JetBrains Plugin
Keeper Secrets Manager plugin for JetBrains IDEs development environment
About
JetBrains IDEs are powerful integrated development environments used by millions of developers worldwide for building applications across various programming languages and frameworks. Whether you're developing in Java, Python, JavaScript, or any other supported language, JetBrains IDEs provide comprehensive tools for coding, debugging, and deployment.
The Keeper Security plugin integrates Keeper Vault into JetBrains IDEs so developers can replace hardcoded secrets with vault references and run commands with injected credentials without exposing sensitive data. The plugin supports Classic and Nested Shared Folder vault items in the same actions — folder and record pickers, secret retrieval, record create/update/generate, and secure execution from .env files.
Features
Secret Management: Save, retrieve, and generate secrets directly from JetBrains IDEs using the Keeper Vault
Secure Execution: Run commands with secrets injected from the Keeper Vault through
.envfile processingHTTP Client Integration (IntelliJ IDEA Ultimate / WebStorm / GoLand): Reference vault secrets directly in
.httprequest files using the{{$keeper("uid","field")}}dynamic variable — no plaintext values in request filesRun Configurations: Save a Run Keeper Securely configuration (
.envpath, working directory, command) under Run → Edit Configurations with output streaming to the Run tool windowFolder Management: Select and manage Keeper vault folders for organized secret storage
Record Operations: Create new records, update existing ones, and retrieve field references
Cross-platform support: Windows, macOS, Linux
Nested Shared Folders: Classic and Nested Shared folders and records in the same actions; automatic routing to
record-*ornsf-*Commander commandsSearchable pickers: Folder and record lists include Classic / Nested badges on each row
Community Edition support: Core vault actions work on IntelliJ IDEA Community Edition; HTTP Client integration requires Ultimate / WebStorm / GoLand
Prerequisites
Keeper Commander CLI
Must be installed and authenticated on your system
Download from Keeper Commander Installation Guide
Authenticate using Persistent login or Biometric login
Keeper Security Account: Active subscription with vault access
Nested Shared Folder operations require a recent Keeper Commander with
nsf-*commands. If you see errors such as unknownnsf-record-add, upgrade Commander:see the Nested Shared Folder CLI reference.
System Requirements
JetBrains IDE: Version 2024.3 or later (IntelliJ IDEA, PyCharm, WebStorm, PhpStorm, RubyMine, CLion, GoLand, and other JetBrains IDEs on platform build 243+)
Java: Version 11 or later (provided by the IDE)
HTTP Client (optional):
.http/.restintegration requires an IDE that bundles the JetBrains HTTP Client (e.g. IntelliJ IDEA Ultimate, WebStorm, GoLand). IntelliJ IDEA Community Edition does not include it; all other Keeper actions work normally on Community EditionPython: Version 3.6+ (required for Keeper Commander CLI)
Setup
Installation
Using JetBrains Marketplace
Open your JetBrains IDE
Go to File → Settings → Plugins (or IntelliJ IDEA → Preferences → Plugins on macOS)
Search for "Keeper Security"
Click "Install" and restart the IDE
Authentication
The plugin supports two authentication methods through Keeper Commander CLI:
Method 1: Biometric Authentication
Method 2: Persistent Login
Plugin Verification
Open any JetBrains IDE
Go to Tools → Keeper Vault → Check Keeper Authorization
Verify the authentication status shows success
Usage
All Keeper actions are available through:
Tools Menu: Tools → Keeper Vault → [Action]
Right-click Context Menu: Right-click in editor → [Action]
Available Commands
Check Keeper Authorization
Verify Keeper CLI installation and authentication status
Troubleshoot connection issues and verify setup
Get Keeper Secret
Insert existing secrets from vault as references (Classic or Nested Shared)
Retrieve stored secrets without exposing actual values
Add Keeper Record
Save selected text as a secret in vault and replace with reference (Classic or Nested Shared)
Replace hardcoded secrets with vault references
Update Keeper Record
Update an existing vault record by record UID and field name; routes to Classic or Nested Shared automatically
Modify existing secrets while maintaining references
Generate Keeper Secret
Generate a secure password and store in vault (Classic or Nested Shared)
Create new secure credentials automatically
Get Keeper Folder
Select a Classic or Nested Shared folder for this project (searchable list with badges)
Choose where new records are created for Add / Generate
Run Keeper Securely
Execute a command with secrets injected from a .env file — Tools menu or saved run configuration under Run → Edit Configurations
Run applications or scripts with vault-backed environment variables
Get Keeper Secret (in .http file)
Inserts {{$keeper("uid","field")}} at cursor in JetBrains HTTP Client request files (Ultimate / WebStorm / GoLand only)
Inject vault secrets directly into HTTP requests without exposing values
Nested Shared Folders (plugin 2.0.2)
Keeper supports two vault models that appear together in the plugin:
Classic — traditional vault folders and records (
record-add,record-update, …)Nested Shared Folder — NSF folder and records (
nsf-record-add,nsf-record-update, …)
The plugin picks the correct Commander command family from vault metadata. You do not choose Classic vs Nested manually for each operation.
