creation.
- KSM-1256, KSM-1255: Fixed a stored serverPublicKeyId outside the bundled key table permanently blocking every future request; it now self-heals to the default key. Stopped re-saving serverPublicKey/serverPublicKeyId on every call when unchanged, and closed a race where concurrent requests could leave a mismatched key/id pair in storage. A custom serverPublicKey now always requires its serverPublicKeyId in the same call.
Resources
- npm package
- JavaScript SDK Documentation
- Sep 14, 2026
- Date parsed from source:Sep 14, 2026
- First seen by Releasebot:Sep 18, 2026
KSM GitHub Action 1.3.2
Keeper adds throttle-wait control and clearer secrets-manager-core errors for faster failures and better diagnostics.
Updates
Added an optional max-throttle-wait-seconds input (default: 60) that caps how long a throttle retry can block; exceeding it fails fast with a clear error instead of hanging silently. Raise it to allow the SDK's full ~176s backoff schedule to run instead.
KSM-1393: Bumped secrets-manager-core to 17.5.0. Stale-pinned-key errors now propagate instead of being swallowed, invalid config values raise a typed error instead of a generic one, and missing-decryption-key entries raise a clearer message.
Resources
GitHub Marketplace
Changelog
GitHub Actions Integration Documentation
Original source - Sep 14, 2026
- Date parsed from source:Sep 14, 2026
- First seen by Releasebot:Sep 15, 2026
Automator 17.1.5
Keeper releases a security-focused Automator update with hardened REST API endpoints and refreshed third-party dependencies. It recommends upgrading active deployments to 17.1.5 as soon as possible to strengthen security and maintain compliance with the latest remediation updates.
This is a security-focused release addressing API security hardening across REST endpoints and updating third-party library dependencies. All Automator deployments should be upgraded to version 17.1.5 as soon as possible, or during the next scheduled maintenance window.
Warning
As documented, ensure all Automator deployments adhere to our recommended Ingress Requirements, ensuring all inbound traffic is restricted to Keeper's infrastructure.
Security Updates
- KAA-169: API Security Hardening
Strengthened security controls across Automator REST API endpoints based on 3rd party pen tests and Bugcrowd issues. - 3rd Party Library Dependencies & SBOM Updates (KAA-185)
Upgraded third-party library dependencies, including Netty and Keycloak components, in accordance with our regular SDLC and SBOM vulnerability remediation processes.
Update Instructions
Updating to version 17.1.5 is recommended for all active deployments:
- For container deployments: Pull the latest container image and restart the service. If re-initialization is required, run automator setup followed by automator init as described in the relevant Installation Method section for your environment.
- For other deployment methods: Refer to the Automator documentation for detailed upgrade steps.
See the Keeper Automator Documentation for full deployment and configuration management instructions.
Original source - Sep 11, 2026
- Date parsed from source:Sep 11, 2026
- First seen by Releasebot:Oct 1, 2026
Vault Release 18.6.2
Keeper releases Web Vault and Desktop App 18.6.2 with stronger security, a refreshed BreachWatch experience, improved accessibility, larger 200MB file uploads, and more reliable imports for Dashlane, PSONO, and LastPass, plus a long list of stability and bug fixes.
Improvements
VAUL-7495: refreshed BreachWatch application interface
VAUL-7616: replaced Record Info section within Record History
VAUL-7627: auto-populates login field with previously saved email for your selected region
VAUL-7670: removed comma-separated usernames in sharing Add People and Edit Shared Folder Users
VAUL-8069: updated gateway selector for configuration records to enable searching online gateways
VAUL-8491: refactored PamConfigurationList and DiscoveryList for keyboard handling
VAUL-8864: added instructional modal with field mapping animation for review and edit import flow
VAUL-9334: added detection and user notification when Chrome policy required for hardware key authentication is not configured in RBI
VAUL-9339: updated PAM record type filters to always remain visible
VAUL-9341: allowed 1PUX imports to map tags to textfield instead of folders
VAUL-9344: increased file upload limit to 200MB
VAUL-9409: disabled record history for PAM configurations
KDE-1730: updated regional dropdown based on selected account email
KDE-2083: prevented loading from file protocol
KDE-2216: ran GitHub CodeQL security analysis for Desktop Vault (18.7.0)
KDE-2250: updated Electron to latest v42
KDE-2253: updated node-ocr packageBug Fixes
VAUL-9382: resolved SheetJS issue
VAUL-9386: resolved vault-protobuf security vulnerabilities
VAUL-6804: fixed dropdown menus getting cut off on small screens
