Skip to main content
Glama
gpitrella
by gpitrella

MCP-Secrets-Vault

Security-first secrets vault for MCP servers, Claude Code, Cursor, and AI agents.

License: AGPL v3 npm MCP Compatible

Stop hardcoding API keys in .env files and MCP configs. MCP-Secrets-Vault stores credentials encrypted (AES-256-GCM) on your machine and exposes them to AI clients via MCP tools.

Quick Start

npx @gpitrella/mcp-secrets-vault init
# Set VAULT_PASSPHRASE in ~/.mcp-secrets-vault/.env
npx @gpitrella/mcp-secrets-vault set openai_key sk-your-key
npx @gpitrella/mcp-secrets-vault get openai_key

Related MCP server: Credential Vault MCP

Claude Desktop / Cursor

{
  "mcpServers": {
    "secrets-vault": {
      "command": "npx",
      "args": ["-y", "@gpitrella/mcp-secrets-vault"],
      "env": {
        "VAULT_PASSPHRASE": "your-passphrase"
      }
    }
  }
}

MCP Tools

Tool

Description

set_secret

Store encrypted credential

get_secret

Retrieve decrypted credential

rotate_secret

Rotate value (keeps 5 versions)

list_secrets

List metadata (no values)

delete_secret

Soft or hard delete

search_secrets

Full-text search

import_env

Bulk import from .env content

export_env

Export as .env format

dashboard

Interactive HTML dashboard

CLI

npx @gpitrella/mcp-secrets-vault init
npx @gpitrella/mcp-secrets-vault set <name> <value> [--workspace=default]
npx @gpitrella/mcp-secrets-vault get <name>
npx @gpitrella/mcp-secrets-vault list
npx @gpitrella/mcp-secrets-vault import .env --workspace=memxus
npx @gpitrella/mcp-secrets-vault export --workspace=memxus
npx @gpitrella/mcp-secrets-vault gen-key

Security

  • Bound to 127.0.0.1 only for HTTP (NeighborJack defense)

  • AES-256-GCM with Node.js crypto (zero third-party crypto deps)

  • Strict Zod validation, additionalProperties: false on all tools

  • Audit logs never contain secret values

  • All dependencies pinned to exact versions

See docs/SECURITY.md for the threat model.

License

AGPL v3 — See LICENSE.

Vault Cloud (coming soon)

Self-hosted is free forever. Hosted tier with team workspaces, RBAC, and compliance reports.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    B
    maintenance
    Secure credential management for AI agents — encrypted storage, auto-refresh, and rate limiting via a single MCP call. Supports OpenAI, Anthropic, Stripe, GitHub, Brave Search, Kalshi, Coinbase, plus generic API key and OAuth2 for any service.
    Last updated
    43
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    MCP-native credential vault that enables AI agents to authenticate with external services without exposing secrets, supporting bearer, basic, OAuth2, and other auth patterns via MCP tools.
    Last updated
    6
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    Enables AI agents to securely manage API keys and secrets via the MCP protocol, with encrypted storage at rest and a simple CLI and Python SDK.
    Last updated
    MIT

View all related MCP servers

Related MCP Connectors

  • Encrypted secret store and rotation for autonomous agent credentials

  • Encrypted A2A object storage for autonomous agent state and artifacts

  • Issue, rotate and revoke scoped API-key passes for 25+ providers — the agent never sees a real key

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/gpitrella/mcp-secrets-vault'

If you have feedback or need assistance with the MCP directory API, please join our Discord server