This guide only authenticates Infisical with Keeper. Once the app connection
is ready, you can use it to set up
integrations.
Prerequisites
- Permission to add users in the Keeper Admin Console
- A host that Infisical can reach over HTTPS
Step 1: Set up Keeper Commander
Infisical sends commands to Keeper Commander, not to Keeper directly. You run Commander in Service Mode on your own host, signed in as a Keeper user you create for Infisical.1
In the Keeper Admin Console, go to Admin, open the Users tab, and select Add User. Enter a Full Name and an Email Address for the Infisical user, such as 
infisical-sync@company.com, then select Add.
2
Select the edit icon next to the new user to open the user’s details, and check that 2FA is Off. Two-factor authentication must stay off for the Infisical user.
Keeper emails the user an invitation. Accept the invitation and set a master password for the user. The user can’t be SSO-only, because Commander signs in with a master password.
Keeper emails the user an invitation. Accept the invitation and set a master password for the user. The user can’t be SSO-only, because Commander signs in with a master password.3
On the host that will run Commander, install Commander and start its shell:In the Commander shell, sign in once as the Infisical user, approving the device when Keeper prompts you:Commander saves the session to
~/.keeper/config.json. Without --config-file, newer Commander versions save the session to the operating system’s keychain instead, and the container can’t read the keychain. Before you continue, check that config.json contains "config_storage": "file" and a device_token.4
Start Commander in Service Mode with Docker, mounting the
config.json file from the previous step:-q nturns off Commander’s request queue, so Commander serves the v1 API that Infisical calls-clists the commands Commander accepts, which are exactly the seven commands Infisical runs-rlsets how many requests Commander accepts per minute-aiplists the IP addresses allowed to call Commander; set it to the IP addresses Infisical connects from
Infisical must be able to reach Commander at the URL you enter in the connection. Serve Commander over HTTPS with a certificate from a public certificate authority, for example through a reverse proxy in front of port
8900. Infisical doesn’t accept self-signed certificates, and it refuses localhost and private IP addresses. If you self-host Infisical and Commander runs on your private network, set ALLOW_INTERNAL_IP_CONNECTIONS to true on your Infisical instance.5
Find the API key Commander generated in the container logs, on the line that starts with Copy the key. You need it to create the connection in Infisical.
Generated API key::Step 2: Create the app connection
Next, create the app connection in Infisical.1
In the sidebar, select Integrations, then open the App Connections tab.

2
Select Add Connection and choose Keeper.

3
Fill out the form’s fields:
The new connection appears in the App Connections tab.
- Name: A descriptive name for the connection, such as
keeper-prod - Description (optional): A note for future reference
- Instance URL: The base URL of your Commander Service Mode instance, such as
https://keeper.company.com, without an/apipath - API Key: The key you copied when you set up Keeper Commander
The new connection appears in the App Connections tab.
whoami command to check that it can reach Commander and that Commander accepts the API key.
Your Keeper app connection is ready to use.
Step 3: Configure integrations
Now that your Keeper app connection is configured, you can use it to set up the following integrations:Keeper Password Manager Secret Sync
Sync secrets from Infisical to a Keeper shared folder.