Skip to main content
Glama
KN0WBOT

clavis-mcp-server

by KN0WBOT

Clavis MCP Server

Secure credential management for Claude Desktop and MCP servers.

Features

  • 🔐 Encrypted credential storage (AES-128-CBC + HMAC-SHA256, via Fernet)

  • 🛡️ Server-side credential injection — the raw key never enters the conversation

  • 🔄 Automatic OAuth token refresh

  • ⚡ Distributed rate limiting

  • 📊 Audit logging on every credential access

Related MCP server: GhostKey

Installation

npx @clavisagent/mcp-server

Or install globally:

npm install -g @clavisagent/mcp-server

Usage with Claude Desktop

Add the following to your Claude Desktop configuration file (claude_desktop_config.json):

{
  "mcpServers": {
    "clavis": {
      "command": "npx",
      "args": ["-y", "@clavisagent/mcp-server"],
      "env": {
        "CLAVIS_API_KEY": "eyJ..."
      }
    }
  }
}

Usage with Claude Code

claude mcp add clavis -- npx -y @clavisagent/mcp-server

Configuration

Variable

Required

Default

Description

CLAVIS_API_KEY

yes

Your Clavis JWT, from POST /v1/auth/login. Not the cla_… key shown at sign-up.

CLAVIS_API_URL

no

https://clavisagent.com

Base URL of your Clavis instance. Set this for self-hosted deployments.

Available Tools

Tool

Description

call_service

Recommended. Make an API call with server-side credential injection — the credential is injected into the upstream request server-side, so the raw key never enters the conversation.

get_credentials

Legacy. Returns the raw access token or API key for a named service. Prefer call_service.

list_services

List all services with stored credentials

check_credential_status

Check the status and expiry of credentials for a service

Security note

Prefer call_service over get_credentials. call_service keeps the secret server-side, so a prompt injection has no credential in context to exfiltrate. get_credentials places the raw key in the conversation and exists only for callers that must hold the token themselves.

License

MIT

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/KN0WBOT/clavis-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server