VAUL-7704: fixed issue where clicking My Vault did not scroll to top in most views
VAUL-7711: fixed incorrect character count display after saving passphrase in password generator
VAUL-7820: disabled Update button in PAM Settings modal until changes are made
VAUL-8173: added Kosovo to country list for phone number and personal info fields
VAUL-8266: fixed PSONO import failing on Windows
VAUL-8373: fixed issue where opening record from notification link did not highlight record in vault list
VAUL-8483: updated browser list in import UI
VAUL-8622: fixed Shared Folder modal design mismatch in QA/JP environments
VAUL-8778: added error display when Content Manager saves folder edits after Owner deleted folder
VAUL-8825: fixed incorrect error messages displayed in Web Vault when device is locked via iOS Session Management
VAUL-8852: fixed record save failure when creating new address/card in custom record in Nested Shared Folders
VAUL-8920: fixed broken Commander CLI link in Settings Developer tab
VAUL-8939: fixed Dashlane import field mapping issue
VAUL-8945: fixed Admin Console record password policies failing to restrict symbols
VAUL-9029: remediated a window.enableNetworkLog() issue
VAUL-9195: removed maximum-scale=1 from viewport meta tag to enable mobile zoom for accessibility
VAUL-9196: fixed invalid autocomplete attribute on login page email field for accessibility
VAUL-9227: fixed missing team permission validation on 'Move To' in KeeperDrive
VAUL-9270: fixed Security Audit filter 'Sort by: Last Changed'
VAUL-9274: fixed unexpected error when setting up Master Password expiration for enterprise user
VAUL-9279: fixed missing day numbers in Custom Date calendar dropdown
VAUL-9354: fixed DB protocol displaying above disabled admin credentials info on DB records
VAUL-9357: fixed OTS checkbox 'Allow recipient to edit record fields and upload files' showing with view-only or can-share permissions
VAUL-9365: fixed error when adding user to Nested Shared Record or Folder
VAUL-9376: fixed issue where folders created in KeeperDrive failed to disinherit permissions
VAUL-9387: fixed internal error displayed after closing Master Password expiration popup
VAUL-9394: fixed improper styling on Secrets Manager search input
VAUL-9402: fixed hover styling and keyboard navigation for PAM Gateway dropdown
VAUL-9403: sanitized logoutReason query string parameter rendered in alert body
VAUL-9405: fixed empty rows in username dropdown
VAUL-9418: fixed deployment workflow for Web Vault
VAUL-9432: fixed issue where non-admin BreachWatch users were directed to checkout
VAUL-9435: fixed zxcvbn tokenization error when processing non-string values
KDE-1909: fixed issue requiring multiple clicks on Windows tray icon to open Keeper Desktop after upgrade
KDE-2075: fixed global shortcut for KFFA not focusing popup on Windows
KDE-2130: fixed crash on logout generating large dump files on Windows 11
KDE-2132: fixed password generator enforcing incorrect password policies
KDE-2198: fixed menu overflow in Desktop client
KDE-2199: fixed Windows-only NTLM wildcard delegation issue
KDE-2227: updated password reset flow in KFFA
KDE-2229: remediated Renderer-accessible arbitrary application launch and shell execution vulnerabilities
KDE-2242: fixed Desktop LastPass import failure behind corporate proxy/Zscaler
KDE-2248: resolved high-severity npm audit findings in brace-expansion and js-yaml
KDE-2268: fixed Desktop app hanging when Windows Store/Standalone silently updates running instance
KDE-2243: fixed AppInstaller x86/x64 VCLibs framework dependency mismatch causing install failure
KDE-2256: fixed OCR model download for keeperbundle://appWeb Vault Update Instructions
To ensure you're using the latest Web Vault, simply reload the vault login page (or Shift+Ctrl/Cmd+R to force refresh)
Desktop Update Instructions
If you installed Keeper Desktop directly from the Keeper website, download the latest version from:
https://www.keepersecurity.com/download.html?t=dIf you installed Keeper Desktop from the Mac App Store or Microsoft Store, visit the store to perform the update.
Original source - Sep 11, 2026
- Date parsed from source:Sep 11, 2026
- First seen by Releasebot:Sep 15, 2026
Vault Release 18.6.2
Keeper releases Web Vault and Desktop App 18.6.2 with stronger security, a refreshed BreachWatch experience, smoother accessibility and navigation, larger file uploads up to 200MB, and more reliable imports from Dashlane, PSONO, and LastPass even in restricted network environments.
Improvements
Web Vault & Desktop App 18.6.2 strengthens security with hardened protections, streamlines the user experience, and resolves critical import barriers. BreachWatch now features a redesigned interface, file uploads scale to 200MB, navigation meets accessibility standards, and Dashlane, PSONO, and LastPass imports work reliably even in restricted network environments.
