Skip to main content
Glama
AIWerk

@aiwerk/mcp-server-vault

by AIWerk

@aiwerk/mcp-server-vault

Bitwarden / Vaultwarden MCP server — BYOK vault access for AI agents.

Exposes 6 tools over stdio. Secret values are never sent in plaintext through list_vault_items or get_vault_metadata — secrets are delivered only through Bitwarden Sends (E2E-encrypted one-time URLs).

Install

npx -y @aiwerk/mcp-server-vault

Related MCP server: VaultBridge

Configure

Variable

Required

Default

Description

VAULT_API_BASE

Base URL of your Bitwarden/Vaultwarden instance (no trailing slash), e.g. https://pass.aiwerk.ch

VAULT_CLIENT_ID

Personal API key client_id (e.g. user.abc-def-1234)

VAULT_CLIENT_SECRET

Personal API key client_secret

VAULT_MASTER_PASSWORD

Vault master password (used for E2E decryption key derivation)

VAULT_EXPOSED_COLLECTION

mcp-exposed

Name of the collection visible to agents

VAULT_AGENT_CREATED_COLLECTION

mcp-agent-created

Name of the collection for agent-created secrets

VAULT_API_TIMEOUT_MS

15000

HTTP timeout in milliseconds

DRY_RUN

0

Set 1 to log write operations without executing them

READ_ONLY

0

Set 1 to block all write operations (Send creation and save)

Auth — Personal API Key

  1. Log in to your Bitwarden/Vaultwarden instance

  2. Go to Account Settings → Security → Keys → API Key

  3. Note the client_id and client_secret

  4. Reference: https://bitwarden.com/help/personal-api-key/

Vault Setup

Before using this server, create two collections in your Vaultwarden organization:

  • mcp-exposed — items you want to expose to agents (your existing secrets: API keys, passwords, etc.)

  • mcp-agent-created — items written by agents via save_generated_secret

Add items to mcp-exposed via the Vaultwarden web UI.

Custom fields

Optionally add these custom fields to items in mcp-exposed for fine-grained control:

Field

Type

Purpose

mcp-scope

text

Comma-separated glob list of tool/server names allowed to use this item (e.g. stripe.*,openai)

mcp-chat-reveal-allowed

text

"true" to allow chat delivery of the Send URL

mcp-delivery-channel

text

"chat" (default), "telegram", or "email"

Tools

Tool

Description

list_vault_items

List items from mcp-exposed and mcp-agent-created. Returns metadata only — no secret values.

get_vault_metadata

Get full metadata for a named item (name, type, username, URIs, custom fields, expiry). No password/secret.

reveal_secret_via_send

Reveal a secret via a Bitwarden Send (E2E-encrypted one-time URL with configurable TTL and max-views).

get_totp_code

Get the current TOTP code for a login item, including remaining seconds in the period.

save_generated_secret

Save an agent-generated secret (password / api-key) into mcp-agent-created as a secure note. CREATE-only — no overwrite.

save_login_item

Save sign-in credentials (username + password + optional URL + TOTP seed) into mcp-agent-created as a real login item. CREATE-only — no overwrite.

health_check

Check connectivity: auth status, API version, collection visibility, item counts, latency.

Security model

  • Opt-in exposure: only items in mcp-exposed or mcp-agent-created are accessible; all other items return item_not_visible

  • Read-only existing items: no update_*, delete_*, or change_* tools exist

  • Secret value delivery via Send only: list_vault_items and get_vault_metadata never return passwords, TOTP seeds, or api-key values

  • E2E encryption preserved: the server decrypts vault data locally (master password stays in env vars, never sent over the wire)

  • Constrained agent writes: save_generated_secret and save_login_item are CREATE-only into the dedicated mcp-agent-created collection

Note: Actual {{vault:NAME}} placeholder resolution in tool call arguments happens in the AIWerk hosted bridge, not in this server. The bridge's resolution uses the same BYOC credentials. See the bridge-patch companion document for details.

License

MIT — AIWerk kontakt@aiwerk.ch

Homepage: https://aiwerkmcp.com

Install Server
A
license - permissive license
A
quality
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    MCP server for Vaultwarden/Bitwarden vault management. Enables AI agents to securely create, search, read, and update vault items via the official Bitwarden CLI, with safe-by-default redaction and support for both stdio and SSE transports.
    53
    341
    12
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Secret management MCP server for AI coding agents that prevents secrets from entering the LLM context window by returning metadata only and using side-channel injection. Integrates with Bitwarden and offers hooks for auto-capture and leak prevention.
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server for using Bitwarden Secrets Manager as durable credential storage for agent workflows, enabling secure secret storage, retrieval, and injection into trusted executables.
    7
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server enabling AI agents to use secrets (API keys, tokens) via encrypted vault, executing HTTP/shell/SSH actions server-side while never exposing secret values to the AI.
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/AIWerk/mcp-server-vault'

If you have feedback or need assistance with the MCP directory API, please join our Discord server