Skip to main content
Glama
AIWerk

@aiwerk/mcp-server-vault

by AIWerk

@aiwerk/mcp-server-vault

Bitwarden / Vaultwarden MCP server — BYOK vault access for AI agents.

Exposes 6 tools over stdio. Secret values are never sent in plaintext through list_vault_items or get_vault_metadata — secrets are delivered only through Bitwarden Sends (E2E-encrypted one-time URLs).

Install

npx -y @aiwerk/mcp-server-vault

Related MCP server: VaultBridge

Configure

Variable

Required

Default

Description

VAULT_API_BASE

Base URL of your Bitwarden/Vaultwarden instance (no trailing slash), e.g. https://pass.aiwerk.ch

VAULT_CLIENT_ID

Personal API key client_id (e.g. user.abc-def-1234)

VAULT_CLIENT_SECRET

Personal API key client_secret

VAULT_MASTER_PASSWORD

Vault master password (used for E2E decryption key derivation)

VAULT_EXPOSED_COLLECTION

mcp-exposed

Name of the collection visible to agents

VAULT_AGENT_CREATED_COLLECTION

mcp-agent-created

Name of the collection for agent-created secrets

VAULT_API_TIMEOUT_MS

15000

HTTP timeout in milliseconds

DRY_RUN

0

Set 1 to log write operations without executing them

READ_ONLY

0

Set 1 to block all write operations (Send creation and save)

Auth — Personal API Key

  1. Log in to your Bitwarden/Vaultwarden instance

  2. Go to Account Settings → Security → Keys → API Key

  3. Note the client_id and client_secret

  4. Reference: https://bitwarden.com/help/personal-api-key/

Vault Setup

Before using this server, create two collections in your Vaultwarden organization:

  • mcp-exposed — items you want to expose to agents (your existing secrets: API keys, passwords, etc.)

  • mcp-agent-created — items written by agents via save_generated_secret

Add items to mcp-exposed via the Vaultwarden web UI.

Custom fields

Optionally add these custom fields to items in mcp-exposed for fine-grained control:

Field

Type

Purpose

mcp-scope

text

Comma-separated glob list of tool/server names allowed to use this item (e.g. stripe.*,openai)

mcp-chat-reveal-allowed

text

"true" to allow chat delivery of the Send URL

mcp-delivery-channel

text

"chat" (default), "telegram", or "email"

Tools

Tool

Description

list_vault_items

List items from mcp-exposed and mcp-agent-created. Returns metadata only — no secret values.

get_vault_metadata

Get full metadata for a named item (name, type, username, URIs, custom fields, expiry). No password/secret.

reveal_secret_via_send

Reveal a secret via a Bitwarden Send (E2E-encrypted one-time URL with configurable TTL and max-views).

get_totp_code

Get the current TOTP code for a login item, including remaining seconds in the period.

save_generated_secret

Save an agent-generated secret (password / api-key) into mcp-agent-created as a secure note. CREATE-only — no overwrite.

save_login_item

Save sign-in credentials (username + password + optional URL + TOTP seed) into mcp-agent-created as a real login item. CREATE-only — no overwrite.

health_check

Check connectivity: auth status, API version, collection visibility, item counts, latency.

Security model

  • Opt-in exposure: only items in mcp-exposed or mcp-agent-created are accessible; all other items return item_not_visible

  • Read-only existing items: no update_*, delete_*, or change_* tools exist

  • Secret value delivery via Send only: list_vault_items and get_vault_metadata never return passwords, TOTP seeds, or api-key values

  • E2E encryption preserved: the server decrypts vault data locally (master password stays in env vars, never sent over the wire)

  • Constrained agent writes: save_generated_secret and save_login_item are CREATE-only into the dedicated mcp-agent-created collection

Note: Actual {{vault:NAME}} placeholder resolution in tool call arguments happens in the AIWerk hosted bridge, not in this server. The bridge's resolution uses the same BYOC credentials. See the bridge-patch companion document for details.

License

MIT — AIWerk kontakt@aiwerk.ch

Homepage: https://aiwerkmcp.com

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    MCP server for Vaultwarden/Bitwarden vault management. Enables AI agents to securely create, search, read, and update vault items via the official Bitwarden CLI, with safe-by-default redaction and support for both stdio and SSE transports.
    Last updated
    53
    325
    12
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    Secret management MCP server for AI coding agents that prevents secrets from entering the LLM context window by returning metadata only and using side-channel injection. Integrates with Bitwarden and offers hooks for auto-capture and leak prevention.
    Last updated
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    MCP server for Wundervault zero-knowledge secret management. Exposes vault secrets to AI agents via the Model Context Protocol — secrets are decrypted server-side and never returned to the agent in plaintext.
    Last updated
    6
    295
    2
    AGPL 3.0
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server for using Bitwarden Secrets Manager as durable credential storage for agent workflows, enabling secure secret storage, retrieval, and injection into trusted executables.
    Last updated
    7
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.

  • Shared long-term memory vault for AI agents with 20 MCP tools.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/AIWerk/mcp-server-vault'

If you have feedback or need assistance with the MCP directory API, please join our Discord server