Skip to main content
Glama
Infisical

Infisical MCP Server

Official
by Infisical

Infisical Model Context Protocol

The Infisical Model Context Protocol server allows you to integrate with Infisical APIs through function calling. This protocol supports various tools to interact with Infisical.

Setup

Environment variables

In order to use the MCP server, you must first set the environment variables required for authentication.

  • INFISICAL_AUTH_METHOD: The authentication method to use. Supported values are universal-auth and access-token. Defaults to universal-auth.

  • INFISICAL_UNIVERSAL_AUTH_CLIENT_ID: The Machine Identity universal auth client ID. Required when INFISICAL_AUTH_METHOD is universal-auth.

  • INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET: The Machine Identity universal auth client secret. Required when INFISICAL_AUTH_METHOD is universal-auth.

  • INFISICAL_TOKEN: An access token for authentication. This can be both a personal access token or a machine identity access token. Required when INFISICAL_AUTH_METHOD is access-token.

  • INFISICAL_HOST_URL: Optionally set a custom host URL. This is useful if you're self-hosting Infisical or you're on dedicated infrastructure. Defaults to https://app.infisical.com.

See Limiting what the server exposes for two optional variables that restrict which tools are available and whether secret values are returned.

To run the Infisical MCP server using npx, use the following command:

npx -y @infisical/mcp

Usage with Claude Desktop

Add the following to your claude_desktop_config.json. See here for more details.

Universal Auth (default)

{
  "mcpServers": {
    "infisical": {
      "command": "npx",
      "args": ["-y", "@infisical/mcp"],
      "env": {
        "INFISICAL_HOST_URL": "https://<custom-host-url>.com",
        "INFISICAL_UNIVERSAL_AUTH_CLIENT_ID": "<machine-identity-universal-auth-client-id>",
        "INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET": "<machine-identity-universal-auth-client-secret>"
      }
    }
  }
}

Access Token

{
  "mcpServers": {
    "infisical": {
      "command": "npx",
      "args": ["-y", "@infisical/mcp"],
      "env": {
        "INFISICAL_HOST_URL": "https://<custom-host-url>.com",
        "INFISICAL_AUTH_METHOD": "access-token",
        "INFISICAL_TOKEN": "<your-access-token>"
      }
    }
  }
}

Available tools

Tool

Description

create-secret

Create a new secret

delete-secret

Delete a secret

update-secret

Update a secret

list-secrets

Lists all secrets

get-secret

Get a single secret

create-project

Create a new project

create-environment

Create a new environment

create-folder

Create a new folder

invite-members-to-project

Invite one or more members to a project

list-projects

List all projects

Limiting what the server exposes

Both variables are optional, and their defaults keep the server's existing behaviour.

  • INFISICAL_ENABLED_TOOLS: a comma-separated allowlist of tools to expose, using the tool names from the table above (for example list-projects,list-secrets,get-secret for a read-only server). Tools left out are hidden from tools/list and refused if called. An unknown name fails at startup. Omit the variable to expose every tool.

  • INFISICAL_MASK_SECRET_VALUES: true or false, case-insensitive. Defaults to false. When true, secret values in tool responses are replaced with <masked>, keeping secret material out of the model's context. Secret names, paths, and other metadata are still returned.

Scope the machine identity to only the projects and environments the server needs, rather than using a token with broader access than the exposed tools require.

Debugging the Server

To debug your server, you can use the MCP Inspector.

First build the server

npm run build

Run the following command in your terminal:

# Start MCP Inspector and server
npx @modelcontextprotocol/inspector node dist/index.js

Instructions

  1. Set the environment variables as described in the Environment Variables step.

  2. Run the command to start the MCP Inspector.

  3. Open the MCP Inspector UI in your browser and click Connect to start the MCP server.

  4. You can see all the available tools and test them individually.