Keyvaci

Integration · Microsoft Entra ID

The team vault that opens
with your Microsoft identity

If your organisation runs Microsoft 365 or Entra ID (formerly Azure AD), every member already has their Keyvaci sign-in. No new passwords to distribute, no user lists to upload, no directory changes to review.

What the integration does

Directory-verified from the very first click

Admin-gated signup

Only a Global Administrator or Privileged Role Administrator of your tenant can create your organisation. Keyvaci verifies the role from Microsoft's own signed tokens, blocking anyone from squatting your company's name.

Standards, not agents

OpenID Connect with PKCE, multi-tenant, tokens verified against Microsoft's published keys on every request. Nothing to install in your tenant, nothing running inside your network.

Lifecycle that follows Entra

Members sign in with their work account. Suspend or remove them in Entra ID and Keyvaci access goes with it; revoking their vault access additionally re-encrypts the vaults they could open.

SSO without weakening encryption

Entra ID answers who you are. What you can decrypt still comes only from your master password, derived on your device. The two systems are separated by design, so adding SSO never dents the zero-knowledge property.

Your MFA policy rides along

Conditional Access, MFA, device compliance: whatever your directory enforces at sign-in applies to Keyvaci automatically, because sign-in is your directory.

Five-minute setup

Sign in, confirm your admin role, save the recovery kit your browser generates, invite the team. Most organisations store their first shared credential inside the first coffee.

Setup, in full

Three steps, no ticket to IT

Sign in with Microsoft

Your tenant admin clicks "Start with Microsoft" and consents to the Keyvaci application, exactly like any Microsoft 365 app. Optional tenant-wide admin consent removes the per-user prompt.

Create the organisation

Keyvaci verifies the admin role, then your browser generates the organisation's signing and recovery keys locally, shows them once, and never sends them to us.

Invite by email

Members sign in with their existing Microsoft account and are recognised automatically. Each sets a master password, gets countersigned by an admin, and starts receiving vaults.

Your Entra sign-in works in all three clients: the web console, the browser extension, and the mobile app on iPhone and Android. The extension hands the sign-in to a window owned by the browser, which it cannot script or read, so a password vault never sees the company password protecting everything else. Running Google Workspace instead? Google sign-in is available now.

Entra ID questions

Asked by every IT admin so far

Does this require changes to our Entra ID tenant?

No. Keyvaci is a standard multi-tenant OIDC application. Users consent at first sign-in like with any Microsoft 365 app; a tenant admin can optionally grant consent for everyone at once. Nothing is written to your directory.

Who can create our organisation?

Only a Global Administrator or Privileged Role Administrator of your tenant, verified from the directory-role claims in Microsoft's signed tokens, checked server-side against Microsoft's keys. An intern with a work email cannot register your company.

Does SSO weaken the zero-knowledge encryption?

No, because sign-in and decryption are separate systems. Entra ID proves who you are. Decryption keys are derived from your master password, on your device, and neither the password nor the keys are ever transmitted. Full detail on the security page.

What about members who are not in our tenant?

Guest scenarios and email-based members are supported through email sign-up with mandatory verification, with the same encryption and the same countersignature step before they can receive any vault. Partners running Google Workspace can sign in with their own directory instead.

Your tenant is the hard part. It's done.

Everything else takes minutes. 14 days, every feature, no card.