- VAUL-7495: refreshed BreachWatch application interface
- VAUL-7616: replaced Record Info section within Record History
- VAUL-7627: auto-populates login field with previously saved email for your selected region
- VAUL-7670: removed comma-separated usernames in sharing Add People and Edit Shared Folder Users
- VAUL-8069: updated gateway selector for configuration records to enable searching online gateways
- VAUL-8491: refactored PamConfigurationList and DiscoveryList for keyboard handling
- VAUL-8864: added instructional modal with field mapping animation for review and edit import flow
- VAUL-9304: ran GitHub CodeQL security analysis for Web Vault 18.7.0
- VAUL-9334: added detection and user notification when Chrome policy required for hardware key authentication is not configured in RBI
- VAUL-9339: updated PAM record type filters to always remain visible
- VAUL-9341: allowed 1PUX imports to map tags to textfield instead of folders
- VAUL-9344: increased file upload limit to 200MB
- VAUL-9409: disabled record history for PAM configurations
- KDE-1730: updated regional dropdown based on selected account email
- KDE-2083: prevented loading from file protocol
- KDE-2216: ran GitHub CodeQL security analysis for Desktop Vault (18.7.0)
- KDE-2250: updated Electron to latest v42
- KDE-2253: updated node-ocr package
Bug Fixes
- VAUL-9382: resolved SheetJS issue
- VAUL-9386: resolved vault-protobuf security vulnerabilities
- VAUL-6804: fixed dropdown menus getting cut off on small screens
- VAUL-7704: fixed issue where clicking My Vault did not scroll to top in most views
- VAUL-7711: fixed incorrect character count display after saving passphrase in password generator
- VAUL-7820: disabled Update button in PAM Settings modal until changes are made
- VAUL-8173: added Kosovo to country list for phone number and personal info fields
- VAUL-8266: fixed PSONO import failing on Windows
- VAUL-8373: fixed issue where opening record from notification link did not highlight record in vault list
- VAUL-8483: updated browser list in import UI
- VAUL-8622: fixed Shared Folder modal design mismatch in QA/JP environments
- VAUL-8778: added error display when Content Manager saves folder edits after Owner deleted folder
- VAUL-8825: fixed incorrect error messages displayed in Web Vault when device is locked via iOS Session Management
- VAUL-8852: fixed record save failure when creating new address/card in custom record in Nested Shared Folders
- VAUL-8920: fixed broken Commander CLI link in Settings Developer tab
- VAUL-8939: fixed Dashlane import field mapping issue
- VAUL-8945: fixed Admin Console record password policies failing to restrict symbols
- VAUL-9029: remediated a window.enableNetworkLog() issue
- VAUL-9195: removed maximum-scale=1 from viewport meta tag to enable mobile zoom for accessibility
- VAUL-9196: fixed invalid autocomplete attribute on login page email field for accessibility
- VAUL-9227: fixed missing team permission validation on 'Move To' in KeeperDrive
- VAUL-9270: fixed Security Audit filter 'Sort by: Last Changed'
- VAUL-9274: fixed unexpected error when setting up Master Password expiration for enterprise user
- VAUL-9279: fixed missing day numbers in Custom Date calendar dropdown
- VAUL-9354: fixed DB protocol displaying above disabled admin credentials info on DB records
- VAUL-9357: fixed OTS checkbox 'Allow recipient to edit record fields and upload files' showing with view-only or can-share permissions
- VAUL-9365: fixed error when adding user to Nested Shared Record or Folder
- VAUL-9376: fixed issue where folders created in KeeperDrive failed to disinherit permissions
- VAUL-9387: fixed internal error displayed after closing Master Password expiration popup
- VAUL-9394: fixed improper styling on Secrets Manager search input
- VAUL-9402: fixed hover styling and keyboard navigation for PAM Gateway dropdown
- VAUL-9403: sanitized logoutReason query string parameter rendered in alert body
- VAUL-9405: fixed empty rows in username dropdown
- VAUL-9418: fixed deployment workflow for Web Vault
- VAUL-9432: fixed issue where non-admin BreachWatch users were directed to checkout
- VAUL-9435: fixed zxcvbn tokenization error when processing non-string values
- KDE-1909: fixed issue requiring multiple clicks on Windows tray icon to open Keeper Desktop after upgrade
- KDE-2075: fixed global shortcut for KFFA not focusing popup on Windows
- KDE-2130: fixed crash on logout generating large dump files on Windows 11
- KDE-2132: fixed password generator enforcing incorrect password policies
- KDE-2198: fixed menu overflow in Desktop client
- KDE-2199: fixed Windows-only NTLM wildcard delegation issue
- KDE-2227: updated password reset flow in KFFA
- KDE-2229: remediated Renderer-accessible arbitrary application launch and shell execution vulnerabilities
- KDE-2242: fixed Desktop LastPass import failure behind corporate proxy/Zscaler
- KDE-2248: resolved high-severity npm audit findings in brace-expansion and js-yaml for lastpass-node
- KDE-2267: fixed deployment workflow for Desktop
- KDE-2268: fixed Desktop app hanging when Windows Store/Standalone silently updates running instance
- KDE-2243: fixed AppInstaller x86/x64 VCLibs framework dependency mismatch causing install failure
- KDE-2256: fixed OCR model download for keeperbundle://app
Web Vault Update Instructions
To ensure you're using the latest Web Vault, simply reload the vault login page (or Shift+Ctrl/Cmd+R to force refresh)
Desktop Update Instructions
If you installed Keeper Desktop directly from the Keeper website, download the latest version from:
https://www.keepersecurity.com/download.html?t=dIf you installed Keeper Desktop from the Mac App Store or Microsoft Store, visit the store to perform the update.
