What is new in SikkerKey
Product updates, security improvements, and platform changes. Subscribe to the feed to stay current.
RSS feedA redesigned dashboard and a rebuilt overview
The dashboard has a refreshed look throughout: a rebuilt overview that shows your role and access at a glance, cleaner and faster tables, smoother loading across every page, redesigned dialogs, and clearer pickers for platforms and webhook integrations.
Read full update →Redis leased credentials, verified connections, a grant builder, and Discord and Slack alerts
Leased credentials now support Redis, verify your database's certificate on every connection, and build grant templates instead of writing SQL by hand. Webhooks get a guided setup flow and post to Discord and Slack, and you can export your audit log as CSV, JSON, or text.
Read →Bring your own key, encrypt a vault with a key you control
Encrypt a vault with a key you hold in your own cloud KMS. Access runs through your own cloud console, so revoking it makes the vault unreadable until you restore access. Google Cloud KMS is supported today, with OVH, Scaleway, and AWS planned.
Read →See each AI agent's exact access, and reconfigure them anytime
Each AI agent now shows the exact applications and projects it can reach, and you can change its capabilities and access anytime from its settings. Plus a guided setup for managed secrets and performance improvements to the dashboard.
Read →Leased Credentials, on-demand database logins that expire on their own
Connect a database once and let your machines mint short-lived logins on demand. Each machine gets its own credential that renews while in use and is revoked when it expires or its machine is turned off. Available for PostgreSQL today, with more providers planned.
Read →Organization roles and security hardening
A two-role model for organization members, refreshed core documentation, and a round of security hardening.
Read →Group a service's projects with Applications
Group the projects for one service, its Prod, Staging, and Dev, under one named application created in a single step. They appear grouped in the dashboard sidebar and the CLI, and the CLI can scope listing, export, and run to one application.
Read →Stronger isolation for the key that protects your secrets, plus reliability fixes
The root key that unlocks your secrets now runs on separate, isolated infrastructure, so a copy of the database alone can't be decrypted. Plus: removing a machine from a project is fixed, and our status page now reports webhook delivery.
Read →See the audit trail for any machine, AI agent, or member
View a dedicated audit trail for any single machine, AI agent, or organization member, filtered by action, severity, and time. The Machines page also gains a Default view and clearer status labels, and large vaults stay fast across the dashboard.
Read →Secret retrieval that scales under load, plus reliability and security hardening
Your applications can now pull secrets in far greater volume at once without slowing each other down, and a slow database no longer ripples into unrelated requests. Plus tighter brute-force lockout counting under simultaneous attempts and steadier long-run stability.
Read →Alerts for blocked access attempts, plus security and reliability hardening
Connections from an IP outside your allowlist now show in your audit log and alerts. Plus single-use two-factor codes, stricter webhook delivery, canary tripwires and read limits that now cover bulk export, and more resilient managed-secret rotation.
Read →More reliable secret access, plus security improvements
Secret retrieval for your applications now runs on its own dedicated infrastructure, so it stays fast and available on its own. We also fixed a problem that could lock machines out by mistake, and strengthened protection for machine connections and automated secret rotation.
Read →