MCP-Secrets-Vault
by gpitrella
README.md
# MCP-Secrets-Vault
> Security-first secrets vault for MCP servers, Claude Code, Cursor, and AI agents.
[](LICENSE)
[](https://www.npmjs.com/package/@gpitrella/mcp-secrets-vault)
[](https://modelcontextprotocol.io)
Stop hardcoding API keys in `.env` files and MCP configs. MCP-Secrets-Vault stores credentials encrypted (AES-256-GCM) on your machine and exposes them to AI clients via MCP tools.
## Quick Start
```bash
npx @gpitrella/mcp-secrets-vault init
# Set VAULT_PASSPHRASE in ~/.mcp-secrets-vault/.env
npx @gpitrella/mcp-secrets-vault set openai_key sk-your-key
npx @gpitrella/mcp-secrets-vault get openai_key
```
## Claude Desktop / Cursor
```json
{
"mcpServers": {
"secrets-vault": {
"command": "npx",
"args": ["-y", "@gpitrella/mcp-secrets-vault"],
"env": {
"VAULT_PASSPHRASE": "your-passphrase"
}
}
}
}
```
## MCP Tools
| Tool | Description |
|------|-------------|
| `set_secret` | Store encrypted credential |
| `get_secret` | Retrieve decrypted credential |
| `rotate_secret` | Rotate value (keeps 5 versions) |
| `list_secrets` | List metadata (no values) |
| `delete_secret` | Soft or hard delete |
| `search_secrets` | Full-text search |
| `import_env` | Bulk import from `.env` content |
| `export_env` | Export as `.env` format |
| `dashboard` | Interactive HTML dashboard |
## CLI
```bash
npx @gpitrella/mcp-secrets-vault init
npx @gpitrella/mcp-secrets-vault set <name> <value> [--workspace=default]
npx @gpitrella/mcp-secrets-vault get <name>
npx @gpitrella/mcp-secrets-vault list
npx @gpitrella/mcp-secrets-vault import .env --workspace=memxus
npx @gpitrella/mcp-secrets-vault export --workspace=memxus
npx @gpitrella/mcp-secrets-vault gen-key
```
## Security
- Bound to `127.0.0.1` only for HTTP (NeighborJack defense)
- AES-256-GCM with Node.js `crypto` (zero third-party crypto deps)
- Strict Zod validation, `additionalProperties: false` on all tools
- Audit logs never contain secret values
- All dependencies pinned to exact versions
See [docs/SECURITY.md](docs/SECURITY.md) for the threat model.
## License
AGPL v3 — See [LICENSE](LICENSE).
## Vault Cloud (coming soon)
Self-hosted is free forever. Hosted tier with team workspaces, RBAC, and compliance reports.
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues