@secr/mcp
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@secr/mcpget the DATABASE_URL secret from production"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@secr/mcp
Secr MCP server — gives AI coding agents (Claude Code, Cursor, Copilot) direct access to secrets via the Model Context Protocol.
Install
npm install @secr/mcpRelated MCP server: Phantom Secrets MCP Server
Setup
Claude Code
claude mcp add secr -e SECR_TOKEN=secr_agent_xxx -- npx @secr/mcpCursor
Add to ~/.cursor/mcp.json:
{
"mcpServers": {
"secr": {
"command": "npx",
"args": ["@secr/mcp"],
"env": { "SECR_TOKEN": "secr_agent_xxx" }
}
}
}VS Code (Copilot)
Add to .vscode/mcp.json:
{
"servers": {
"secr": {
"command": "npx",
"args": ["@secr/mcp"],
"env": { "SECR_TOKEN": "secr_agent_xxx" }
}
}
}Tools
The server exposes 5 tools to AI agents:
Tool | Description |
| Get a single secret value by key |
| List secret key names (no values) with optional search |
| Create or update a secret |
| Delete a secret |
| List environments for a project |
All tools accept optional org, project, and environment parameters. When omitted, they resolve from environment variables or .secr.json.
Environment Variables
Variable | Required | Default | Description |
| Yes | -- | Agent token ( |
| No |
| Organization slug |
| No |
| Project slug |
| No |
| Default environment slug |
| No |
| API base URL |
Creating an Agent Token
secr agents create --name "claude-code" --scope "read:secrets,write:secrets"Agent tokens use scoped permissions — the server only has access to what the token allows.
Documentation
Full docs at secr.dev/docs.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Secrets for developers and agents—secure context and workflows without exposing secret values.
A secret store for AI agents: the agent never sees the plaintext.
Encrypted secret store and rotation for autonomous agent credentials
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables interaction with HashiCorp Vault for secret management operations including reading, writing, listing, and deleting secrets through the Model Context Protocol.1-
- AlicenseNot gradedqualityAmaintenanceEnables AI coding tools to securely manage secrets via MCP tools for vault operations, diagnostics, and cloud sync, ensuring real keys never enter the LLM context.16MIT
- AlicenseCqualityCmaintenanceEnables AI agents to securely store and manage encrypted secrets locally while using them indirectly through environment-variable injection or file writes, so plaintext values never enter the agent's context.8MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI coding agents to securely inject API keys and secrets into environment files, configs, or commands without the agent ever seeing the secret values.7 npmMIT