The Keeper Password Manager Secret Sync requires a Keeper app
connection. This guide walks you
through creating a project-scoped app connection.
Prerequisites
- A project with secrets configured
- Keeper Commander running in Service Mode and its API key (see Set up Keeper Commander)
Step 1: Configure a shared folder
The sync writes secrets to a Keeper shared folder that the Infisical user can manage. The Infisical user is the Keeper user you created when you set up Keeper Commander.1
In your Keeper vault, choose the shared folder Infisical syncs secrets to. To create a new shared folder, select Create New, then select Shared Folder.

2
In My Vault, select the three dot menu next to the shared folder.
In the folder panel, select the Settings tab.
In the folder panel, select the Settings tab.
3
Select Edit Folder (the pencil icon).
On the Settings tab, set these permissions:
Keeper gives these permissions only to the users and records you add to the folder after you save the settings.
On the Settings tab, set these permissions:- User Permissions: Can Manage Records, so Infisical can create and delete records
- Record Permissions: Can Edit, so Infisical can update record values
Keeper gives these permissions only to the users and records you add to the folder after you save the settings.4
Share the folder with the Infisical user. Select Edit Folder again, then select the Users tab. In Email or Team Name, enter the Infisical user’s email address, select Add, then select Save.
The Infisical user gets the permissions you set in the previous step. In the Permissions column, check that the Infisical user has Can Manage Records.To share the folder from Commander instead, run this command as a user who manages the folder:If you’ll create the sync through the API, note the folder’s UID. The API identifies the folder by its UID, not its name.
The Infisical user gets the permissions you set in the previous step. In the Permissions column, check that the Infisical user has Can Manage Records.To share the folder from Commander instead, run this command as a user who manages the folder:Step 2: Set up the sync in Infisical
1
In your project, go to Integrations and open the Secret Syncs tab. Select + Add Sync.
Then, select the Keeper Password Manager sync.
Then, select the Keeper Password Manager sync.
2
Under Source, choose which secrets to sync from Infisical:Then select Continue.
- Environment: The project environment to retrieve secrets from
- Secret Path: The folder path to retrieve secrets from
-
Include secrets from all subfolders: When enabled, also syncs secrets from every folder under the secret path (secret names must be unique across those folders)
Commander reads
${ in a record title as the start of a variable. If any secret at this path has a name that contains ${, the sync fails without writing any secrets, and the error names each rejected key.3
Under Destination, create or select the Keeper app connection the sync will use, then choose the shared folder secrets go to.
- Create a new app connection
- Use an existing connection
Under Keeper Connection, select Create Connection in the dropdown, then fill in:
- Name: A descriptive name for the connection, such as
keeper-prod - Description (optional): A note for future reference
- Instance URL: The base URL of your Commander Service Mode instance, such as
https://keeper.company.com, without an/apipath - API Key: The key you copied when you set up Keeper Commander
This creates a connection scoped to the current project. To share the connection across other projects, create it at the organization level first, then select it here.
-
Shared Folder: The Keeper shared folder to sync secrets to, chosen from the shared folders you’ve shared with the Infisical user
4
Under Initial Sync Behavior, choose how Infisical handles login records that already exist in the shared folder on the first sync:
Then select Continue.
- Overwrite Keeper Password Manager: Infisical imports nothing, and writes its secrets to the shared folder
- Import from Keeper, prioritize Infisical: Infisical first imports the title and password of each login record in the folder; if a secret exists in both places, Infisical keeps its own value
- Import from Keeper, prioritize Keeper: Infisical first imports the title and password of each login record in the folder; if a secret exists in both places, the Keeper value replaces the Infisical value
Then select Continue.5
Under Sync Options, choose how secrets are synced:
Then select Continue.
- Prevent secret deletion: When enabled, Infisical adds and updates login records in the shared folder but never deletes them; enable this if you manage some records in the folder outside of Infisical
- Auto-sync on changes: When enabled, secrets sync to Keeper automatically as the source changes; turn it off to sync manually only
- Customize key names: Adds a prefix or suffix to every synced name, using
{{secretKey}}for the original name and{{environment}}for the environment slug
Then select Continue.6
Give the sync a Name and an optional Description. The name must be slug-friendly.
Then select Continue.
Then select Continue.7
Review your Keeper Password Manager Sync configuration, then select Create Sync.


The sync is created and appears in the Secret Syncs tab. If Auto-sync on changes is enabled, it begins syncing secrets to your Keeper shared folder right away.

FAQ
Why does a sync fail with rate limit errors?
Why does a sync fail with rate limit errors?
Every sync reads the whole shared folder: one request to list the folder,
one request per record in the folder, and one more request for each secret
that changed. With
-rl 120/minute, a folder with about 100 records or more
can go over the limit. Start the container with a higher -rl value, or
split your secrets across several shared folders.What happens when the Commander session expires?
What happens when the Commander session expires?
Commander rejects every command, and the sync shows Commander’s error. Sign
in to Commander on the host again, as in Set up Keeper
Commander,
then restart the container with
docker restart keeper-service.Next steps
Keeper
Create a Keeper connection at the organization level to share it across
projects.
Overview
See every destination you can sync secrets to.