TKeeper documentation

TKeeper gives machines, agents, services, and workflows a cryptographic identity whose use is constrained by explicit authorities and policy.

Read first

Common paths

Goal Start here
Understand the product What is TKeeper?
Map it to your use case Use Cases
Run it locally Local Single Node
Build an artifact Build and Features
Design backup and recovery Backup and Recovery
Choose mono or threshold Quorum Modes
Create and govern identities Create, Rotate, and Refresh
Govern signing Authorities
Select cryptographic platforms Platforms
Use the HTTP API OpenAPI
Run integration tests Integration Tests
Review executable security evidence Security Assurance

By audience

Reader Recommended path
Application integrator Getting Started -> Signing -> Java SDK or OpenAPI
Security reviewer Security Model -> Threat Model -> Security Assurance -> Status and Limitations
Platform operator Deployment -> Production Checklist -> Operations
Cryptography reviewer Crypto Platforms -> Quorum Modes -> Anvil threat model