Credential governance for MSPs that outgrew the spreadsheet.
EzKey is the partner console for every key you hold: the ones Microsoft issues, and the ones you paste in from anywhere else. Register, reveal with audit, rotate on time, and prove it to anyone who asks.
What the others get wrong
No integration required
Most tools only see what their connectors reach. EzKey tracks any credential for any vendor: paste it in, set the expiry, assign an owner, done.
Evidence, not just reminders
Anyone can email you 30 days before an expiry date. EzKey shows whether a key is really in use, with per-tenant gateway traffic and probe windows, before you rotate or revoke it.
Secrets with a paper trail
Stored secrets are sealed per tenant, and every reveal is written to an append-only audit chain before the secret is ever decrypted.
Key register and audited reveal
Every credential lives in one register, organized per client, integration or not. Reveals are logged: who, when, and why.
Guided Microsoft onboarding
Connect Entra and Azure in minutes with a wizard that asks only for read-only roles and shows you exactly what it will see.
Expiry and staleness findings
Findings surface expired, expiring, unclaimed, overprivileged, rotation-overdue, and stale credentials before they become a problem.
Secrets gateway
Per-tenant gateway hostnames prove which keys are really used, closing the gap between registered and real.
ConnectWise tickets
Findings open and close ConnectWise tickets on their own, so your PSA reflects reality without manual entry.
Azure Key Vault and storage keys
Discover Key Vault secrets, keys, and certificates alongside storage account keys, whose rotation age is tracked automatically. Storage-key retrieval evidence comes straight from Azure's own activity log. EzKey governs your clients' keys without needing them: every read is a metadata listing, never a secret value.
Signed webhooks
Findings deliver as signed webhook payloads your tools can verify, retried on a backoff schedule and dead-lettered if they never land.
Team governance
Roles, invites, and an append-only audit chain cover every change your team makes.
Built to be trusted with keys
You are granting a vendor visibility into your clients' credentials. Here is why that is safe.
- Read-only where it counts. The Microsoft roles EzKey requests can list metadata, never fetch secret values. The only place EzKey writes is your PSA, to open and close the tickets you asked for.
- We never call listKeys. Storage key evidence comes from Azure's own activity log.
- Escrowed secrets are sealed per tenant with authenticated encryption.
- Every reveal is audited before the secret is decrypted. No trail, no reveal.
- Azure sign-in tokens live only in your session and expire within minutes. EzKey never stores them.
Built for MSPs
Multi-tenant by design.
Findings become tickets in your PSA.
Every reveal leaves a trail.
No onboarding alert storm: existing issues arrive as one baseline summary, not a ticket flood.
Scoped REST API tokens and email alerting, included.
Pricing
Our price list is on this page. You should not have to book a call to find out what software costs.
The first tenant is free.
30 days free, no card, up to 25 tenants.
Billed monthly. No minimum term.
| Billable tenants | Price |
|---|---|
| 1 to 5 | $45 a month |
| 6 to 10 | $9 per tenant a month |
| 11 to 25 | $7 per tenant a month |
| 26 to 50 | $5.50 per tenant a month |
| 51 to 100 | $4.50 per tenant a month |
| 101 to 171 | $3.50 per tenant a month |
| 172 and above | $599 a month |