Infisical MCP Server
OfficialInfisical Model Context Protocol
The Infisical Model Context Protocol server allows you to integrate with Infisical APIs through function calling. This protocol supports various tools to interact with Infisical.
Setup
Environment variables
In order to use the MCP server, you must first set the environment variables required for authentication.
INFISICAL_AUTH_METHOD: The authentication method to use. Supported values areuniversal-authandaccess-token. Defaults touniversal-auth.INFISICAL_UNIVERSAL_AUTH_CLIENT_ID: The Machine Identity universal auth client ID. Required whenINFISICAL_AUTH_METHODisuniversal-auth.INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET: The Machine Identity universal auth client secret. Required whenINFISICAL_AUTH_METHODisuniversal-auth.INFISICAL_TOKEN: An access token for authentication. This can be both a personal access token or a machine identity access token. Required whenINFISICAL_AUTH_METHODisaccess-token.INFISICAL_HOST_URL: Optionally set a custom host URL. This is useful if you're self-hosting Infisical or you're on dedicated infrastructure. Defaults tohttps://app.infisical.com.
See Limiting what the server exposes for two optional variables that restrict which tools are available and whether secret values are returned.
To run the Infisical MCP server using npx, use the following command:
npx -y @infisical/mcpUsage with Claude Desktop
Add the following to your claude_desktop_config.json. See here for more details.
Universal Auth (default)
{
"mcpServers": {
"infisical": {
"command": "npx",
"args": ["-y", "@infisical/mcp"],
"env": {
"INFISICAL_HOST_URL": "https://<custom-host-url>.com",
"INFISICAL_UNIVERSAL_AUTH_CLIENT_ID": "<machine-identity-universal-auth-client-id>",
"INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET": "<machine-identity-universal-auth-client-secret>"
}
}
}
}Access Token
{
"mcpServers": {
"infisical": {
"command": "npx",
"args": ["-y", "@infisical/mcp"],
"env": {
"INFISICAL_HOST_URL": "https://<custom-host-url>.com",
"INFISICAL_AUTH_METHOD": "access-token",
"INFISICAL_TOKEN": "<your-access-token>"
}
}
}
}Available tools
Tool | Description |
| Create a new secret |
| Delete a secret |
| Update a secret |
| Lists all secrets |
| Get a single secret |
| Create a new project |
| Create a new environment |
| Create a new folder |
| Invite one or more members to a project |
| List all projects |
Limiting what the server exposes
Both variables are optional, and their defaults keep the server's existing behaviour.
INFISICAL_ENABLED_TOOLS: a comma-separated allowlist of tools to expose, using the tool names from the table above (for examplelist-projects,list-secrets,get-secretfor a read-only server). Tools left out are hidden fromtools/listand refused if called. An unknown name fails at startup. Omit the variable to expose every tool.INFISICAL_MASK_SECRET_VALUES:trueorfalse, case-insensitive. Defaults tofalse. Whentrue, secret values in tool responses are replaced with<masked>, keeping secret material out of the model's context. Secret names, paths, and other metadata are still returned.
Scope the machine identity to only the projects and environments the server needs, rather than using a token with broader access than the exposed tools require.
Debugging the Server
To debug your server, you can use the MCP Inspector.
First build the server
npm run buildRun the following command in your terminal:
# Start MCP Inspector and server
npx @modelcontextprotocol/inspector node dist/index.jsInstructions
Set the environment variables as described in the Environment Variables step.
Run the command to start the MCP Inspector.
Open the MCP Inspector UI in your browser and click Connect to start the MCP server.
You can see all the available tools and test them individually.