← Package directory
Available on winget

Install Keeper Commander

Keeper Commander is a python-based CLI and SDK interface to the Keeper Security platform. Provides administrative controls, reporting, import/export and vault management.

Install with winget
winget install --id KeeperSecurity.Commander
Upgrade
winget upgrade --id KeeperSecurity.Commander
Uninstall
winget uninstall --id KeeperSecurity.Commander

About Keeper Commander

Keeper Commander is a command-line and SDK interface to Keeper® Password Manager. Commander can be used to access and control your Keeper vault, perform administrative functions (such as end-user onboarding and data import/export), launch remote sessions, rotate passwords, eliminate hardcoded passwords and more. Keeper Commander is an open source project with contributions from Keeper's engineering team and partners.

What's new in 18.0.15

Keeper Commander release v18.0.13 New Features • CyberArk → KeeperPAM migration — Added a new pam project cyberark-import command to migrate CyberArk safes, accounts, platforms, and policies into KeeperPAM. See docs/cyberark-pam-import.md for details. Improvements • import --no-shortcuts — Added a --no-shortcuts flag to the import command. When an imported record is identical to an existing vault record, import normally creates a shortcut; with --no-shortcuts it creates a new record instead.

Read release notes

Version history

Version Updated Notes
18.0.15 Unknown Keeper Commander release v18.0.13 New Features • CyberArk → KeeperPAM migration — Added a new pam project cyberark-import command to migrate CyberArk safes, accounts, platforms, and policies into KeeperPAM. See docs/cybe...
18.0.13 Unknown Keeper Commander release v18.0.13 New Features - CyberArk → KeeperPAM migration — Added a new pam project cyberark-import command to migrate CyberArk safes, accounts, platforms, and policies into KeeperPAM. See docs/cybe...
18.0.12 Unknown Keeper Commander release version v18.0.12 New Features - CNAPP integration commands — Added new commands and helpers for CNAPP (Cloud-Native Application Protection) integration. - Slack multi-channel approvals — Added se...
18.0.11 Unknown Commander 18.0.11 Bug Fixes - Import command — Records are now only updated when they belong to the same folder as the import target. - PAM config list — Fixed CRON expression parsing dropping the seconds field from 6-pa...
18.0.10 Unknown What's New in 18.0.10 New Features - Vault-style passphrase generation — Added passphrase generation to Commander CLI. - PAM action service map — New pam action service map command to map users to discovered Windows serv...
18.0.9 Unknown New Features - KeeperAI PAM Connection Settings (pam connection ai) New command to manage KeeperAI settings on PAM resources and remote browser instances. Supports show, set, unset, and remove operations for AI configura...
18.0.8 Unknown Keeper Commander 18.0.8 PAM: Expanded Database Protocol Support - pam connection edit and pam import now support seven additional database protocols: mariadb, oracle, mongodb, redis, elasticsearch, clickhouse, and dynamo...
18.0.7 Unknown Keeper Commander release v18.0.7 Bug fixes - kcm-import --output filename tighten file permissions
18.0.6 Unknown Keeper Commander 18.0.6 New Features - Universal Secret Sync — New commands to configure and run synchronization of secrets across networks: - pam universal-sync-config (alias usc) — manage sync configurations with list/...
18.0.5 Unknown Keeper Commander 18.0.5 ✨ New Features - Universal Secret Sync — new commands for syncing secrets across providers. - Cloud secret import to Nested Shared Folders — import cloud secrets directly into Nested Shared Folder...
18.0.4 Unknown Keeper Commander 18.0.4 Security - Service mode hardening: Restricted cross-API-key usage on GET requests and blocked command injection via line breaks in service-mode payloads. New features - share-folder --roe / list-s...
18.0.3 Unknown Keeper Commander release version v18.0.3 Highlights - Added nhi-report for Non-Human Identity reporting. - Added OS-native keychain storage for Commander configuration. - Renamed KeeperDrive CLI commands from the kd-* pr...
18.0.2 Unknown Keeper Commander 18.0.2 Features & Enhancements - connect / ssh: confirmation prompt before shell command execution - pam search --device — new flag to look up PAM Gateways and the PAM Configurations bound to them - shar...
18.0.1 Unknown Keeper Commander 18.0.1 Breaking changes - Dropped Python 3.7 support. Minimum supported Python is now 3.8 New commands & features SSO / Identity - New sso-cloud command suite for managing Keeper SSO Connect Cloud config...
18.0.0 Unknown Keeper Commander 18.0.0 — Release Notes This is a major release headlined by KeeperDrive — a brand-new command suite for managing folders, records, sharing, and permissions through the Keeper API. It also adds KCM/Guacam...
17.2.15 Unknown Keeper Commander 17.2.15 — Release Notes PAM bug fixes - Added proper error message when Workflow blocks connection - Increased WebRTC connect timeout to accomodate for ephemeral accounts - Added JIT / Ephemeral suport t...
17.2.13 Unknown Keeper Commander release version v17.2.13 PAM Fixes - Fix rotation settings linking to PAM Configuration instead of PAM Directory when directory_uid is provided - Skip email delivery gracefully when email.config_name is...
17.2.12 Unknown Release Notes — v17.2.12 New Features - Bulk Legacy Record Conversion — Added convert-all command for converting legacy records in bulk - Secrets Manager Client Revoke — Added command for quick device revocation in secre...
17.2.11 Unknown Release Notes — v17.2.11 (April 1, 2026) New Features - Atlassian Onboarding: Added AD user creation via Gateway with support for username templates. - Domain Alias Commands — New commands for managing domain aliases. -...
17.2.10 Unknown Keeper Commander release version v17.2.10 New Features - CSPM Integration Type — Added CSPM as a supported integration type for public-api-key - pam action debug command — New pam action debug command that dumps all reco...