Original source - Sep 10, 2026
- Date parsed from source:Sep 10, 2026
- First seen by Releasebot:Sep 11, 2026
KeeperDB 2.5.1
Keeper adds a maintenance update to KeeperDB with new DynamoDB and MongoDB connection options, improved Microsoft SQL Server sign-in, and the ability to edit saved connection details from Settings. It also brings driver fixes and stability improvements across multiple connections.
KeeperDB is a fast, secure, cross-platform database management tool. Use it inside KeeperPAM connections or as a standalone desktop app on Windows, macOS, and Linux.
Query, explore, and operate PostgreSQL, MySQL, SQLite, Microsoft SQL Server, Oracle, Amazon Redshift, MongoDB, and Amazon DynamoDB from one interface.
KeeperDB is built for engineers and data scientists. It replaces legacy tools like DBeaver, MySQL Workbench, and pgAdmin. In KeeperPAM, it brings core database workflows into a fully managed passwordless experience.
Quick Links
Product Documentation | Download Now
Version 2.5.1 Summary
KeeperDB 2.5.1 is a maintenance release. Amazon DynamoDB and MongoDB are now available when opening an additional connection, Microsoft SQL Server adds a legacy Entra ID username/password sign-in option alongside the existing token-based sign-in, and saved connections can be modified via settings now. The rest is driver fixes and stability work across multiple simultaneous connections.
KeeperDB 2.5.1 is available standalone, and built into the upcoming Keeper Gateway release.
New Connection Types
Amazon DynamoDB and MongoDB can now be opened from the "Open Another Connection" picker, alongside your existing connections.
MSSQL Sign-In Improvements
- Sign in to Azure SQL and SQL Server with an Entra ID username and password (Entra Legacy OAuth [ROPC]), alongside the existing token-based Entra sign-in
- Windows-style usernames (DOMAIN\user) are now detected automatically, so Windows authentication (NTLM) is selected without an extra step
Modify Saved Connection Details
Connection details can now be updated from Settings.
Driver and Stability Improvements
- PostgreSQL, SQL Server, and Oracle now show the definition for a view instead of an error when viewing its schema
- Amazon Redshift schema browsing and view definition fixes
- Switching between connection or query tabs no longer loses in-flight or just-finished query results
- A slow-to-connect Oracle database with connection string overrides no longer hangs the connection attempt indefinitely
Resources
- KeeperDB Documentation
- KeeperDB Proxy Documentation
- KeeperDB Feature Page
- KeeperAI Documentation
- KeeperPAM
Roadmap
We publish monthly updates based on customer feedback. Send feature requests and bug reports to [email protected], or post on our Reddit community page.
Original source - Sep 10, 2026
- Date parsed from source:Sep 10, 2026
- First seen by Releasebot:Sep 10, 2026
Endpoint Privilege Manager 2.1.1
Keeper releases EPM 2.1.1 with stronger security hardening, broader policy coverage, and faster privilege workflows across Windows, macOS, and Linux. It adds Linux real-time monitoring, improves registration and approval reliability, and smooths agentic AI and file access handling.
EPM 2.1.1 Overview
Release 2.1.1 delivers security hardening, platform stabilization, faster privilege workflows, and expanded policy coverage across Windows, macOS, and Linux. It also introduces the Linux real-time monitoring foundation and improves reliability for agentic-AI, File Access, registration, and approval workflows.
New Features
- Linux Real-Time Process and File Monitoring — introduces the KeeperLinuxAgent monitoring foundation, including Fanotify execution monitoring, process metadata extraction, auto-allow filters, MQTT lifecycle management, policy request/response envelopes, timeout and fail-open safety, dual logging, startup and mount-namespace coordination, parent-chain trust handling, and reduced per-event overhead.
- Registration Continuity Across Hostname Changes — administrators can preserve and reapply agent registration when an endpoint hostname changes.
- Enterprise-Aware macOS Setup — managed macOS deployments use a silent enterprise-default path, while unmanaged or explicitly requested installations continue to use the setup wizard.
Enhancements
Command Line Policy Modernization
- matching now evaluates ApplicationCheck against the executable and AllowCommands / DenyCommands against arguments; legacy policies receive migration warnings and automatic normalization.
Policy Matching Coverage
- user filters now try login, UPN, and other valid account names; Azure AD and SCIM user collections resolve more consistently; Azure AD group membership supports domain global and universal groups; OS collections are honored; and Azure AD privilege-elevation group filters are evaluated correctly.
File Access Policy Consistency
- wildcard matching is aligned across platforms, leading-wildcard paths resolve correctly, macOS .app bundles are covered consistently, protected-path behavior is defined, and policy scope is limited to the intended applications and binaries.
Network and Protocol Coverage
- intercepted DNS queries can resolve against a substitute domain, and TCP traffic is intercepted through the Keeper Filter Driver.
Notification and Registration Experience
- job notifications are grouped and rate-limited per user; registration status and menus are consistent across platforms; internet connectivity is checked before registration requests; and default administrator protection is maintained on Linux.
