envbouncer
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@envbouncerwhat environment variables am I allowed to read?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
envbouncer
A tiny local MCP server and CLI that lets AI agents read only allowlisted environment variables, redacts known secrets from text, and logs every access.
๐ฏ Why?
AI coding agents and MCP servers often need environment variables, but giving them full shell or .env access risks leaking secrets. Existing guardrails mostly block dangerous shell commands or reduce context, but do not broker environment-variable access at runtime. EnvBouncer fills that gap with a declarative allowlist, redaction tooling, and an audit trail.
Target audience: Developers using Claude Code, Cursor, Codex, or custom MCP servers who want to grant agents limited access to environment configuration without exposing the entire .env file or shell environment.
Related MCP server: Agentic Vault
โจ Features
โจ Declarative TOML allowlist for environment variables
โจ MCP tools for listing, reading, and redacting allowed variables
โจ CLI commands for init, check, redact, audit, and stdio MCP serving
โจ JSONL audit trail for reads, denials, missing variables, and redactions
๐ Quick Start
# Install
pip install envbouncer
# Run
envbouncer --help๐ฆ Installation
From Source
git clone https://github.com/YOUR_USERNAME/envbouncer.git
cd envbouncer# Create virtual environment
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
# Install in development mode
pip install -e ".[dev]"
# Run tests
pytest -v๐ฌ Demo
The GIF above was recorded using Charm VHS:
vhs < demo.tape๐ Usage
# Show help
envbouncer --help
# Common usage examples
envbouncer --example๐๏ธ Architecture
graph LR
A[Input] --> B[Core Engine]
B --> C[Output]
B --> D[Plugins]
D --> E[Extensions]๐ค Contributing
Contributions are welcome! Please:
Fork the repo
Create a feature branch (
git checkout -b feature/amazing-feature)Commit your changes (
git commit -m 'Add amazing feature')Push to the branch (
git push origin feature/amazing-feature)Open a Pull Request
๐ License
MIT ยฉ 2026 โ See LICENSE for details.
If this project helped you, please โญ star it!
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Security firewall for AI agents โ scans MCP calls for injection, secrets, and risks.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceLocal-first CLI and MCP server for redacting sensitive text before sharing logs, configs, and errors with AI tools.MIT
- AlicenseNot gradedqualityCmaintenanceMCP server that lets AI agents call APIs without ever seeing the credentials, using a local encrypted vault and per-secret allowlist policies for HTTP requests and subprocess environment variables.1AGPL 3.0
- FlicenseAqualityCmaintenanceA local-first secrets vault for MCP clients that lets AI assistants use secrets by injecting them into child processes, without the plaintext ever entering the model's context.5-
- AlicenseAqualityBmaintenanceA deterministic MCP server that guards AI/agent output by detecting secrets, injection, and PII in ~85ยตs with zero dependencies. Gives a clear ship/block verdict and runs locally or hosted.2Apache 2.0