Skip to main content
Glama
gpitrella
by gpitrella

MCP-Secrets-Vault

Security-first secrets vault for MCP servers, Claude Code, Cursor, and AI agents.

License: AGPL v3 npm MCP Compatible

Stop hardcoding API keys in .env files and MCP configs. MCP-Secrets-Vault stores credentials encrypted (AES-256-GCM) on your machine and exposes them to AI clients via MCP tools.

Quick Start

npx @gpitrella/mcp-secrets-vault init
# Set VAULT_PASSPHRASE in ~/.mcp-secrets-vault/.env
npx @gpitrella/mcp-secrets-vault set openai_key sk-your-key
npx @gpitrella/mcp-secrets-vault get openai_key

Related MCP server: Credential Vault MCP

Claude Desktop / Cursor

{
  "mcpServers": {
    "secrets-vault": {
      "command": "npx",
      "args": ["-y", "@gpitrella/mcp-secrets-vault"],
      "env": {
        "VAULT_PASSPHRASE": "your-passphrase"
      }
    }
  }
}

MCP Tools

Tool

Description

set_secret

Store encrypted credential

get_secret

Retrieve decrypted credential

rotate_secret

Rotate value (keeps 5 versions)

list_secrets

List metadata (no values)

delete_secret

Soft or hard delete

search_secrets

Full-text search

import_env

Bulk import from .env content

export_env

Export as .env format

dashboard

Interactive HTML dashboard

CLI

npx @gpitrella/mcp-secrets-vault init
npx @gpitrella/mcp-secrets-vault set <name> <value> [--workspace=default]
npx @gpitrella/mcp-secrets-vault get <name>
npx @gpitrella/mcp-secrets-vault list
npx @gpitrella/mcp-secrets-vault import .env --workspace=memxus
npx @gpitrella/mcp-secrets-vault export --workspace=memxus
npx @gpitrella/mcp-secrets-vault gen-key

Security

  • Bound to 127.0.0.1 only for HTTP (NeighborJack defense)

  • AES-256-GCM with Node.js crypto (zero third-party crypto deps)

  • Strict Zod validation, additionalProperties: false on all tools

  • Audit logs never contain secret values

  • All dependencies pinned to exact versions

See docs/SECURITY.md for the threat model.

License

AGPL v3 — See LICENSE.

Vault Cloud (coming soon)

Self-hosted is free forever. Hosted tier with team workspaces, RBAC, and compliance reports.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Secure credential management for AI agents — encrypted storage, auto-refresh, and rate limiting via a single MCP call. Supports OpenAI, Anthropic, Stripe, GitHub, Brave Search, Kalshi, Coinbase, plus generic API key and OAuth2 for any service.
    4
    47 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables secure credential storage for AI agents by encrypting secrets and providing agent-invisible references, ensuring sensitive data never leaks to the model.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    MCP-native credential vault that enables AI agents to authenticate with external services without exposing secrets, supporting bearer, basic, OAuth2, and other auth patterns via MCP tools.
    9 npm
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to securely manage API keys and secrets via the MCP protocol, with encrypted storage at rest and a simple CLI and Python SDK.
    MIT