Skip to main content
Glama
marstudio360

VibeDNA Vault MCP

by marstudio360

VibeDNA Vault MCP

Encrypted local vault for API keys. Your AI fetches keys on demand and scans code for leaks.

Vault keeps every API key, token and password in one encrypted file on your machine (Fernet, with the key derived from your master password by scrypt). The master password is read from your system keyring, or from VAULT_MASTER_PASSWORD on machines with no keyring. Your AI searches the vault and fetches the exact key it needs when it needs it, so keys stop getting pasted into chats. It exports an entry as .env lines, tracks rotation dates, keeps a usage log, ships entry templates for common services, and scans a project folder for keys left in plain text, reporting file and line.

A desktop window (vault_ui.py) and a terminal CLI (vault_core.py) open the same vault with no AI involved. There is no password reset: lose the master password and the file stays unreadable.

Homepage: https://vibedna.ai/store/vault

Tools (17)

Tool

What it does

credential_exists(name)

Check whether an entry exists before asking the user for a key

get_credential(name, key)

Return one field of one entry

list_credentials()

Entry names, categories and field names. No values

search_credentials(term)

Search by name, category or notes

add_credential(name, category, fields, notes)

Add an entry (fields is a JSON object)

edit_credential(name, fields)

Update fields; an empty value removes that field

delete_credential(name, confirm)

Delete an entry (confirm must equal the name)

export_env(name)

The entry's fields as KEY=value lines

add_with_template(service, name, fields, notes)

Add an entry from a service template

list_templates()

The available templates

scan_for_leaks(path)

Scan a folder for plaintext keys: your vault's values plus known key patterns

leak_history()

Recent leak-scan results

check_rotation_due(days)

Entries not rotated in days

mark_rotated(name)

Record a rotation

usage_log(name)

Recent credential-access events

backup_vault()

Copy the encrypted file to the backup folder

check_for_update()

Compare this copy with the published version

Related MCP server: Keyway MCP Server

Install

git clone https://github.com/marstudio360/vibedna-vault-mcp
cd vibedna-vault-mcp
python -m venv .venv
# Windows: .venv\Scripts\activate    mac/linux: source .venv/bin/activate
pip install -r requirements.txt
python vault_core.py init

Store the master password in your system keyring once, so the MCP server can open the vault:

python -c "import keyring; keyring.set_password('vibedna-vault','master', input('master password: '))"

Claude Code

claude mcp add vault --scope user -- /absolute/path/to/vibedna-vault-mcp/.venv/bin/python /absolute/path/to/vibedna-vault-mcp/server.py

Or in a project's .mcp.json:

{
  "mcpServers": {
    "vault": {
      "command": "/absolute/path/to/vibedna-vault-mcp/.venv/bin/python",
      "args": ["/absolute/path/to/vibedna-vault-mcp/server.py"]
    }
  }
}

On Windows the interpreter is .venv\Scripts\python.exe.

Cursor

Add the same mcpServers block to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project).

Claude Desktop

Add the same mcpServers block to claude_desktop_config.json (Settings > Developer > Edit Config), then restart Claude Desktop.

INSTALL.md is a step-by-step guide written so you can paste it into an AI chat and let the AI do the install. It also covers the desktop window and the CLI.

Configuration

Variable

Default

What it does

VAULT_HOME

~/.vibedna-vault

Folder of the encrypted vault file (vault.enc)

VAULT_MASTER_PASSWORD

(unset)

Master password for machines with no system keyring

VAULT_BACKUP_HOME

~/.vibedna-vault/backups

Where backup_vault writes copies (the last 30 are kept)

The usage log and leak-scan results are written next to the vault file, in logs/.

Network

The vault, the window and the CLI make no network calls. check_for_update is the one tool that does: it asks https://vibedna.ai/api/mcp/latest for the published version number.

License

MIT, see LICENSE. Copyright (c) 2026 VibeDNA.

Support: admin@vibedna.ai

Related MCP Connectors

Related MCP Servers

  • -
    license
    Not graded
    quality
    Not graded
    maintenance
    Enables secure management of API keys through an encrypted environment file with automatic categorization, search functionality, and backup operations. Provides comprehensive API key organization with value masking, audit trails, and export capabilities for safe credential management.
    -
  • A
    license
    A
    quality
    F
    maintenance
    A GitHub-native secrets manager that allows AI assistants to securely manage, generate, and validate credentials without exposing sensitive values in conversation history. It supports secret scanning, environment diffing, and secure command execution by injecting masked variables directly into the runtime environment.
    8
    10 npm
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Local AES-256-GCM encrypted vault for AI agents. Resolve {{PLACEHOLDER}} secrets in prompts at runtime — LLMs never see real API keys. Argon2id key derivation, zero cloud.
    2
    62 npm
    3
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    A cross-platform secrets manager that stores named credential sets in the system keychain and injects them as environment variables, enabling secure secret management for AI coding assistants and CLI tools.
    5
    MIT