Skip to main content
Glama
KN0WBOT

clavis-mcp-server

Clavis MCP Server

Secure credential management for Claude Desktop and MCP servers.

Features

  • 🔐 Encrypted credential storage (AES-128-CBC + HMAC-SHA256, via Fernet)

  • 🛡️ Server-side credential injection — the raw key never enters the conversation

  • 🔄 Automatic OAuth token refresh

  • 📡 Thin forwarding layer — rate limiting, audit logging, and usage tracking are all handled by the Clavis server

Related MCP server: GhostKey

Installation

npx @clavisagent/mcp-server

Or install globally:

npm install -g @clavisagent/mcp-server

Usage with Claude Desktop

Add the following to your Claude Desktop configuration file (claude_desktop_config.json):

{
  "mcpServers": {
    "clavis": {
      "command": "npx",
      "args": ["-y", "@clavisagent/mcp-server"],
      "env": {
        "CLAVIS_API_KEY": "eyJ..."
      }
    }
  }
}

Usage with Claude Code

claude mcp add clavis -- npx -y @clavisagent/mcp-server

Configuration

Variable

Required

Default

Description

CLAVIS_API_KEY

yes

Your Clavis JWT, from POST /v1/auth/login. Not the cla_… key shown at sign-up.

CLAVIS_API_URL

no

https://clavisagent.com

Base URL of your Clavis instance. Set this for self-hosted deployments.

Available Tools

Tool

Description

call_service

Recommended. Make an API call with server-side credential injection — the credential is injected into the upstream request server-side, so the raw key never enters the conversation.

get_credentials

Legacy. Returns the raw access token or API key for a named service. Prefer call_service.

list_services

List all services with stored credentials

check_credential_status

Check the status and expiry of credentials for a service

Security note

Prefer call_service over get_credentials. call_service keeps the secret server-side, so a prompt injection has no credential in context to exfiltrate. get_credentials places the raw key in the conversation and exists only for callers that must hold the token themselves.

License

MIT

Install Server
A
license - permissive license
A
quality
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    Encrypted credential vault with a 21-tool MCP server. Store and manage LLM API keys, service API keys, and OAuth credentials — then let your AI agent list, reveal, rotate, rename, pause, and proxy calls through them.
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    MCP-native credential vault that enables AI agents to authenticate with external services without exposing secrets, supporting bearer, basic, OAuth2, and other auth patterns via MCP tools.
    7
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    Credential vault for LLM agents that stores credentials encrypted and exposes MCP tools for authenticated HTTP requests, web scraping, and credential management, preventing AI assistants from seeing secrets.
    Apache 2.0

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/KN0WBOT/clavis-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server