Skip to main content
Glama
ceweldy

bitwarden-agent-vault-mcp

by ceweldy

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
BWS_ACCESS_TOKENNoBitwarden machine access token (required on non-macOS, optional on macOS if stored in Keychain)
BITWARDEN_AGENT_CONFIGNoPath to custom config.json file (default: ~/.config/bitwarden-agent-vault/config.json)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
statusA

Check local CLI installation, machine-token availability, and optional live Bitwarden access without exposing credentials.

list_projectsA

List Bitwarden Secrets Manager projects accessible to this machine identity. Returns metadata only.

list_secretsA

List secret names and metadata, optionally filtered by project or search text. Values are never returned by this tool.

get_secretA

Return one secret value in plaintext by UUID or exact key when private configuration explicitly enables plaintext reveal.

store_secretA

Create a stable secret or update the existing exact-key match in one project. The returned result omits the secret value.

run_with_secretsA

Run one privately allowlisted executable with only the selected project secrets injected as environment variables. Command execution is disabled by default. Exact secret values are redacted from returned output.

open_bitwardenA

Open the Bitwarden Secrets Manager web vault, narrowed to a project when a project UUID is supplied.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4/5.0

Scored across 7 tools

Disambiguation5/5

Each tool serves a distinct purpose: retrieving plaintext secrets, listing metadata, running commands with injected secrets, opening the vault, checking status, and storing secrets. No overlapping functionality.

Naming Consistency4/5

Most tool names follow a verb_noun pattern (e.g., get_secret, list_projects). The use of 'status' (a noun) and 'run_with_secrets' (verb plus preposition) are minor deviations but still clear.

Tool Count5/5

With 7 tools covering key operations (list, get, store, execute, navigate, check), the count is well-scoped for the server's purpose without superfluous tools.

Completeness4/5

Core CRUD and lifecycle operations are present, including read, create/update, and execution. Missing a dedicated delete tool, but store_secret can update, so only a minor gap.

Maintenance

ActivityInactive
ResponsivenessNo issues