What is new in SikkerKey
Product updates, security improvements, and platform changes. Subscribe to the feed to stay current.
RSS feedA fallback cache that keeps reads working through an outage, and an open-source CLI
Turn on the fallback cache and your applications keep reading secrets when SikkerKey is unreachable, from an encrypted copy only that machine can open. Available in the CLI and all six SDKs. The CLI is now open source under MIT, and the docs are moving to sikkerkey.com/docs.
Read →Redis leased credentials, verified connections, a grant builder, and Discord and Slack alerts
Leased credentials now support Redis, verify your database's certificate on every connection, and build grant templates instead of writing SQL by hand. Webhooks get a guided setup flow and post to Discord and Slack, and you can export your audit log as CSV, JSON, or text.
Read →Leased Credentials, on-demand database logins that expire on their own
Connect a database once and let your machines mint short-lived logins on demand. Each machine gets its own credential that renews while in use and is revoked when it expires or its machine is turned off. Available for PostgreSQL today, with more providers planned.
Read →Organization roles and security hardening
A two-role model for organization members, refreshed core documentation, and a round of security hardening.
Read →Group a service's projects with Applications
Group the projects for one service, its Prod, Staging, and Dev, under one named application created in a single step. They appear grouped in the dashboard sidebar and the CLI, and the CLI can scope listing, export, and run to one application.
Read →SikkerLink, free one-time secret links
SikkerLink is a free tool for sending a secret over a link that opens once, then deletes itself. No account needed. Everything is encrypted in your browser, so only the recipient can read it, and the link self-destructs after the first view or when it expires.
Read →Single sign-on (SAML 2.0) for your organization
SikkerKey organizations can now sign members in with SAML 2.0 single sign-on (SSO). Connect your identity provider, verify your domains, and new members provision on first sign-in. Offer it next to existing sign-in, or enforce it.
Read →Multi-user secrets management with Organizations
Convert a personal vault to an organization, invite people by email, and assign each one a capability template that bundles permissions and project scope. The machine plane is untouched.
Read →Temporary machines for scoped, time-bounded access
Provision a single machine with a fixed lifetime from one hour to twelve months, with optional per-machine guardrails covering IP, country, and time-of-day. Manual approval, single-step revert on extensions, and a clear audit signal on every guardrail block.
Read →AI agents for Claude Code, Codex, and Cursor
Manage your vault from any MCP-compatible AI client. Ed25519-bound, scope-restricted, fully audited, and structurally unable to read the plaintext content of any stored secret.
Read →