For it teams
Shared admin access, without shared passwords everywhere
Network gear, cloud consoles, service accounts and SSH keys: keep them in collections your team can use, with a log of who opened what.
Prices and options by email
How to get started today
The problem with passwords here
IT teams hold the most powerful credentials in the organization, and often share them in the least safe ways.
Secrets in too many places
Admin passwords in a spreadsheet, SSH keys on laptops, API tokens in chat history.
Hard to tell who knows what
When someone leaves, nobody is sure which shared passwords they could see.
Second factors that block the team
A shared admin account with two-step login tied to one person's phone.
How KeyCare Pass helps
Collections
One collection per system
Group credentials by system or environment and give each person or group exactly the access they need, up to managing the collection.
- Store SSH keys: generate Ed25519 or RSA keys or import yours
- Keep API tokens and recovery codes in secure notes
- Attach config files and certificates, encrypted
Shared two-step login
Authenticator codes the whole team can use
Put a shared account's authenticator key in its login, in a collection, and everyone with access gets the current code without passing a phone around.
Accountability
Every view and change, logged
The event log records who viewed a password, edited an item or changed a collection, with the IP address. Read it in the Admin Console or pull it with the public API.
Recommended setup
Enterprise, with these policies on
Turn the policies on before you invite anyone, then deploy the extension to managed browsers.
- Require two-step login and set master password requirements
- Single organization, then account recovery administration
- Collections per system, groups per team
- Install the extension with the ExtensionInstallForcelist policy
- Consider self-hosting for networks that must stay closed
Frequently asked questions
Can KeyCare Pass rotate passwords on servers for us?
No. KeyCare Pass stores and shares credentials; it does not log in to your systems to change them. GovPAM's Gov PAM platform does privileged access management of that kind.
Can we use KeyCare Pass from the command line?
A command-line client is not available to download yet. Today, use the web vault or the browser extension.
Can the server run in an isolated network?
A self-hosted KeyCare Pass server does not need to contact GovPAM. Managed computers can get the extension through a browser policy, from the Chrome Web Store or, where the store is blocked, from a signed package. For IT administrators.
Get your team's admin credentials under control
Tell us about your organization, or start setting up today.
Prices and options by email
How to get started today