Skip to main content
Glama

πŸ›‘οΈ EnvGuard Secrets Vault


🌟 Overview

EnvGuard Secrets Vault is a next-generation secrets security platform and developer toolkit designed for modern cloud architectures, CI/CD pipelines, and autonomous AI coding agents.

It replaces fragile .env file handling with military-grade envelope encryption (AES-256-GCM + PBKDF2), scans 50+ provider token patterns, calculates Shannon entropy, identifies dangerous framework prefix leaks (e.g., Next.js NEXT_PUBLIC_), injects secrets into runtime processes with zero disk writes, and exposes a standardized Model Context Protocol (MCP) server for AI assistants (Claude Desktop, Cursor, Cline, Zed).


Related MCP server: agent-vault

πŸš€ Key Highlights

  • πŸ›‘οΈ Live Secret Auditor & Scanner: 50+ detection signatures (OpenAI, Anthropic, AWS, Stripe, GitHub, Slack, DB passwords, JWTs, Private Keys) + Shannon entropy scoring.

  • πŸ” Zero-Exposure Encrypted Vault: Authenticated AES-256-GCM payload with PBKDF2-HMAC-SHA256 key derivation.

  • ⚑ Zero-Disk Process Execution (envguard vault run): Decrypts secrets directly into process RAM and child environment blocks. No plaintext touches disk.

  • πŸ€– Native Model Context Protocol (MCP) Server: 11 standardized tools (env_scan_secrets, env_mask_variables, env_generate_example, env_vault_encrypt, env_vault_decrypt, env_diff_environments, env_get_diagnostics, env_shamir_split, env_shamir_combine, env_audit_rotation, env_rotate_secrets) for AI coding agents.

  • πŸ”„ Secret Rotation & Ephemerality Sentinel: Enforce # @expires, # @created, and # @rotation_days policies with realistic ephemeral replacement tokens across 14+ providers and unified diff generation.

  • 🌐 EnvGuard Secrets Studio UI (public/index.html): Offline-first web app (design influenced by Material 3) with Web Crypto API encryption, risk gauges, and preset inspection.


πŸ“¦ Installation

# Via pip
pip install envguard-secrets-vault

# Or using uv
uv pip install envguard-secrets-vault

⚑ Quick Start (CLI)

1. Audit Environment Files for Secret Leaks

# Scan a specific environment file
envguard scan .env.production

# Deep recursive scan of workspace
envguard audit ./src

2. Generate Safe Sanitized Template (.env.example)

envguard sanitize .env.production --output .env.example

3. Create an Encrypted Vault File

envguard vault create .env.production --output secrets.vault

4. Zero-Disk Runtime Execution

# Run application with secrets injected directly into memory
envguard vault run --vault secrets.vault -- npm start

# Python Web Server
envguard vault run --vault secrets.vault -- uvicorn app.main:app --port 8080

5. Multi-Format Transformation

# Convert .env to JSON
envguard convert .env.production --format json

# Convert .env to Docker Compose format
envguard convert .env.production --format docker

6. Secret Rotation & Ephemerality Sentinel

# Audit secret ages, TTLs, and rotation policy compliance
envguard rotate .env.production --audit-only

# Rotate expired/overdue credentials with ephemeral mock tokens and view unified diff
envguard rotate .env.production --diff

# Rotate specific secrets and write directly to destination
envguard rotate .env.production --keys STRIPE_SECRET_KEY DATABASE_URL --output .env.rotated

🐍 Python API Reference

from envguard_secrets_vault import Vault, SecretAuditor, Sanitizer

# 1. Audit an environment file
auditor = SecretAuditor()
report = auditor.scan_file(".env.production")
print(f"Security Grade: {report.grade} ({report.score}/100)")
for finding in report.findings:
    print(f"[{finding.severity}] {finding.key}: {finding.recommendation}")

# 2. Encrypt to Vault
vault = Vault.encrypt_file(
    source_path=".env.production",
    password="your-master-password"
)
vault.save("secrets.vault")

# 3. Decrypt in memory (Zero Disk Leak)
env_vars = Vault.load("secrets.vault").decrypt("your-master-password")
print(f"Loaded {len(env_vars)} variables into RAM.")

πŸ€– AI Agent & MCP Integration

EnvGuard includes a standard Model Context Protocol (MCP) server that empowers AI coding agents to manage and use secrets securely:

{
  "mcpServers": {
    "envguard": {
      "command": "python3",
      "args": ["-m", "envguard.mcp"],
      "env": {
        "ENVGUARD_VAULT_PASSWORD": "${ENVGUARD_VAULT_PASSWORD}"
      }
    }
  }
}

See the MCP Client Integration Guide for Claude Desktop, Cursor, Cline, and Zed configurations.


🌐 EnvGuard Secrets Studio Web UI (Design Influenced by Material 3)

Open public/index.html in your browser or run:

python3 -m http.server 8080 --directory public

Navigate to http://localhost:8080 for:

  • πŸ›‘οΈ Interactive Secret Auditor with 0-100 Grade Gauge.

  • πŸ”„ Format Transformer (Dotenv, JSON, YAML, Docker Compose, Kubernetes Secret).

  • πŸ” In-Browser Web Crypto AES-256-GCM Encrypted Vault.

  • πŸ€– AI Agent MCP Config Generator.


πŸ“š Documentation


πŸ“„ License

Apache License 2.0. Copyright (c) 2026 EnvGuard Contributors.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to securely use secrets by running commands with environment-injected credentials and sanitizing output to prevent leakage.
    1
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Agent Vault is a local credential vault for AI agents. It enables agents to use secrets by name without ever seeing their values, with host allowlists, output scrubbing, and audit logging.
    4
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to make authenticated API calls and run commands with secrets injected, while keeping credentials completely hidden from the model, with policy enforcement, grants, and audit logging.
    2
    6
    MIT
  • A
    license
    C
    quality
    C
    maintenance
    Enables AI agents to securely store and manage encrypted secrets locally while using them indirectly through environment-variable injection or file writes, so plaintext values never enter the agent's context.
    8
    MIT