LICENSEWARE

Keeper Security MSP and partner licensing

This article is about KeeperMSP consumption-based billing, MSP base plans and Secure Add-Ons, and the Keeper Partner Terms for resellers, distributors, MSP resellers and MSP distributors. For direct business subscriptions see Keeper Security licensing.

On This Page

KeeperMSP is Keeper Security’s multi-tenant offering for managed service providers. An MSP administers its own Keeper tenant and a separate tenant for each Managed Company (MC), and licences are billed under Keeper’s consumption model.[4] Keeper’s billing platform “will track your account’s daily license usage and bill you monthly, in arrears”.[1] Keeper contrasts KeeperMSP with Keeper Enterprise, which is “built for a single organization managing its own users”. KeeperMSP adds a multi-tenant layer for allocating licences across client tenants.[8] Catalog program: KeeperMSP consumption-based billing.

The commercial relationship is set by the Partner Terms, which sit on Keeper’s legal page next to the SaaS Terms of Use. They define four channels: Resellers, Distributors, MSP Resellers and MSP Distributors.[7] Catalog program: Keeper Partner Terms.

Editions

Each Managed Company is placed on a base plan. “Business” plans are for smaller businesses that do not need advanced provisioning. “Enterprise” plans add Active Directory, SSO, Microsoft Entra ID and SCIM provisioning.[3] All base plans include an encrypted vault, shared team folders, unlimited devices, role-based access controls, security audit, activity reporting, 2FA and 100 GB of Secure File Storage.[3] Business Plus and Enterprise Plus include ARAM, BreachWatch and 1TB of Secure File Storage.[2] Catalog rows: KeeperMSP Business base plan, KeeperMSP Enterprise base plan, KeeperMSP Business Plus and Enterprise Plus. Catalog proof: MSP Enterprise base plans add advanced provisioning; MSP Plus plans include ARAM, BreachWatch and 1TB storage.

Metrics

The base metric is the Average Daily License Usage. Licences in use are counted and stored daily. The average is “the total of all daily counts, divided by the number of days in a billing cycle”.[1] Secure Add-Ons use these units.[2]

Secure Add-On Unit used to calculate charges 
Secure File Storage per day(s) in use (pro-rated) 
ARAM per user 
BreachWatch per user 
KeeperChat per user 
Compliance Reporting per user 
Keeper Connection Manager (KCM) per KCM user (specified by MC) 
Keeper Secrets Manager (KSM) per API call bundle 
Dedicated Service & Support flat monthly rate 

Source: Secure Add-Ons (Keeper MSP).[2] Catalog proof: MSP Secure Add-On charge units. KeeperPAM is also a Secure Add-On that MSPs “can add or remove at any time” for Managed Companies.[12]

Counting / floors

Daily average, monthly in arrears. “Keeper maintains daily license counts for MSP internal and Managed Company licenses. At the end of the month, daily average license counts are used to calculate the monthly charges.”[1] Bills are generated on the first day of the following month, with a PDF breakdown per Managed Company.[1] Licence allocation, which in practice means adding users in an MC, “triggers consumption billing for the base plan and most secure add-on features”.[3] Catalog proof: MSP licences billed on average daily usage, monthly in arrears.

Exceptions to averaging. Dedicated services and support “is billed for the entire month if enabled for any day within the month”.[1] Catalog proof: MSP dedicated service and support billed for the whole month.

No commitment, optional cap. Keeper lists “No long-term commitments on licenses” among the model’s features.[1] An MSP Admin can set an optional maximum number of licences for each Managed Company. “by default, there is no limit”.[4] Catalog proof: MSP may cap licences per Managed Company.

Removing users. “Once a user is deleted, starting the following day that user will not be counted toward the MCs daily license count.” The vault is deleted with the account. Personal and Family Plan vaults are not affected.[5] The documentation names deletion as the step that ends counting. Catalog proof: Deleted MSP user stops counting the following day.

Legacy licence pools. Some MSPs still hold pre-purchased licence pools. Their accounts move to consumption billing based on the pool balance, and the switch is automatic once current entitlements “match or exceed your consumption”.[6] Catalog proof: Legacy MSP licence pools convert to consumption billing.

Reconciliation

Billing Statements in the Managed Companies section show a daily summary and a per-Managed-Company view of base plan and add-on usage.[2] The Admin REST API exposes monthly billing usage, with unit price, quantity and cost per product and MC, and a current-usage snapshot. The API requires an active MSP or Distributor account and the ARAM add-on.[11] KeeperMSP consolidates billing “at the MSP level, so you’re working from a single invoice”.[8] Catalog proof: MSP billing consolidated at MSP level.

Virtualization & partitioning

Not applicable to the licence count, which is per user, per day or per API call bundle. Tenants are isolated by region: accounts are created in US, EU, CA, AU, JP or US_GOV, and “the region cannot be changed without re-creating the environment”.[4] Catalog proof: Data region cannot be changed without re-creating the tenant.