Folder and record pickers
Get Keeper Folder and Get Keeper Secret show Classic and Nested Shared items in one searchable dialog.
Each row displays a Classic or Nested badge.
Duplicate display names are resolved by record/folder UID internally — the row you click is the one used.
Targeting a folder for new records
Run Tools → Keeper Vault → Get Keeper Folder and pick a folder (Classic or Nested).
The selection is saved for the current project.
Add Keeper Record and Generate Keeper Secret create records in that folder using the matching command family.
Get Keeper Folder is required before Add or Generate. If no folder is saved for the project, those actions prompt you to run Get Keeper Folder first.
Commander requirement
Nested Shared Folder create/update flows need a recent Commander with nsf-* support. Upgrade with pip install --upgrade keepercommander if commands such as nsf-record-add are not recognized.
Basic Secret Management
Retrieving Existing Secrets
Adding New Secrets
Generating Secure Passwords
Secure Command Execution
Environment File Setup
Create a .env file with Keeper references, for example:
Record UID format: Values in keeper:// references must use a valid Keeper record UID (22 URL-safe Base64 characters: A-Z, a-z, 0-9, _, -). Invalid UIDs are skipped and reported as errors at run time.
Running Commands with Injected Secrets
Option 1: Quick run (right-click action)
Right-click in your project → Run Keeper Securely
Select or confirm the
.envfileEnter your command (e.g., python3 app.py)
The plugin resolves secrets from the vault, runs the command, and shows output when the run completes (interactive Tools-menu flow). For repeat runs with full Run-tool-window history, use a saved Run Keeper Securely configuration (see Option 2).
Option 2: Saved Run Configuration (recommended for repeat runs)
Available since plugin version 1.1.0.
Go to Run → Edit Configurations… → + → Run Keeper Securely
Fill in the three fields:
Environment file (.env) — path to your
.envfile containingkeeper://referencesWorking directory — leave empty to use the project root
Command — the command to run (e.g.
python main.py,node app.js)
Click OK and run with the standard Run/Debug toolbar buttons
Output and errors stream directly into the Run tool window — supports re-running, stopping, and full output history
New configurations automatically prefill the Python interpreter (from project SDK or detected venv) and common entry scripts (main.py / app.py / run.py) when found in the project root.
Complete Workflow Example
HTTP Client Integration
Available since plugin version 1.1.0.
Requirement: This feature requires an IDE that bundles the JetBrains HTTP Client plugin — IntelliJ IDEA Ultimate, WebStorm, or GoLand. IntelliJ IDEA Community Edition does not include it. The rest of the Keeper plugin works normally on Community.
Nested Shared Folder records use the same
{{$keeper("RECORD_UID", "field-name")}}syntax as Classic records — the UID is the Keeper record UID regardless of vault model.
The Keeper plugin registers a $keeper dynamic variable for the JetBrains HTTP Client. Use it in any .http or .rest file to reference a vault secret without typing the actual value.
Syntax
RECORD_UID— the Keeper record UID (same as inkeeper://UID/field/...)field-name— the field path (e.g.password,login,custom.api_key)
Example
Authenticated API call
Basic auth
Inserting via Get Keeper Secret
Instead of typing the UID manually:
Open a
.httpfile and position the cursor where you want the referenceTools → Keeper Vault → Get Keeper Secret (or right-click → Get Keeper Secret)
Search and select a record (
ClassicorNested Shared; each row shows a badge), then choose the fieldThe plugin inserts
{{$keeper("uid","field")}}automatically at the cursor
Actions Reference
Check Keeper Authorization
Verifies Keeper CLI installation and authentication status.
Usage: Tools → Keeper Vault → Check Keeper Authorization
Purpose: Troubleshoot connection issues and verify setup
Get Keeper Secret
Retrieves existing secrets from vault as references.
