> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Keeper Security

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/keeper.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=3922ae9ff118af783ef36e7abbe7432d" alt="" noZoom width="29" height="29" data-path="images/connectors/keeper.svg" />

  <h1>Keeper Security</h1>
</div>

## Connection

### Setup

On the node Klef should manage, add
[SCIM provisioning](https://docs.keeper.io/en/enterprise-guide/user-and-team-provisioning) in the Admin
Console.

### Settings

| Setting      | Required | Description                                                                                                                                                                                              |
| ------------ | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SCIM URL     | Yes      | Provisioning endpoint of the node, as the Keeper Admin Console shows it, such as [https://keepersecurity.com/api/rest/scim/v2/1234567890123](https://keepersecurity.com/api/rest/scim/v2/1234567890123). |
| Bearer token | Yes      | Token generated alongside that endpoint. Keeper shows it once, when the provisioning method is created. Stored encrypted.                                                                                |

### Permissions

Minimum permissions the connection requires.

| Capability      | Required | Granted by (any one)        |
| --------------- | -------- | --------------------------- |
| Provision users | Yes      | `Provisioning bearer token` |
| Read teams      | Yes      | `Provisioning bearer token` |

## keeper.user

### Fields

| Field         | Type   | Required | Description                                                                                 |
| ------------- | ------ | -------- | ------------------------------------------------------------------------------------------- |
| `userName`    | string | Yes      | Email address the user signs in to Keeper with.                                             |
| `displayName` | string |          | Full name shown in the Keeper Admin Console.                                                |
| `givenName`   | string |          | First name.                                                                                 |
| `familyName`  | string |          | Last name.                                                                                  |
| `active`      | bool   |          | Whether the user is active. An inactive user is locked out, and keeps their vault.          |
| `teams`       | grant  |          | Teams the user belongs to, which is what shares records with them. One row grants one team. |
| `teams[]`     | string |          | Team ID.                                                                                    |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in Keeper Security, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `userName`    | `worker.business_email` |

## Examples

### Keeper users

A Keeper seat for every engineer, in the teams that share their records, locked and cleared when they leave.

```hcl theme={null}
stage active {
  target keeper.user {
    userName    = worker.business_email
    displayName = worker.display_name
    givenName   = worker.legal_name.given
    familyName  = worker.legal_name.family
    active      = true
    teams       = ["Engineering"]
  }
}
```
