Keyring

Optanik Keyring

The vault that lives with the fleet.

Every endpoint already has a login, an Optanik IP, an OS, and a BitLocker key when one exists. Keyring keeps those secrets next to the machines — then lets Keymasters add folders, shares, and TOTP the same way they would in Keeper.

  • Same Optanik account
  • Auto endpoint entries
  • REST & MCP
  • $1.50 / Keymaster

How it works

Login and register use Optanik, then we forward you in.

There is no separate Keyring account. The same email you use on Optanik opens the vault — the same pattern as Optanik Ticketing.

  1. 01

    Open Keyring

    Come to optanikkeyring.com and hit Login or Get started.

  2. 02

    Sign in on Optanik

    We send you to app.optanik.com with next=keyring. Register if you do not have an account yet.

  3. 03

    MFA if you use it

    Optanik keeps the session. After the code, we mint a Keyring SSO and bring you back.

  4. 04

    Land in the vault

    Folders for Windows, Linux, and MAC OS are already there. Endpoint entries are waiting.

The vault

Built like Keeper. Wired to the fleet.

Default OS folders. One entry per hostname. Share a folder or a single secret. Add TOTP to any login.

Windows, Linux, MAC OS

Every workspace starts with those three folders. New endpoints land in the right one by OS.

Endpoint entries

IP, Optanik IP, OS, Optanik username and password, and BitLocker when the agent has a key.

Keeper record types

Logins, cards, notes, SSH keys, Wi-Fi, licenses, passports, and the rest of the Keeper set.

Authenticator codes

Store a TOTP secret on an entry and Keyring shows the rotating code in the vault.

Share by email

Share a folder or one record with another user on the workspace, or invite by email.

Auto-sync

When Optanik adds an endpoint, Keyring creates the entry. Existing machines were backfilled.

API & MCP

Full control from REST and MCP.

Create folders, write entries, share, and delete from Cursor, Claude, or any REST client. Reads work for everyone with a key. Writes need a Full key and a paid Keymaster — unless the workspace is exempt.

REST API

Bearer keys on the Optanik API. Same workspace. Same folders and records you see in the vault.

  • GET /api/keyring/folders
  • POST /api/keyring/folders
  • GET /api/keyring/records
  • POST /api/keyring/records
  • POST /api/keyring/shares

MCP access

Optanik MCP tools for the vault. List, get, create, update, share, and delete without leaving the agent.

  • keyring_list_folders
  • keyring_list_records
  • keyring_upsert_record
  • keyring_share
  • keyring_delete

Write gate

Unpaid users stay read-only over MCP and REST, including the owner. Exempt workspaces get full write for every member.

  • 402 when a Keymaster seat is needed
  • Checkout URL on the error
  • Exempt = unlimited Keymasters

Why Keyring

Secrets next to the machines they belong to.

One Optanik login

Login and Register on this site open Optanik, then SSO you into the vault. Logout signs you out of both.

Encrypted at rest

Record fields are encrypted in the Keyring database. The public site never stores a second password.

Keymasters

$1.50 per user per month to edit system entries and create your own. The owner is not included for free.

Pricing

Pay for the people who hold the keys.

Everyone can read what the fleet already synced. Writing costs a Keymaster seat.

Read only

$0 / included

  • See synced endpoint logins
  • Copy values you already have rights to
  • MCP and REST stay read-only
  • Exempt workspaces skip this and get full write
Login

Looks like Optanik because it is Optanik.

Same account, same workspace, same MFA. Sign in here, or start without an Optanik account — we create both, then forward you into the vault.