Agentic Grant Defaults
- one-time Agentic AI grants use the configured 240-minute policy default rather than an unintended 24-hour duration.
Security
- Command-Line Policy Enforcement — hardened substring matching policies to ensure an unprivileged user cannot obtain root execution.
- MQTT and Elevation Request Validation — strengthened MQTT authorization and validated elevation file paths instead of trusting request-supplied values.
- Linux Certificate and Registration Protection — tightened certificate validation and restricted Linux agent registration to administrators.
- AI-Agent File Access Enforcement — WMI process creation is covered by AI-agent File Access controls, and additional AI-agent application exclusions improve classification accuracy.
- Elevation Path Validation — temporary paths containing curly braces, including Visual C++ Redistributable bootstrapper paths, are handled correctly during elevation.
- Privilege-Deny Enforcement — deny policies are consistently applied through KeeperClient Request Elevation, including command files and scripts.
Improvements
Windows
- Privilege elevation is faster by reducing work on the critical path for scheduled tasks and ephemeral accounts.
- Approval requests reattach to the existing request while waiting, preventing duplicate requests and improving approval continuity.
- Deny, approval, MFA, and monitor dialogs now show accurate policy and process details, including clearer acknowledgement text.
- History-based elevation requests use current file information, and endpoint state is preserved when registration or removal does not complete successfully.
- Azure AD auto-update prompting and policy evaluation are more reliable; endpoint registration remains stable during hostname and network changes.
- Windows process ancestry and application identity reporting are more accurate, including Claude and other AI applications.
- MSIX OAuth protocol activation continues to use the correct Windows activation mechanism.
- Updater logs are stored under C:\ProgramData\Keeper Security\Endpoint Privilege Manager for consistent supportability.
- %ProgramData% exclusions resolve to the correct Windows path during file evaluation.
macOS
- KeeperClient, privilege elevation, and .app launches work together reliably, including elevated GUI applications and Agentic AI workflows.
- KeeperTrash intercepts file deletion consistently from the desktop, drag-and-drop, and context-menu workflows.
- Ephemeral elevation accounts are created as system accounts, improving compatibility with macOS elevation flows.
- Agentic AI wildcard approvals handle missing or invalid likelihood settings safely, and operator approval responses are processed reliably.
- Post-install presentation is streamlined, while policy and process launch handling remains compatible with macOS system integrations.
Linux
- Agent registration and operator approval are more reliable, including fresh installs, administrator restrictions, default-admin preservation, and correct keepersudo --approval argument handling.
- GNOME-launched applications no longer inherit an unrelated AI-Agent Access requirement from earlier activity, while fork/exec and bundled-install ancestry are resolved more accurately.
- Linux builds and packaging are more resilient, including stable x64 signing and release pipeline behavior.
- KeeperLinuxAgent logging honors Keeper Privilege Manager settings and remains concise for system-UID decisions.
Cross-platform and service reliability
- Agentic AI audit events use consistent policy types, correlation identifiers, ancestry, and event boundaries; unnecessary subprocess events are no longer emitted.
- Elevation and File Access audit streams avoid spurious status events and preserve accurate policy attribution, while users without policies do not receive unrelated audit messages.
- Startup, update, and service lifecycle coordination reduces AI application launch storms, retry storms, orphaned profiles, and upgrade conflicts.
- Ephemeral account and profile cleanup is more efficient and avoids conflicts with active elevation sessions.
- KeeperUSession, AOT JSON parsing, and endpoint file-access availability are more resilient during startup and registration.
- Automated cloud-approval coverage, baseline tests, shared helper extraction, and test-harness maintenance improve release confidence.
- Reboot warnings, duplicate notifications, and user-facing policy messages are clearer and more consistent.
- Sep 8, 2026
- Date parsed from source:Sep 8, 2026
- First seen by Releasebot:Sep 18, 2026
Freshservice Workflow
Keeper launches the Freshservice Workflow app, bringing governed Keeper vault access requests and approvals into the ticket sidebar. Agents can search vaults, share records or folders, issue one-time links, and approve EPM or device requests without leaving Freshservice.
Overview
The Keeper Security Freshservice Workflow app enables IT and security teams to fulfill Keeper vault access and approval requests directly from the Freshservice ticket sidebar. Agents search the Keeper vault, configure share permissions, and approve or deny requests without leaving the ticket.
All Keeper-side operations are executed through a customer-hosted Keeper Commander ServiceMode endpoint over HTTPS. The app does not store Keeper credentials in Freshservice tickets.
This app is the fulfillment layer for governed Keeper access in Freshservice.
