Skip to main content
A Keeper connection authenticates Infisical to Keeper Commander Service Mode with the API key Commander generates. Service Mode is a REST API for Keeper Commander that you run in your own infrastructure. Commander signs in to Keeper as a user you create for Infisical, so Infisical can only reach the shared folders you share with that user.
This guide only authenticates Infisical with Keeper. Once the app connection is ready, you can use it to set up integrations.

Prerequisites

  • Permission to add users in the Keeper Admin Console
  • A host that Infisical can reach over HTTPS

Step 1: Set up Keeper Commander

Infisical sends commands to Keeper Commander, not to Keeper directly. You run Commander in Service Mode on your own host, signed in as a Keeper user you create for Infisical.
1
In the Keeper Admin Console, go to Admin, open the Users tab, and select Add User. Enter a Full Name and an Email Address for the Infisical user, such as infisical-sync@company.com, then select Add.Add User
2
Select the edit icon next to the new user to open the user’s details, and check that 2FA is Off. Two-factor authentication must stay off for the Infisical user.User DetailsKeeper emails the user an invitation. Accept the invitation and set a master password for the user. The user can’t be SSO-only, because Commander signs in with a master password.
3
On the host that will run Commander, install Commander and start its shell:
In the Commander shell, sign in once as the Infisical user, approving the device when Keeper prompts you:
Commander saves the session to ~/.keeper/config.json. Without --config-file, newer Commander versions save the session to the operating system’s keychain instead, and the container can’t read the keychain. Before you continue, check that config.json contains "config_storage": "file" and a device_token.
4
Start Commander in Service Mode with Docker, mounting the config.json file from the previous step:
  • -q n turns off Commander’s request queue, so Commander serves the v1 API that Infisical calls
  • -c lists the commands Commander accepts, which are exactly the seven commands Infisical runs
  • -rl sets how many requests Commander accepts per minute
  • -aip lists the IP addresses allowed to call Commander; set it to the IP addresses Infisical connects from
For other options, see Keeper’s Docker deployment guide.
Infisical must be able to reach Commander at the URL you enter in the connection. Serve Commander over HTTPS with a certificate from a public certificate authority, for example through a reverse proxy in front of port 8900. Infisical doesn’t accept self-signed certificates, and it refuses localhost and private IP addresses. If you self-host Infisical and Commander runs on your private network, set ALLOW_INTERNAL_IP_CONNECTIONS to true on your Infisical instance.
5
Find the API key Commander generated in the container logs, on the line that starts with Generated API key::
Copy the key. You need it to create the connection in Infisical.

Step 2: Create the app connection

Next, create the app connection in Infisical.
To create the connection using the API, use the Create Keeper Connection endpoint.
1
In the sidebar, select Integrations, then open the App Connections tab.App Connections Tab
2
Select Add Connection and choose Keeper.Select Keeper Connection
3
Fill out the form’s fields:
  • Name: A descriptive name for the connection, such as keeper-prod
  • Description (optional): A note for future reference
  • Instance URL: The base URL of your Commander Service Mode instance, such as https://keeper.company.com, without an /api path
  • API Key: The key you copied when you set up Keeper Commander
Then, select Connect to Keeper.Keeper Connection FormThe new connection appears in the App Connections tab.Keeper Connection Created
When you select Connect to Keeper, Infisical runs Commander’s whoami command to check that it can reach Commander and that Commander accepts the API key.
Your Keeper app connection is ready to use.

Step 3: Configure integrations

Now that your Keeper app connection is configured, you can use it to set up the following integrations:

Keeper Password Manager Secret Sync

Sync secrets from Infisical to a Keeper shared folder.