AgentVault MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| AGENTVAULT_URL | Yes | The URL of the AgentVault server | |
| AGENTVAULT_TOKEN | Yes | The authentication token for AgentVault |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| av_create_vaultC | Create a new vault. |
| av_put_secretB | Create or update a secret (name + field map) in a vault. |
| av_get_secretC | Get the decrypted field map of a secret. |
| av_resolveA | Resolve an av://vault/secret/field reference to a single value. |
| av_list_secretsA | List secret names in a vault. |
| av_issue_tokenB | Mint a scoped Agent Access Token (requires admin token). |
| av_rotate_secretC | Rotate (replace) a secret's value. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 7 tools
While av_get_secret and av_resolve both retrieve secret data, av_get_secret returns the full field map while av_resolve targets a specific field via reference. av_put_secret and av_rotate_secret are similarly distinct (create/update vs. replace). The purposes are mostly clear, though the boundary between get/resolve and put/rotate could momentarily confuse.
The av_ prefix is consistent, and most tools follow av_<verb>_<noun> (create_vault, put_secret, get_secret, list_secrets, issue_token, rotate_secret). The verb style is uniform, but 'av_resolve' lacks an explicit object, a minor deviation.
With 7 tools, the set is well-scoped for a vault management server, fitting the typical 3-15 range. Each tool addresses a distinct operation without redundancy or bloat.
The server covers the core lifecycle of vaults and secrets: create, read, update, list, rotate, and token issuance. However, there is no delete operation for vaults or secrets, which could be considered a gap for complete lifecycle management, though it may be intentional for security.