Features
- Ticket sidebar fulfillment for vault access requests and Keeper approval tickets
- Vault search — search records and folders before approving access
- Share Record — grant view, edit, share, edit-share, or change-owner access (Classic and Nested records)
- Share Folder — grant or revoke Classic or Nested folder access with manage-records / manage-users options
- One-Time Share — generate a self-destructing share link and surface the URL to the agent
- Approve EPM — approve or deny Endpoint Privilege Manager (KEPM) requests
- Approve Device — approve or deny Cloud SSO device enrollment requests
- Install-time health check — verifies ServiceMode reachability and API key validity on install
- Optional Activity notes — posts public notes to the ticket Activity tab after approve or deny when a Freshservice API key is configured
- Apps launcher fallback — full-page entry point when the ticket sidebar surface is unavailable on a tenant
Prerequisites
- Freshservice account with permission to install marketplace or custom apps
- Keeper Commander ServiceMode deployed on a publicly reachable HTTPS endpoint (reverse proxy, load balancer, cloud tunnel, etc.)
- ServiceMode API key with permissions to perform share, approval, and vault-search operations on behalf of the configured Keeper service account
- After install, a Freshservice admin must manually create and publish a service catalog item with three required custom fields: Request Type (dropdown), Requirements (paragraph), Justification for this request (paragraph)
- Request Type options: Record Access, Folder Access, One-Time Share Link
- Optional — Keeper Security ITSM for Freshservice: required only for automated EPM and device approval ticket creation from Keeper alerts
- Optional — Freshservice admin API key: enables Activity notes and server-side ticket enrichment; fulfillment still works without it
Roles Required in Freshservice
- Install and configure the app: Account Admin
- Fulfill vault access requests: Agent with access to assigned tickets
- Approve or deny EPM / device requests: Security or IT admin agent
- Manage service catalog items: Admin or service catalog manager
- View app installation and support: Admin
Configuration Instructions
Step 1 — Deploy Keeper Commander ServiceMode
- Install Keeper Commander on a server reachable from the public internet (Freshworks cloud must reach your ServiceMode host).
- Create and start ServiceMode with the commands required for this integration. Supported commands should include at minimum: sync-down, search, share-record, nsf-share-record, share-folder, nsf-share-folder, one-time-share, device-approve, epm
- Note the hostname (no https://, no path) and the generated API key.
Step 2 — Install the app in Freshservice
- Log in to Freshservice with Account Admin privileges.
- Navigate to Admin → Apps.
- Search for Keeper Security Workflow and click Install (or upload the custom app package).
- On the installation screen, enter the parameters below and click Install (or Save when editing):
- Keeper Commander ServiceMode Host: Hostname only — no https:// and no path. Example: keeper-sm.example.com
- ServiceMode API Key: API key from ServiceMode setup. Stored encrypted; not displayed after save.
- Freshservice API Key (optional): Admin API key used server-side to load ticket details and post public Activity notes after approve or deny. Leave blank to skip Freshservice API calls.
- Freshservice Domain (when Freshservice API key set): Hostname only, e.g. yourcompany.freshservice.com (no https://). Used server-side for ticket enrichment and Activity notes.
- On install, the app runs a health check against ServiceMode. Install fails if the endpoint is unreachable or the API key is rejected.
Step 3 — Service catalog setup (required, manual)
- The app does not create service catalog items on install. Install only runs a ServiceMode health check. A Freshservice admin must create and publish the catalog item after the app is installed.
- Create the service item:
- Go to Admin → Service Catalog.
- Click New Service Item (or edit an existing item).
- On the General tab, set:
- Name: Request Keeper Vault Access (recommended)
- Short description: Request access to a Keeper vault record, folder, or one-time share link
- Category: your choice (for example Security, Identity, or IT)
- Add custom fields (all required):
- Request Type (Dropdown): Record Access, Folder Access, One-Time Share Link (use these exact labels)
- Requirements (Paragraph): Requester describes what they need (record, folder, or use case)
- Justification for this request (Paragraph): Requester explains why access is needed
- Mark each field Required so requesters cannot submit without completing them. All four Behavior checkboxes should be checked.
- Publish the item to the employee portal.
- Submit a test request for each Request Type option.
- Open each ticket and confirm the Keeper Vault sidebar tab appears and shows the correct flow (record, folder, or one-time share).
Step 4 — Configure Keeper alerts for EPM and device tickets (optional)
- EPM and device approval fulfillment in this app depends on tickets created by the Keeper Security ITSM for Freshservice app.
- Install and configure Keeper Security ITSM for Freshservice on your tenant.
- In Keeper Admin Console → Reporting and Alerts → Alerts, create or edit an alert configuration.
- Add a Webhook recipient with the URL and token from the ITSM app guided setup.
- Enable alert types for:
- Endpoint Privilege Manager approval requests
- Cloud SSO device admin approval requests
- When alerts fire, the ITSM app creates Freshservice tickets with keeper_request_id (and related fields). This Workflow app reads those fields for approve/deny.
- This Workflow app does not ingest webhooks directly.
Example Use Cases
- Request access to a Keeper vault record:
- Trigger: An employee submits a Freshservice service catalog request for Record Access.
- Approval: The request is approved per your Freshservice approval workflow.
- Fulfillment: An agent opens the ticket, opens the Keeper Vault sidebar tab, searches for the record, selects permissions, and clicks Approve.
- Result: Commander runs share-record and grants access to the requester. If configured, a public Activity note is added to the ticket.
