Optanik Keyring
The vault that lives with the fleet.
Every endpoint already has a login, an Optanik IP, an OS, and a BitLocker key when one exists. Keyring keeps those secrets next to the machines — then lets Keymasters add folders, shares, and TOTP the same way they would in Keeper.
- Same Optanik account
- Auto endpoint entries
- REST & MCP
- $1.50 / Keymaster
How it works
Login and register use Optanik, then we forward you in.
There is no separate Keyring account. The same email you use on Optanik opens the vault — the same pattern as Optanik Ticketing.
-
01
Open Keyring
Come to optanikkeyring.com and hit Login or Get started.
-
02
Sign in on Optanik
We send you to app.optanik.com with next=keyring. Register if you do not have an account yet.
-
03
MFA if you use it
Optanik keeps the session. After the code, we mint a Keyring SSO and bring you back.
-
04
Land in the vault
Folders for Windows, Linux, and MAC OS are already there. Endpoint entries are waiting.
The vault
Built like Keeper. Wired to the fleet.
Default OS folders. One entry per hostname. Share a folder or a single secret. Add TOTP to any login.
Windows, Linux, MAC OS
Every workspace starts with those three folders. New endpoints land in the right one by OS.
Endpoint entries
IP, Optanik IP, OS, Optanik username and password, and BitLocker when the agent has a key.
Keeper record types
Logins, cards, notes, SSH keys, Wi-Fi, licenses, passports, and the rest of the Keeper set.
Authenticator codes
Store a TOTP secret on an entry and Keyring shows the rotating code in the vault.
Share by email
Share a folder or one record with another user on the workspace, or invite by email.
Auto-sync
When Optanik adds an endpoint, Keyring creates the entry. Existing machines were backfilled.
API & MCP
Full control from REST and MCP.
Create folders, write entries, share, and delete from Cursor, Claude, or any REST client. Reads work for everyone with a key. Writes need a Full key and a paid Keymaster — unless the workspace is exempt.
REST API
Bearer keys on the Optanik API. Same workspace. Same folders and records you see in the vault.
- GET /api/keyring/folders
- POST /api/keyring/folders
- GET /api/keyring/records
- POST /api/keyring/records
- POST /api/keyring/shares
MCP access
Optanik MCP tools for the vault. List, get, create, update, share, and delete without leaving the agent.
- keyring_list_folders
- keyring_list_records
- keyring_upsert_record
- keyring_share
- keyring_delete
Write gate
Unpaid users stay read-only over MCP and REST, including the owner. Exempt workspaces get full write for every member.
- 402 when a Keymaster seat is needed
- Checkout URL on the error
- Exempt = unlimited Keymasters
Why Keyring
Secrets next to the machines they belong to.
One Optanik login
Login and Register on this site open Optanik, then SSO you into the vault. Logout signs you out of both.
Encrypted at rest
Record fields are encrypted in the Keyring database. The public site never stores a second password.
Keymasters
$1.50 per user per month to edit system entries and create your own. The owner is not included for free.
Pricing
Pay for the people who hold the keys.
Everyone can read what the fleet already synced. Writing costs a Keymaster seat.
Keymaster
$1.50 / user / month
- Edit endpoint entries Optanik created
- Create folders and every Keeper record type
- Share folders and individual secrets
- Write from the web, REST, and MCP
- Owner is not free — subscribe that user too
Read only
$0 / included
- See synced endpoint logins
- Copy values you already have rights to
- MCP and REST stay read-only
- Exempt workspaces skip this and get full write
Looks like Optanik because it is Optanik.
Same account, same workspace, same MFA. Sign in here, or start without an Optanik account — we create both, then forward you into the vault.