Partner Terms

Grant. Keeper grants a partner “a non-exclusive right to sell, resell or distribute the Keeper software and services via the Channel(s)” and Territories approved in the Partner Portal and the Schedule 1. The Schedule 1 holds pricing, discounts and channel obligations, and controls over the Partner Terms on its subject matter.[7]

Channel Sells to Contract with end customer Remits to Keeper 
Reseller End Customers directly End Customers agree to the TOU Annually in advance 
Distributor Authorised Resellers only Resellers must bind End Customers to the TOU Annually in advance 
MSP Reseller End Customers directly MSP Reseller is “the sole contracting counterparty (Keeper terms, including the TOU shall not apply)” Monthly in arrears (Net 30) on Keeper’s licence reporting 
MSP Distributor Authorised MSP Resellers only Binds MSP Resellers to s.2(c) Annually in advance 

Source: Partner Terms s.2.[7] Catalog proof: Resellers bind End Customers to the Terms of Use and pay annually in advance; MSP Resellers pay monthly in arrears on Keeper licence reporting.

An MSP Reseller is also responsible to its End Customers for provisioning, primary training and support, data security and regulatory compliance, and all billing.[7] A company served by an MSP Reseller therefore has no direct Keeper entitlement. Its users are counted in the MSP’s consumption. MSP Distributors are excluded from the consumption billing method and “will continue to be invoiced through Keeper’s partner team”. MSPs supplied by a distributor receive monthly invoices without prices.[1] Catalog proof: Consumption billing does not apply to MSP Distributors.

Audit and reporting. Partners send monthly sales reports by Channel and End Customer. They must “promptly cooperate with Keeper in any audit or review reasonably required to confirm compliance”.[7] Catalog proof: Partners must cooperate with Keeper compliance audits.

Pricing changes and termination. Pricing, discounts and deal registration rules are set in the Partner Portal and may change on 30 days’ notice. Either party may end the Partner Terms on 30 days’ written notice.[7] If a partner materially breaches its payment obligations, Keeper may let affected End Users “convert their accounts into direct Keeper customer accounts”.[7] Catalog proof: Keeper may convert end users to direct accounts on partner non-payment.

Programs

Moving between MSPs

A Managed Company can be isolated into a stand-alone instance, or moved to another MSP. Once removed from its current MSP, “the managed company will automatically be transitioned to an Enterprise Trial account for a period of 14 days”. Users on SSO must first switch to master passwords, and roles and teams must be recreated at the new MSP.[5] Catalog proof: Managed Company removed from an MSP becomes a 14-day Enterprise trial.

Out of scope

  • Per-unit MSP prices, Schedule 1 discounts and Partner Portal program terms, none of which are public.
  • KSM API call bundle sizes, which are not published.
  • Third-party PSA billing integrations described in Keeper’s documentation, which do not change licence terms.

References

  1. Consumption-Based Billing (Keeper MSP)Undated. Catalog: Consumption-Based Billing (Keeper MSP)Retrieved 2026-10-07.
  2. Secure Add-Ons (Keeper MSP)Undated. Catalog: Secure Add-Ons (Keeper MSP)Retrieved 2026-10-07.
  3. Getting Started (Keeper MSP)MSP base plans. Undated. Catalog: Getting Started (Keeper MSP)Retrieved 2026-10-07.
  4. Fundamentals (Keeper MSP)Undated. Catalog: Fundamentals (Keeper MSP)Retrieved 2026-10-07.
  5. Offboarding (Keeper MSP)Undated. Catalog: Offboarding (Keeper MSP)Retrieved 2026-10-07.
  6. Existing MSP Admins (Keeper MSP)Licence pool to consumption transition. Undated. Catalog: Existing MSP Admins (Keeper MSP)Retrieved 2026-10-07.
  7. Keeper Security Terms of Use for Web, SaaS and PartnersPartner Terms ss.1-11. Undated.Retrieved 2026-10-07.
  8. Password Manager for MSPs - KeeperMSPBilling FAQ. Undated. Catalog: Password Manager for MSPs - KeeperMSPRetrieved 2026-10-07.
  9. Free Trial (Keeper MSP)Undated. Catalog: Free Trial (Keeper MSP)Retrieved 2026-10-07.
  10. Become a Keeper MSP PartnerPartner tiers. Undated. Catalog: Become a Keeper MSP PartnerRetrieved 2026-10-07.
  11. MSP Billing (Keeper Commander Admin REST API)Billing usage and current usage endpoints; requires ARAM. Undated.Retrieved 2026-10-07.
  12. KeeperPAM Licensing (KeeperPAM documentation)KeeperPAM as an MSP Secure Add-On. Undated.Retrieved 2026-10-07.

See also

Catalog Rows Cited

5Programs3SKUs18Rules4Metrics

Esc