MCP-Secrets-Vault
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP-Secrets-Vaultsave my GitHub token"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP-Secrets-Vault
Security-first secrets vault for MCP servers, Claude Code, Cursor, and AI agents.
Stop hardcoding API keys in .env files and MCP configs. MCP-Secrets-Vault stores credentials encrypted (AES-256-GCM) on your machine and exposes them to AI clients via MCP tools.
Quick Start
npx @gpitrella/mcp-secrets-vault init
# Set VAULT_PASSPHRASE in ~/.mcp-secrets-vault/.env
npx @gpitrella/mcp-secrets-vault set openai_key sk-your-key
npx @gpitrella/mcp-secrets-vault get openai_keyRelated MCP server: Credential Vault MCP
Claude Desktop / Cursor
{
"mcpServers": {
"secrets-vault": {
"command": "npx",
"args": ["-y", "@gpitrella/mcp-secrets-vault"],
"env": {
"VAULT_PASSPHRASE": "your-passphrase"
}
}
}
}MCP Tools
Tool | Description |
| Store encrypted credential |
| Retrieve decrypted credential |
| Rotate value (keeps 5 versions) |
| List metadata (no values) |
| Soft or hard delete |
| Full-text search |
| Bulk import from |
| Export as |
| Interactive HTML dashboard |
CLI
npx @gpitrella/mcp-secrets-vault init
npx @gpitrella/mcp-secrets-vault set <name> <value> [--workspace=default]
npx @gpitrella/mcp-secrets-vault get <name>
npx @gpitrella/mcp-secrets-vault list
npx @gpitrella/mcp-secrets-vault import .env --workspace=memxus
npx @gpitrella/mcp-secrets-vault export --workspace=memxus
npx @gpitrella/mcp-secrets-vault gen-keySecurity
Bound to
127.0.0.1only for HTTP (NeighborJack defense)AES-256-GCM with Node.js
crypto(zero third-party crypto deps)Strict Zod validation,
additionalProperties: falseon all toolsAudit logs never contain secret values
All dependencies pinned to exact versions
See docs/SECURITY.md for the threat model.
License
AGPL v3 — See LICENSE.
Vault Cloud (coming soon)
Self-hosted is free forever. Hosted tier with team workspaces, RBAC, and compliance reports.
This server cannot be deployed
Maintenance
Related MCP Connectors
Encrypted secret store and rotation for autonomous agent credentials
A secret store for AI agents: the agent never sees the plaintext.
MCP-native Trust Infrastructure for AI Agents. Persistent encrypted memory with Trust Quotient.
- FullmaktOAuthai.fullmakt
Credential broker for AI agents: scoped, revocable API access with policy enforcement and audit.
Related MCP Servers
- AlicenseAqualityBmaintenanceSecure credential management for AI agents — encrypted storage, auto-refresh, and rate limiting via a single MCP call. Supports OpenAI, Anthropic, Stripe, GitHub, Brave Search, Kalshi, Coinbase, plus generic API key and OAuth2 for any service.447 npmMIT
- AlicenseNot gradedqualityCmaintenanceEnables secure credential storage for AI agents by encrypting secrets and providing agent-invisible references, ensuring sensitive data never leaks to the model.MIT
- AlicenseNot gradedqualityBmaintenanceMCP-native credential vault that enables AI agents to authenticate with external services without exposing secrets, supporting bearer, basic, OAuth2, and other auth patterns via MCP tools.9 npmMIT
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to securely manage API keys and secrets via the MCP protocol, with encrypted storage at rest and a simple CLI and Python SDK.MIT