- Request access to a shared folder:
- Trigger: An employee submits a Folder Access catalog request.
- Approval: The request is approved.
- Fulfillment: The agent searches folders in the sidebar, selects manage-records / manage-users options (or a Nested folder role), and approves.
- Result: Commander runs share-folder or nsf-share-folder. The requester receives folder access.
- One-time share link:
- Trigger: An employee submits a One-Time Share Link request.
- Fulfillment: The agent searches for the record, sets link expiration and whether the recipient can edit, and approves.
- Result: Commander returns a one-time share URL (https://…/vault/share#…). The agent forwards the link to the requester from the sidebar or Activity note.
- Deny a vault access request:
- Trigger: An approved vault access ticket requires denial (policy, wrong record, etc.).
- Action: The agent clicks Deny request in the sidebar and enters a justification.
- Result: No Keeper share command is executed. If a Freshservice API key is configured, a public Activity note records the denial and justification.
- Endpoint Privilege Manager (EPM) approval:
- Trigger: A user requests privilege elevation on an endpoint. Keeper Admin Console sends an alert; the Keeper Security ITSM for Freshservice app creates a ticket with keeper_request_id.
- Fulfillment: A security admin opens the ticket and clicks Approve or Deny in the Keeper sidebar.
- Result: Commander runs epm approval action --approve or --deny. The ticket is annotated in Activity when configured.
- Cloud SSO device approval:
- Trigger: A user enrolls a device pending admin approval. The ITSM app creates a Freshservice ticket.
- Fulfillment: An admin approves or denies from the Keeper sidebar using the email or device id on the ticket.
- Result: Commander runs device-approve.
Agent Fulfillment Guide
- Open the Keeper sidebar:
- Open a Freshservice ticket for a Keeper vault access or approval request.
- Click the Keeper Vault tab in the ticket sidebar.
- If the sidebar tab does not appear on your tenant, open the app from Apps in the Freshservice launcher (same UI, full-page entry point).
- Fulfill a Record Access request:
- Confirm the ticket request type is Record Access.
- In the sidebar, choose Records search scope.
- Enter at least 2 characters and click Search.
- Select a result from the list.
- Enter the Recipient email.
- Choose Classic record permission or Nested record role depending on record type.
- Optionally set Expiration when the permission model supports time-limited access.
- Click Approve.
- Fulfill a Folder Access request:
- Confirm the ticket request type is Folder Access.
- Choose Folders search scope.
- Search and select the target folder.
- Enter the Recipient email.
- For Classic folders, choose: No User Permissions, Manage records, Manage users, or Manage records & users.
- For Nested share folders, choose the appropriate Nested folder role.
- Optionally set expiration.
- Click Approve.
- Fulfill a One-Time Share Link request:
- Confirm the ticket request type is One-Time Share Link.
- Search and select the record.
- Set Expiration (default in the UI: 5 minutes; options include 5m, 10m, 30m, 1h, 4h, 8h, 24h, 7d).
- Optionally check Can edit for a bidirectional share.
- Click Approve.
- Copy the one-time share URL from the sidebar and send it to the requester.
- Deny a vault access request:
- Click Deny request (available without searching the vault).
- Enter a justification (required, up to 500 characters).
- Click Confirm denial.
Permission Models
- The app supports Classic and Nested Keeper permission models.
- Classic record permissions include View, Edit, Share, Edit & share, Change owner with corresponding Commander behaviors.
- Nested record roles include Viewer, Share Manager, Content Manager, Content & Share Manager, Full Manager, Transfer Ownership.
- Classic folder permissions options include No User Permissions, Manage records, Manage users, Manage records & users with manage_records and manage_users flags.
Expiration notes
- Some permission levels do not support time-limited expiration (e.g., Classic share, edit-share, change-owner).
- When expiration is not supported for the selected permission, the expiration control is hidden and access is granted without expiry.
- One-time share expiration uses Commander units: Nmi (minutes), Nh (hours), Nd (days). The UI normalizes friendly forms such as 30m to 30mi.
Commander Commands Reference
- Before any vault share command (shareRecord, shareFolder, createOneTimeShare), the server runs sync-down to refresh the local vault cache.
- epm sync-down runs only before EPM approval actions.
- Detailed Commander commands for actions like share record (view, edit, share, edit-share, change-owner), share folder (grant, remove), nested share record/folder, one-time share, approve device, approve EPM, vault search (records, folders).
Error Handling
- ServiceMode unreachable on install: Install fails with a message to verify host and API key.
- Invalid email, permission, decision, or expiration: Returns INVALID_INPUT; agent sees a validation message.
- ServiceMode HTTP 401 / 403: Returns UPSTREAM_AUTH — verify or rotate the API key in app settings.
- ServiceMode request expired or poll timeout: Returns UPSTREAM_TIMEOUT.
- ServiceMode failed, 4xx / 5xx, or inner Commander error: Returns UPSTREAM_FAILED with Commander's error message.
- Commander rejects OTS on unsupported record type: UPSTREAM_FAILED with Commander's verbatim message.
