Log inJoin the waitlist

Search the help center, features, guides and more.

Business

Your team's passwords. Nobody else's.

An admin console, single sign-on, SCIM, policies and audit logs, on the end-to-end encryption that protects a person's vault. Built so that not even our server can change who's in your organization.

A company's members in the Vallkey admin console, each with a role and their key's fingerprint.

For teams and companies

Admin control, without admin access for us.

Admins decide who gets what. Nobody but a vault's members, and your admins, can read it.

  • Admin console

    People, groups and vaults in one place, with who can reach what, in the web vault.

  • Single sign-on

    Okta, Microsoft Entra ID, Google Workspace or any OpenID Connect or SAML 2.0 provider, in both plans.

  • SCIM 2.0 provisioning

    Your identity provider adds and removes people and groups. Someone deactivated loses your vaults at once.

  • Policies

    Master password strength, locking, exports, Travel Mode and no sharing outside the company, signed so no server can relax them.

  • Audit logs

    Sign-ins, members, groups, vaults, policies, and items opened or filled, sent to a webhook, Splunk, Datadog, Microsoft Sentinel or S3.

  • Offboarding

    When someone leaves, see every item they could open and which still hold what they saw. Change each with the password fixer, and download a report.

  • Fill-only access

    Let someone sign in with a login without ever seeing, copying or exporting its password.

  • Device approval

    A member's logged-in device lets their new one in. If you allow it, an admin can let in someone who lost every device.

  • Key connector

    Run it on your own servers, and your people have no master password at all. It alone opens nothing.

Why it's different

Our server can't add a member. It can't make an admin.

Organizations are where other password managers were broken: in 2026, researchers showed a malicious server changing who was in one, and reading what it shared. In Vallkey the server stores and passes things along, and holds no say.

  • A roster only you can sign

    Members, roles, groups, who has which vault, and your policies are one signed document. The key that signs it lives only on your admins' devices.

  • Every device checks it

    A member's device takes a roster only with your organization's signature, by the key it pinned when it joined and checked against the public key log.

  • Taking away is immediate

    The one thing a server can always do is stop sending. So removing someone works at once, and adding someone always takes an admin's device.

Single sign-on

SSO that can't read your vaults.

Your identity provider says who someone is. It never holds the keys to their vault, and neither do we.

  1. A member logs in

    On a new device, with their master password and Secret Key as always. Those still make every key, on the device.

  2. Your identity provider vouches

    The app opens your provider's sign-in page and shows a six-digit code. Your second factors and device checks apply.

  3. They allow it

    A page asks whether to allow this login, showing the same six digits. Only then does the device get the organization's vaults.

Deactivate someone at your provider, and they get no new session. A company that wants no master passwords at all can run a key connector on its own servers. How single sign-on works

Roles and access

Who can do what.

Give a vault to a group or to one person, to edit, to view, or only to fill.

Owners
Everything an admin can, and make or remove admins and owners.
Admins
Invite and remove people, make groups and vaults, grant access, set policies.
Members
Use the vaults granted to them or to their groups.
On a vaultSees passwordsFills themAdds and changes
Can edit
Can view
Fill onlySigns in, and never sees the password

For your engineers

Secrets out of .env files, and out of chat.

The command line gives scripts and builds what they need from a vault, by reference.

  • Command line

    Secrets for a command's environment or a config file, named by reference and never pasted.

  • Service accounts

    A token for CI that opens only the vaults shared with it, and is taken back by deleting it.

  • AI-agent logins

    An agent asks, a person approves, and Vallkey fills the page. The agent never sees the password.

The foundation

What every plan stands on.

The same core, in every app, for a person and for a company.

  • Shared vaults, with new keys

    Removing someone gives the vault, and every item in it, a new key.

  • Key transparency

    Every key you share to is checked against a public log, so a server can't slip in its own.

  • Signed vaults

    Each vault carries a signed manifest: devices catch a server that drops, rolls back or changes items.

  • Every platform

    Windows, Mac, Linux, iPhone, Android and every major browser, with the same protections everywhere.

  • Works offline

    Each device keeps the vault, encrypted. An outage pauses sync and locks nobody out.

  • Import from what you use

    1Password, LastPass, Bitwarden, Dashlane, Keeper and more, with a report before anything is saved.

Pricing

Simple per-user pricing. SSO included.

A new organization tries everything for 14 days. After that, a price locked for as long as you stay, like every Vallkey plan.

Teams

For small teams.

$4/user/monthbilled monthly

Talk to sales
  • Organization vaults and groups
  • Admin console, with fill-only access
  • Single sign-on included
  • Audit log in the console
  • Price locked while you stay

Business

For teams and companies.

$7/user/monthbilled monthly

Talk to sales
  • Everything in Teams
  • SCIM provisioning
  • Policies for exports and Travel Mode
  • Audit log sent to your SIEM
Teams
$1,200a year, at $4 a person each month
Business
$2,100a year, at $7 a person each month

Prices in US dollars, billed each month for each person, with single sign-on included. A new organization tries everything for 14 days.

More than 500 people, or need an invoice or a purchase order? Talk to us.

Questions teams ask

How do we start?

Talk to us. We'll set up your organization, and every new organization tries everything for 14 days.

Is single sign-on an extra?

No. It's part of both Teams and Business. SCIM, sending the audit log to your log system, and the policies for exports and Travel Mode take Business.

Can our identity provider read our vaults?

No. It says who someone is, and never holds a key. Each person's keys come from their master password and Secret Key, on their own devices. A company that wants no master passwords at all can run a key connector on its own servers.

Can Vallkey's staff read our vaults, or add someone to our organization?

No. Vaults are encrypted on your people's devices with keys we never have, titles, website addresses and tags included. And who's in your organization is signed with a key only your admins' devices hold, which every member's device checks.

Can admins read everything?

Admins can open every vault of the organization: that's what lets them grant access. They can't open a member's own vaults, unless you turn on letting admins approve members' new devices, which every member's app then says plainly.

What happens when someone leaves?

Every vault they had gets a new key, so nothing saved afterwards reaches them. Offboarding then lists each item they could open and which still hold what they saw, with a button to change each password, and a report.

Can we host it ourselves?

The same server that runs Vallkey Cloud runs on your own machines., with organizations, single sign-on, SCIM and audit logs included.

Where is our data stored?

In the region you choose: Vallkey Cloud has separate regions in the United States and the European Union, and each account stays in the region chosen at sign-up, backups included.

How do we move from 1Password, LastPass or Bitwarden?

Each person exports from the old app and imports the file in Vallkey, which shows what will come over before anything does. The switch guides show each step.

Will you sign a DPA, and do you take purchase orders?

Yes: a data processing agreement is part of the terms, and it's on the legal pages. Plans are bought by card, by an organization's owner. For annual contracts, invoices and purchase orders, tell us what your purchasing needs.

Be one of the first teams.

Tell us about your team, and we'll talk about what you need.