Skip to main content
Glama
megamaced

passwords-mcp

by megamaced

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
DEBUGNoSet to any value to log method, path, status and a correlation id to stderr (never secrets or response bodies).
NEXTCLOUD_URLYesInstance base URL (no trailing slash). Must be https://.
NEXTCLOUD_USERYesNextcloud username.
PASSWORDS_READONLYNoSet to true to expose only the read tools and refuse all writes.
ALLOW_INSECURE_HTTPNoSet to true to permit plaintext http:// for a loopback host only (localhost testing). Remote hosts are refused regardless.
NEXTCLOUD_APP_PASSWORDYesA dedicated app-password.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
pingA

Verify connectivity to the configured Nextcloud Passwords instance: that the URL and app-password work, the Passwords app is installed, and client-side encryption is disabled. Reads no vault data.

list_passwordsA

List saved passwords as METADATA ONLY (id, label, username, url, folder, timestamps). The secret value is never included — use get_password with a specific id to reveal one. Optionally filter by folder id.

search_passwordsA

Search saved passwords by a case-insensitive substring of their label, username or URL. Returns METADATA ONLY (no secret values). Use get_password with an id from the results to reveal a single secret.

get_passwordA

Reveal a SINGLE password entry by its id, including the plaintext secret, notes and any custom fields. This exposes sensitive credentials — only call it for a specific id the user has asked to see, never to bulk-export. Get ids from list_passwords or search_passwords.

list_foldersA

List all folders (id, label, parent folder id, timestamps). Folders hold no secret material. Use a folder id with list_passwords to filter.

get_folderA

Fetch a single folder by its id.

create_passwordA

Create a new password entry. Requires a label and the secret value; username, url, notes, folder id and favorite are optional. Stored with server-side encryption (cseType none).

update_passwordA

Update fields of an existing password by id. Only the fields you pass are changed; all others — including hidden/favorite state and custom fields — are preserved (the server rejects the write if the entry changed underneath us). Note that customFields REPLACES the whole set. Tags are left untouched and cannot be edited through this server. Provide at least one field besides id.

delete_passwordA

Move a password to the trash (a reversible, soft delete — restore it from the Passwords app). Refuses if the entry is already trashed, so it can never permanently delete anything.

restore_passwordA

Restore a trashed password, undoing delete_password. Only takes the entry out of the trash — it never rolls the entry back to an older revision. Reports an error if the password is not in the trash.

create_folderB

Create a new folder. Requires a label; parent folder id is optional.

update_folderA

Rename a folder, move it under a different parent, or change its favorite/hidden state, by id. Fields you do not pass keep their current value. Hiding a folder also hides everything inside it.

delete_folderA

Move a folder AND ITS CONTENTS to the trash (reversible, soft delete). Refuses if the folder is already trashed, so it can never permanently delete.

restore_folderA

Restore a trashed folder, undoing delete_folder. Only takes the folder out of the trash — it never rolls it back to an older revision. Reports an error if the folder is not in the trash.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.2/5.0

Scored across 14 tools

Disambiguation5/5

Each tool targets a distinct action on a distinct resource (password vs folder) with clear separation between metadata-only listing, search, and secret-revealing get. The restore/delete pairs are unambiguous, and ping stands alone. No two tools overlap in purpose.

Naming Consistency5/5

All tools follow a consistent verb_noun snake_case pattern (list_passwords, get_password, create_folder, restore_password, etc.). The only deviation, 'ping', is a standard health-check verb that fits the style. Naming is predictable and uniform.

Tool Count5/5

14 tools cover the full password and folder lifecycle (CRUD + restore + search + metadata listing) without bloat. Each tool serves a necessary function and the count matches the domain scope well.

Completeness5/5

The server provides complete coverage for password and folder management: create, read (metadata and secret), update, delete (soft with restore), plus search and folder hierarchy operations. No obvious gaps; bulk export is intentionally omitted for security, and all required actions are supported.

Maintenance

ActivityMaintained
ResponsivenessResponsive