Burrow ·

Burrow 5.0.0

Sign in through your company's identity provider with SAML or OIDC, provision members and roles with SCIM, and share a secret by link with view and time limits.

Single sign-on#

Sign in with your identity provider. Connect your company's identity provider over SAML or OIDC under Burrow Settings → SSO. Start by verifying your email domain with a DNS record, and everyone at that domain signs in to your burrow through your identity provider.

Your domain's accounts, managed by you. Existing accounts at a verified domain move to your identity provider the first time they sign in with it, and new people can get an account on their first sign-in. From then on, your identity provider decides who gets in and for how long.

Require SSO. Turn it on and every member except the owner has to sign in through your identity provider. Sessions started any other way end straight away.

SCIM provisioning#

Keep members in step with your directory. Create a SCIM token under Burrow Settings → SCIM and your identity provider adds, updates and removes members for you. Someone removed from your directory loses access to the burrow.

Map groups to roles. Put your directory groups in order and give each one a role. Every member gets the role of the first group they're in, and someone in none of them loses access until they're added to one.

SSO and SCIM are available on eligible plans.

Share a secret by link. Create a link to a secret's value in one environment, with a limit of 1 to 1,000 views and an expiry from 5 minutes to 30 days. Add a generated passphrase, or let only members of your burrow open it. The link shows the value as it was when you made it, and five wrong passphrases destroy it.

See and revoke live links. A secret with live links is marked in the list. Open it to copy a link again, see how many views are left, or revoke it. Share links have their own permissions, so you decide which roles can create, see and revoke them.

Audit log#

More of what happens is recorded. Every share link that's created, opened, refused, revoked or expired is in the audit log, and links opened without signing in show as anonymous. Opening the live console and downloading a log file are recorded too.

.NET SDK reads are named. Secrets read by the .NET SDK now show its name and version, like the other SDKs.

Fixes#

The sign-in page shows your burrow's display name when it has one.

Learn more in the docs.

Burrow

[email protected]

Building RatelKey — a self-hosted secrets manager whose decryption key never leaves your infrastructure.

Keep reading