SaaSPass
SaaSPass is where your team keeps the logins, API keys and backup codes that would otherwise sit in a spreadsheet or a chat thread. You store each secret once, choose who can see it, and get told when something is close to expiring or has turned up in a known password breach.
What's included
| Page | What it's for |
|---|---|
| SaaSPass | Browse and search every item you can see, filtered by vault, folder, or type |
| Expiring soon | Items that have already expired or expire within the next 30 days |
| Share links | Time-limited links that give someone outside your team access to specific items |
Getting started
- Open SaaSPass from the sidebar.
- Select Add item.
- Pick a Type — Password, API key, Backup codes, or Secure note — and enter a Name. The type can't be changed later.
- Choose a Vault. Personal (only you) keeps the item to yourself; Team (shared with everyone) shares it with your whole workspace.
- Fill in Expires on if the secret has a renewal date, then select Create item.
Organising and finding items
The items table shows Type, Name, Username, Folder, Expiry, Status, and Updated — metadata only. Secrets are never included in the list.
- Use the Vaults rail to switch between All vaults, your personal vault, the team vault, and any shared vaults you belong to.
- Use the Vault folders rail to narrow to one folder, or select New folder to add one. A folder created while a specific vault is selected belongs to that vault.
- Use the type tabs — All, Passwords, API keys, Backup codes, Notes — and the Search items box to filter further.
- Select a row to open the item, where Reveal, Copy secret, Edit, and Delete live. A revealed secret hides itself again automatically after 30 seconds.
Sharing with your team
Personal items stay with you. To share with named colleagues rather than the whole workspace, select
New shared vault, then use Manage members to add people as viewer, editor, or admin.
To move an existing item, open it and change its vault — the modal notes that this is how you "Move this item to another vault to change who can see it."
Expiry and breach alerts
Items with an Expires on date get a badge: Expired, Expires today, or Expires in N days once they are inside 30 days. The Expiring soon page groups them into Expired, Next 7 days, and Next 30 days.
Stored passwords are checked against the HaveIBeenPwned breach corpus, which SaaSy re-runs weekly. A match shows a Breached badge in the Status column and a Seen in N breaches note on the item; a clean item reads No known breaches. Use Breached only to list just the affected items. The breach notice tells you to change the password everywhere it's used, then update the vault entry.
Sending a secret outside your team
- Open Share links and select Create share link.
- Choose the Items to include — up to 50 per link.
- Set Expires (1 hour up to 30 days, defaulting to 7 days), an optional View limit, and an optional Passphrase of at least 8 characters.
- Tick One-time link to make the link stop working after its first reveal.
- Select Create link, then Copy the URL. It is shown once and never again. If you set a passphrase, send it through a separate channel — it is not part of the link.
Each share has an Access log recording Viewed details, Revealed secret(s), Wrong passphrase, and Blocked (expired, revoked, or used up) events with an IP and timestamp. Select Revoke to kill a link immediately.
How secrets are stored
Secrets are encrypted per workspace on the SaaSy server before they are written to the database, and list and search views never return them. Because SaaSy holds the encryption key, this is not end-to-end or zero-knowledge encryption. Creating, updating, deleting, and revealing an item are each recorded in your workspace audit log.
Availability
SaaSPass is on by default in every vertical pack, so it appears in your sidebar whichever industry you picked. If it's missing, check Settings → Navigation.
SaaSPass is included free with every SaaSy plan — Starter, Growth, and Scale. There is no free tier, so an active subscription is required. It can also be bought on its own, priced by band, if you don't have a plan. Without an entitlement, opening the page shows an upsell card instead of the vault.
See Modules, packs, and plans for how visibility and entitlement interact.