Usage: Position cursor, then Tools → Keeper Vault → Get Keeper Secret (or right-click → Get Keeper Secret)
Properties:
Input: Cursor position in editor
Output: Keeper reference inserted at cursor — format depends on the file type:
.env, .py, .js, scripts, etc.
keeper://record-uid/field/field-name
.http / .rest (HTTP Client)
{{$keeper("record-uid","field-name")}}
Picker: Searchable list of Classic and Nested Shared records; each row shows a Classic or Nested badge
HTTP Client: Requires IntelliJ IDEA Ultimate, WebStorm, or GoLand
Add Keeper Record
Creates a new vault record from selected text and replaces it with a reference.
Usage: Select text, then right-click → Add Keeper Record or Tools → Keeper Vault → Add Keeper Record
Properties:
Input: Selected text containing a secret
Output: Selected text replaced with a
keeper://referencePrompts: Record title, field name
Folder targeting: Run Get Keeper Folder first to store new records in a specific Classic or Nested Shared folder
Required: Run Get Keeper Folder first and save a project folder. Add / Generate do not run without a saved folder.
Routing: Classic folders use
record-add; Nested Shared folders usensf-record-add
Update Keeper Record
Updates an existing vault record with a new value from selected text.
Usage: Select the new secret value (or place the caret on the value after =), then right-click → Update Keeper Record
Properties:
Input: Selected text with the updated secret value
Prompts: Keeper record UID, then field name
Validation: The plugin validates the UID and confirms the record exists before updating
Output: Text replaced with the existing record's
keeper://referenceRouting: Classic records use
record-update; Nested Shared records usensf-record-update
Generate Keeper Secret
Generates a secure password and stores it in the vault.
Usage: Position cursor, then Tools → Keeper Vault → Generate Keeper Secret (or right-click → Generate Keeper Secret)
Properties:
Input: Cursor position
Output: Generated secure password reference inserted at cursor
Prompts: Record title, field name
Folder targeting: Run Get Keeper Folder first to create the record in a specific Classic or Nested Shared folder
Required: Run Get Keeper Folder first and save a project folder. Add / Generate do not run without a saved folder.
Routing: Classic folders use
record-add; Nested Shared folders usensf-record-add
Get Keeper Folder
Selects a Classic or Nested Shared folder for organizing new records in the current project.
Usage: Tools → Keeper Vault → Get Keeper Folder
Properties:
Purpose: Set the project folder used by Add Keeper Record and Generate Keeper Secret
Picker: Searchable list of Classic and Nested Shared folders; each row shows a Classic or Nested badge
Scope: Applies to the current project/workspace
Persistence: Selection remembered across IDE sessions for that project
Routing: Classic selection routes Add/Generate to
record-*; Nested Shared selection routes tonsf-*
Run Keeper Securely
Executes commands with secrets injected from .env file.
Usage: Right-click in the editor → Run Keeper Securely (or Tools → Keeper Vault → Run Keeper Securely)
Properties:
Input:
.envfile with Keeper referencesProcess: Fetches actual secret values from vault
Output: Interactive run (Tools menu or editor right-click) shows output in a dialog when complete; saved Run Configuration streams output to the Run tool window
Security: Secrets are resolved in memory and injected as environment variables; no secret values are written to disk. The subprocess environment is rebuilt from validated vault values plus a minimal whitelist of parent variables (such as
PATHandHOME) — inherited IDE hook variables are not passed throughUID validation:
keeper://record UIDs in the.envfile must be valid 22-character Keeper record UIDs; invalid entries are skipped with an error
Option: Saved Run Configuration (Available since plugin version 1.1.0.)
In addition to the right-click action, Run Keeper Securely is also available as a persistent run configuration type.
Usage: Run → Edit Configurations → + → Run Keeper Securely
Properties:
Environment file: Path to the
.envfile withkeeper://references (relative or absolute)Working directory: Directory the command runs in; empty defaults to the project root
Command: Full command string (e.g.
python main.py,node server.js,./gradlew run)Output: Streams to the Run tool window — supports stop, re-run, and scrollable history
Security: Secrets are resolved in memory and injected as environment variables; no secret values are written to disk
Platforms
The following platforms are supported:
Linux: Ubuntu 18.04+, CentOS 7+, RHEL 7+, Debian 9+, Fedora 30+
macOS: 10.14+ (Mojave and later)
Windows: Windows 10+, Windows Server 2016+
Requirements
JetBrains IDEs
IntelliJ IDEA: 2024.3+
PyCharm: 2024.3+
WebStorm: 2024.3+
PhpStorm: 2024.3+
RubyMine: 2024.3+
CLion: 2024.3+
GoLand: 2024.3+
DataGrip: 2024.3+
Rider: 2024.3+
Dependencies
Java Runtime: 11+ (provided by JetBrains IDE)
Python: 3.6+ (for Keeper Commander CLI)
pip: Latest version (for CLI installation)
Last updated

