teleport_pack
Encrypt selected secrets into a single AES-256-GCM bundle for safe transfer between machines. Choose passphrase or recipient public keys to control who can decrypt.
Instructions
[teleport] Encrypt one or more secrets into a single AES-256-GCM bundle string that can be safely transferred between machines. Use to hand off a curated set of credentials to another developer or environment; prefer export_secrets for plaintext .env output (single machine, trusted) and tunnel_create for ephemeral one-shot delivery on the same machine. Two modes, exactly one required: passphrase (v1, symmetric — receiver needs the same string) or recipients (v2, public-key — each receiver's qring1... string from qring teleport identity; no shared secret, only the listed identities can open it). Reads each secret value (records 'export' audit events) and produces a base64-encoded ciphertext. Returns the bundle string directly. Errors with 'No secrets to pack' if the filter matched zero secrets.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| keys | No | Whitelist of exact key names to include. Omit to pack every secret in the requested scope. | |
| orgId | No | Organization identifier for org-scoped secrets. Required only when scope='org'. Example: 'acme-corp'. | |
| scope | No | Where the secret lives. 'global' = user keyring (default if omitted on reads), 'project' = scoped to projectPath, 'team' = team-shared (needs teamId), 'org' = org-shared (needs orgId). | |
| teamId | No | Team identifier for team-scoped secrets. Required only when scope='team'. Example: 'acme-platform'. | |
| passphrase | No | Symmetric passphrase used to derive the AES-256-GCM key (v1 bundle). The receiver must supply the same string to `teleport_unpack`. Pick something high-entropy and share it out-of-band. Mutually exclusive with `recipients`. | |
| recipients | No | Recipient public keys (`qring1...` strings, one per teammate) for a v2 recipient pack. The bundle can only be opened by the matching private keys, which each receiver created with `qring teleport keygen`. Mutually exclusive with `passphrase`. | |
| projectPath | No | Absolute path to the project root for project-scoped secrets and policy resolution. Defaults to the MCP server's current working directory when omitted. |