teleport_unpack
Decrypt a packed bundle and import each contained secret into the local keyring. Preview with dryRun first; v1 requires passphrase, v2 uses your keyring identity.
Instructions
[teleport] Decrypt a bundle produced by teleport_pack and import each contained secret into the local keyring. Use on the receiving machine after a packer hands you the bundle; prefer dryRun=true first to preview what will be written. Passphrase (v1) bundles need passphrase. Recipient (v2) bundles need no input: this machine's teleport identity is read from the OS keyring (create one with qring teleport keygen; the private key is never returned). When dryRun is false this mutates the keyring (one 'write' event per imported secret) at the requested scope. Bad passphrase, missing identity, not-a-recipient or tampered bundle returns JSON { ok: false, error: { message } } with isError: true. On success returns 'Imported N secret(s) from teleport bundle'; in dryRun mode returns 'Would import N secrets:' followed by a KEY [scope] listing (v2 also lists the recipient ids the bundle is addressed to).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| orgId | No | Organization identifier for org-scoped secrets. Required only when scope='org'. Example: 'acme-corp'. | |
| scope | No | Where the secret lives. 'global' = user keyring (default if omitted on reads), 'project' = scoped to projectPath, 'team' = team-shared (needs teamId), 'org' = org-shared (needs orgId). | global |
| bundle | Yes | Base64-encoded ciphertext returned by `teleport_pack`. Pass through whitespace untouched if possible. | |
| dryRun | No | If true, decrypt and report what would be written but do not mutate the keyring. Useful for verifying bundle contents before commit. | |
| teamId | No | Team identifier for team-scoped secrets. Required only when scope='team'. Example: 'acme-platform'. | |
| passphrase | No | The passphrase used to pack a v1 bundle. Omit for v2 recipient bundles (decrypted with this machine's keyring identity). Bad passphrases return an authentication error rather than wrong plaintext. | |
| projectPath | No | Absolute path to the project root for project-scoped secrets and policy resolution. Defaults to the MCP server's current working directory when omitted. |