Changelog

What is new in SikkerKey

Product updates, security improvements, and platform changes. Subscribe to the feed to stay current.

RSS feed
May 30, 2026Security

Full data erasure on vault deletion, plus security hardening

Delete a vault and your secrets, audit logs, and machine identities are now erased from production and backups within 30 days. Plus tighter browser security across the apps, abuse protection on single sign-on, and auto-clearing clipboard copies in SikkerLink.

Read
May 25, 2026Releases

SikkerLink, free one-time secret links

SikkerLink is a free tool for sending a secret over a link that opens once, then deletes itself. No account needed. Everything is encrypted in your browser, so only the recipient can read it, and the link self-destructs after the first view or when it expires.

Read
May 23, 2026Releases

Single sign-on (SAML 2.0) for your organization

SikkerKey organizations can now sign members in with SAML 2.0 single sign-on (SSO). Connect your identity provider, verify your domains, and new members provision on first sign-in. Offer it next to existing sign-in, or enforce it.

Read
May 19, 2026Releases

Multi-user secrets management with Organizations

Convert a personal vault to an organization, invite people by email, and assign each one a capability template that bundles permissions and project scope. The machine plane is untouched.

Read
May 11, 2026Releases

Temporary machines for scoped, time-bounded access

Provision a single machine with a fixed lifetime from one hour to twelve months, with optional per-machine guardrails covering IP, country, and time-of-day. Manual approval, single-step revert on extensions, and a clear audit signal on every guardrail block.

Read
May 4, 2026Releases

AI agents for Claude Code, Codex, and Cursor

Manage your vault from any MCP-compatible AI client. Ed25519-bound, scope-restricted, fully audited, and structurally unable to read the plaintext content of any stored secret.

Read
May 1, 2026Improvements

Passkey sign-in for the dashboard

Phishing-resistant sign-in via FIDO2/WebAuthn. Register passkeys per device, optionally remove your password entirely with passwordless mode, and use recovery codes if you lose your authenticator.

Read