Secrets continue to leak through development environments. API keys, tokens, and credentials often live outside the tools developers use every day. That gap creates friction, and friction leads to shortcuts.
Keeper Security’s new JetBrains extension is built around that reality.
Eric Kalseth, Senior Director of Global MSP Sales at Keeper Security, describes the issue as structural, not careless behavior, to MSSP Alert.
He says, “When credentials exist in external vaults, developers default to the path of least resistance - like hardcoding credentials, storing them in plaintext config files or copying and pasting them into places they shouldn't be. These aren't malicious decisions; they're workflow friction problems with security implications.”
By embedding secrets management directly into JetBrains IDEs such as IntelliJ IDEA, PyCharm, and GoLand, Keeper is removing the need for developers to step outside their normal workflow to access credentials. That change directly targets secret sprawl, accidental exposure, and security controls that arrive too late to matter. “By embedding vault access directly in the IDE, teams can apply zero-trust principles from the first line of code,” Kalseth said.
From cleanup to prevention
For security teams, credential issues usually surface after damage is done. A leaked API key shows up in a scan, an audit flags hardcoded secrets, or a breach exposes credentials that have already spread across repositories and pipelines. “Traditionally, security teams only discover developer credential issues after an incident,” Kalseth said. “By that point, the damage is already done.”
The JetBrains extension changes that timeline. Integrated with KeeperPAM, every secret accessed inside the IDE is logged in real time, with a clear record of who accessed what and from where. “Every secret retrieval is logged with a detailed audit trail showing who accessed what and from which development environment,” Kalseth explained.
That visibility fills a long-standing blind spot between code repositories and credential stores. Security teams gain centralized insight across all developer IDEs, and secret access events can be streamed into existing SIEM platforms.
“This shifts security teams from post-incident discovery to continuous oversight of credential usage throughout the development lifecycle,” Kalseth said.
What this means for MSSPs
Developer environments have always been difficult for MSSPs to govern consistently. Developers move fast, generate credentials constantly, and often see security controls as an obstacle rather than a safeguard. Kalseth frames the challenge clearly: “MSSPs face a persistent challenge within developer environments, which is accountability without direct control.”
By enforcing zero-trust policies at the point where secrets are accessed, the JetBrains extension removes the need for manual reviews or separate enforcement tools. “Policies are enforced automatically at the point of secret access, without requiring separate tools, manual reviews or ongoing intervention from the MSSP,” Kalseth said.
Least-privilege access and credential rotation are handled centrally through KeeperPAM, which means auditing becomes continuous instead of episodic. “MSSPs no longer rely on written policies or periodic checks; they can demonstrate consistent enforcement and visibility across all client environments by default,” he added.
Differentiation without added complexity
In a crowded PAM market, many solutions bring heavy infrastructure requirements and ongoing services work that limit scalability for MSSPs. Keeper’s approach is designed to avoid that tradeoff. “Its cloud-native, zero-knowledge architecture eliminates the need for MSSPs to deploy or manage infrastructure,” Kalseth said.
Because secrets management runs inside tools developers already use, onboarding friction stays low. MSSPs gain centralized, multi-tenant visibility and built-in reporting without adding delivery overhead. “The result is a scalable service model that delivers embedded, proactive security rather than reactive monitoring,” Kalseth said.
For MSSPs, IDE-level secrets control becomes less about another feature and more about solving a problem that has quietly driven risk for years: security that lives outside the workflow rarely holds up inside it.