Skip to main content
Glama
privacyplaybook

sops-mcp

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
SOPS_AGE_KEYNoAge private key — required for any mutation tool (rotate, add, update, rename, delete)
SOPS_MCP_HOSTNoBind host for SSE transport127.0.0.1
SOPS_MCP_PORTNoBind port for SSE transport55090
SOPS_MCP_API_TOKENNoAPI token for SSE authentication. Required when SSE transport binds to 0.0.0.0.
SOPS_MCP_LOG_LEVELNoLog levelWARNING
SOPS_MCP_TRANSPORTNoTransport: stdio or ssestdio
SOPS_AGE_RECIPIENTSNoAlternative to SOPS_MCP_AGE_PUBLIC_KEY. Must be set if SOPS_MCP_AGE_PUBLIC_KEY is not set.
SOPS_MCP_SOPS_BINARYNoPath to sops binarysops
SOPS_MCP_ALLOWED_HOSTSNoComma-separated allowlist for the SSE Host header (DNS rebinding protection)127.0.0.1,127.0.0.1:*,localhost,localhost:*
SOPS_MCP_AGE_PUBLIC_KEYNoAge public key for encryption. Must be set if SOPS_AGE_RECIPIENTS is not set.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
sops_create_secretsA

Generate and encrypt secrets as SOPS YAML. Returns encrypted content for the client to write to disk. Supports three sources: 'generated' (cryptographic randomness), 'external' (user-provided values), and 'derived' (computed from another key in the same file via a transform such as pbkdf2_sha512_authelia). Derived secret plaintexts are returned in the response so they can be copied into config files.

sops_list_secretsA

List key names and metadata from a SOPS-encrypted file. No decryption needed — reads key names from encrypted YAML and metadata from the _meta_unencrypted block.

sops_rotate_generatedA

Re-generate 'generated' secrets with new random values while preserving 'external' secrets. Requires a private key for the target domain.

sops_add_secretsA

Add new secrets to an existing SOPS-encrypted file. Decrypts the file, merges in new secrets, and re-encrypts — preserving all existing values and metadata. Rejects keys that already exist in the file. Supports generated, external, and derived sources. Requires a private key for the target domain.

sops_add_metadataA

Add _meta_unencrypted metadata to an existing SOPS-encrypted file that lacks it. Decrypts the file, adds metadata, and re-encrypts preserving original plaintext values. Requires a private key for the target domain.

sops_delete_secretsA

Delete one or more keys from an existing SOPS-encrypted file. Removes both the encrypted value and the _meta_unencrypted entry. Rejects deletion of keys that other derived secrets depend on unless those dependents are also in the delete list. Requires a private key for the domain.

sops_rename_secretA

Rename a key in an existing SOPS-encrypted file. Preserves the value, source type, and metadata. Updates 'from' references in any derived secrets that depend on the renamed key. Requires a private key for the target domain.

sops_update_externalA

Replace the value of an 'external' secret (e.g. after the user rotated an upstream API key). Rejects attempts to update 'generated' or 'derived' secrets — use sops_rotate_generated for those. Recomputes any derived secrets that reference this key. Requires a private key for the domain.

sops_create_oidc_secretA

Convenience tool: create an Authelia-compatible OIDC client secret. Generates KEY_NAME as a 64-char alphanumeric 'generated' secret AND KEY_NAME_HASH as a 'derived' PBKDF2-SHA512 hash of it, stored together in a new encrypted file. The hash is returned in the response for pasting into Authelia's configuration.yml. Equivalent to calling sops_create_secrets with one generated and one derived (pbkdf2_sha512_authelia) entry.

sops_list_domainsA

List the key domains this server is configured with: their names, age recipients (public keys), how many private keys the server holds for each, and whether the domain can decrypt or only encrypt. Never returns private key material.

sops_rekeyA

Re-encrypt a SOPS file onto the current recipient list of the named domain, updating its recorded domain. This is the tool to run after a domain's recipients change, and the way to clear the 'recipients do not match' refusal from the other mutation tools. It changes who can read the file, so 'domain' is required rather than inferred. Requires a private key for that domain.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.9/5.0

Scored across 11 tools

Disambiguation4/5

Most tools have clearly distinct roles (update_external vs rotate_generated vs add_secrets are well-differentiated by their descriptions). The main overlap is between sops_create_secrets and sops_add_secrets, and especially sops_create_oidc_secret which is explicitly a convenience wrapper over create_secrets, but the descriptions make the boundaries clear enough to choose correctly.

Naming Consistency4/5

All tools use a consistent sops_verb_noun snake_case pattern (sops_create_secrets, sops_delete_secrets, sops_list_domains). Minor deviations: sops_update_external drops the 'secrets' noun and sops_rename_secret uses singular 'secret' whereas peers use plural, but the convention is still predictable.

Tool Count5/5

11 tools is well-scoped for a SOPS secret lifecycle server, with each mutation, read, and maintenance operation earning its place. No redundant or filler tools.

Completeness4/5

Covers creation, addition, deletion, renaming, rotation, metadata, rekeying, domain listing, and external update — a solid lifecycle surface. The notable gap is a tool to decrypt/read plaintext values of existing secrets (list_secrets only exposes key names), which could force workarounds.

Maintenance

ActivityMaintained
ResponsivenessSlow