- Request already processed in Keeper: Sidebar shows processed state; no duplicate action.
Testing the Configuration
- Tests include app install, service catalog item, vault search, approve record/folder access, approve one-time share, deny request, approve EPM/device, invalid API key.
Troubleshooting
- Install fails — ServiceMode unreachable: Confirm ServiceMode Host has no https:// prefix and no path; confirm ServiceMode is running and listening on HTTPS; confirm host is reachable from the public internet; check firewall, reverse-proxy, and TLS certificate configuration.
- Install fails — authentication error: Regenerate the ServiceMode API key; re-enter the key in app settings; confirm the key has permissions for the required Commander commands.
- Keeper sidebar not shown on a vault access ticket: Confirm the service catalog item is published and the ticket came from that item; confirm the item name or description includes a Keeper vault access phrase; confirm the request_type dropdown uses Record Access, Folder Access, or One-Time Share Link; if the ticket sidebar tab is missing, open the app from the Apps launcher; see Step 3 for the full admin checklist.
- UPSTREAM_AUTH when approving: Open app settings and verify the ServiceMode API key; rotate the API key on the ServiceMode host and update app settings.
- Sidebar tab not visible on tickets: Some Freshservice tenants do not render ticket_sidebar reliably; open the app from the Apps launcher instead; confirm the app is installed and enabled.
- Ticket shows "not a Keeper vault access or approval request": Confirm the ticket is a Keeper catalog request or an ITSM-generated EPM/device ticket; verify the request type is Record Access, Folder Access, or One-Time Share Link; confirm keeper_request_id is populated for EPM/device.
- Vault search returns no results: Confirm the ServiceMode service account can run sync-down and search; use at least 2 characters in the search query; confirm the record or folder exists in the vault visible to the ServiceMode account.
- Vault search shows an unexpected error: Confirm ServiceMode is running; check ServiceMode logs for Commander errors; verify supported commands include search and sync-down.
- Approve succeeds but no Activity note: Configure the Freshservice API Key in app settings; confirm the key belongs to an admin account with permission to add ticket notes; without the API key, Keeper fulfillment still runs; only ticket notes are skipped.
- EPM or device requests not appearing: Confirm Keeper Security ITSM for Freshservice is installed and configured; confirm EPM and device alerts are enabled; confirm webhook URL and token match ITSM app configuration; verify a test alert creates a ticket with keeper_request_id.
- One-time share fails with Commander error: Confirm the record type supports one-time shares; confirm the record UID is valid and not expired; surface error.message from the app response to the agent.
- Request already processed outside Freshservice: If a request was approved or denied directly in Keeper Admin Console or Commander, the sidebar shows a processed state and does not re-submit the action.
Related Documentation
- Commander Service Mode REST API
- Sharing Commands reference
- Keeper Security ITSM for Freshservice
- Sep 2, 2026
- Date parsed from source:Sep 2, 2026
- First seen by Releasebot:Sep 3, 2026
Commander 18.1.4
Keeper improves CyberArk imports, expands PAM service management, and strengthens Nested Shared Folder support across workflows. It also adds more reliable Service Mode automation and delivers fixes for record handling, SCIM binding, and security restrictions.
Highlights
Improved CyberArk classic imports with richer account metadata retention and more resilient password-retrieval skip handling.
Added PAM service-management support for COM, DCOM, COM+, and SCOM.
Improved Nested Shared Folder (NSF) support across PAM workflows and eligible shared-folder discovery.
Enhancements
list-sf --roe-eligible now includes eligible Nested Shared Folders and identifies each result as Classic or Nested.
CyberArk imports support selectively skipping team, role, or user processing with --skip.
PAM service listings now correctly render individual service entries in text output.
Service Mode treats first-time share invitations as successful, improving automation reliability.
Fixes
Fixed NSF-backed PAM records reverting fields after pam tunnel edit, pam connection edit, and related updates.
Fixed NSF record loading in ls.
Fixed duplicate Active Directory binding during SCIM operations.
Security
Service Mode now blocks access to host filesystem paths, including local-file import/export, and path-based command arguments.
SailPoint integration is now restricted to documented capabilities. enterprise-role/er, record ownership transfers, and certain enterprise-user operations are no longer permitted through SailPoint Service Mode integrations.
References
Keeper Commander CLI Documentation
Original source - Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 2, 2026
Backend API 18.1.7.2
Keeper improves security, notification handling, and audit log reliability with backend fixes, dependency updates, and stronger Automator endpoint hardening.
KA-9494: Updated core security libraries and system dependencies to the latest compliance standards.
KA-9479: Resolved an issue where users received duplicate automated email notifications when access to shared folder records was expiring. Email notification frequency has been corrected to ensure proper notification delivery without repeated alerts.
KA-9480: Fixed timestamp precision handling in backend database queries to prevent processing errors during audit log ingestion. This improves reporting reliability and ensures consistent data storage across system event logs.
KA-9162: Improved hardening of the Automator endpoints based on 3rd party pen testing.
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.