io.github.wkoverfield/switchboard
Integrates with GitHub by letting agents access scoped GitHub MCP tools and CI tokens through expiring passes, with secrets stored in the OS keychain instead of plaintext config.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@io.github.wkoverfield/switchboardscan this repo and show which MCP servers and tokens my agents can reach"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Switchboard
A firewall and password manager for your AI coding agents.
Switchboard controls what Claude Code and Codex can reach in a repo. It finds the MCP servers and tokens your agents can already touch, gets secrets out of plaintext config and behind named keychain refs, and puts each agent on a scoped pass that expires on its own.

Everything runs locally. No account, no hosted service, no telemetry.
What it does
switchboard scanshows which MCP servers and tokens agents can reach in this repo, and which routes bypass Switchboard entirely.switchboard importconsolidates scattered Claude/Codex MCP config into one Switchboard route, with timestamped backups and exact rollback commands.Secrets live in your OS keychain as named refs. Config files carry
secretRef: "github/ci/token", never the token itself.switchboard grantputs the agent on a pass: named tools reachable, everything else denied, gone in a few hours.switchboard statusanswers whether a pass is live right now.switchboard revokeends one early.Every tool call routed through Switchboard lands in a local audit log.
switchboard logsreads it.
Related MCP server: agent-vault
Install
npm install -g @switchboard-mcp/cliOr without installing:
npx -y @switchboard-mcp/cli@latest scanRequires Node 22 or newer. Daily use is on macOS, CI runs on Linux, and a Windows keychain backend exists but gets less exercise.
Quickstart
Start in a repo where your agents already work:
$ switchboard scan
This looks like acme-app.
Detected:
- Codex Switchboard route missing
- Claude Switchboard route missing
- Claude direct MCP server "github" detected
Authority bypasses:
high claude:github (github; direct-mcp-server, secret-env-name)
Warnings:
- 1 direct MCP bypass finding(s), including 1 high-risk finding(s), were detected.That high-risk finding is a GitHub token sitting in plaintext in .mcp.json.
Move it behind Switchboard:
switchboard import --dry-run # see the plan first
switchboard import --write --cleanup-client
switchboard secrets set <ref> # store the token; import prints the exact command
switchboard install claude --write # route the agent through SwitchboardImport rewrites client config to a single Switchboard route, replaces the
plaintext token with a named keychain ref, and leaves a backup plus the exact
rollback command. Import never reads secret values itself; the secrets set
step is where the token actually enters your keychain. Then scope the agent:
switchboard grant --for 4hYou get the pass above. When you want it gone early:
$ switchboard revoke
Revoked pass grant-main (main). The agent's scoped access is off now.switchboard doctor tells you the next thing to fix at any point. If a repo
has no MCP config yet, switchboard setup github-ci starts from a safe
provider template instead.
What Switchboard does not do
It is not a sandbox. Switchboard governs the paths routed through it: Switchboard MCP endpoints and
switchboard run. An agent with raw shell access, a provider CLI, a browser session, or a direct MCP route can bypass it.switchboard scanreports those bypass routes so you can clean them up or accept them deliberately.Backups keep your old config exactly as it was. If a token was in plaintext before import, the backup still contains it. Rotate old tokens after migrating, and keep backups private.
A pass only binds routed agents.
switchboard grantsays so itself when no client is wired up yet, andswitchboard install <claude|codex>closes the gap.It is alpha software. Local-first workflows, conservative claims, rough edges. The pass and audit contracts are versioned JSON, but expect change.
Commands
Command | What it does |
| Show what agents can reach in this repo, including bypass routes |
| Consolidate Claude/Codex MCP config into one guarded route |
| Give the repo's agent an expiring scoped pass, or end it now |
| Is a pass live right now, and which config is active |
| Check the setup and print the next thing to fix |
| Guided setup from a provider safety template ( |
| Store the provider token for a preset in the keychain |
| Set, list, remove, and doctor named secret refs |
| Run an allowed provider command with pass-scoped credentials and audit |
| Route Claude Code or Codex through Switchboard (add |
| Create and inspect task-scoped passes with leases, gates, handoffs |
| Review and decide approval-gated tool calls |
| List the tool surface a pass exposes |
| Read the local audit log |
| Local read-only dashboard: live passes, denials, audit stream |
| Repo authority posture report, exportable as JSONL |
Commands that report state take --json for scripts and harnesses, with
versioned schemas. switchboard <command> --help has the rest.
How it works
Switchboard reads layered YAML config (global, then .switchboard.yaml, then
.switchboard.local.yaml). Each profile names an upstream MCP server and the
secret refs it needs. At runtime, Switchboard mounts permitted profiles as one
MCP endpoint, resolves secret refs from the OS keychain only at launch, and
namespaces every tool so a pass can allow github_ci_* and deny everything
else. Passes, approvals, and audit entries are plain local files that reference
secrets by name, never by value.
Secret storage uses OS keychain backends by default. Plaintext fallbacks exist
for dev machines and CI, and require an explicit
SWITCHBOARD_ALLOW_UNSAFE_SECRET_BACKENDS=1 opt-in.
For harnesses and subagent systems
switchboard pass create --from github-ci --json returns a
workspaceLease.mcpLaunch payload: the exact command to launch a
pass-scoped stdio MCP endpoint, plus the pass policy and lease. Switchboard
grants and audits authority; your harness owns scheduling, retries, and agent
processes. JSON contracts are documented in
docs/use-cases/harness-json-contracts.md.
Alternatives
Project MCP config alone works, but it is static wiring with tokens in files. Switchboard imports that wiring, moves the tokens, and adds scoped expiring access on top.
Docker MCP Gateway and MCP runtimes run and package MCP servers well. Switchboard is the local authority layer above them, deciding which profile, tools, and lease an agent gets for a task. A gateway can be an upstream behind a Switchboard profile.
Hosted tool platforms (Composio, Arcade) offer managed OAuth and broad SaaS coverage. Switchboard is local-first for coding-agent repos: local secrets, local audit, no hosted dependency.
Just giving the agent a token is fast until the token is broad, live, or copied into the wrong file. That is the failure mode Switchboard exists for.
Development
git clone https://github.com/wkoverfield/switchboard.git
cd switchboard
pnpm install
pnpm build
pnpm switchboard --help
pnpm testContributions are welcome; see CONTRIBUTING.md, and report vulnerabilities privately per SECURITY.md.
Smoke tests and fresh-agent evals live in scripts/; CI runs the full set.
The top demo is a VHS tape: brew install vhs && pnpm build && vhs examples/switchboard.tape.
Deeper docs: quickstart,
threat model,
provider safety templates,
roadmap.
Agents can read these docs over MCP:
npx -y @switchboard-mcp/docs-mcp serves list_docs, read_doc, and
search_docs, and llms.txt is kept current. The landing and docs
site lives in site/ (static build, pnpm --filter @switchboard-mcp/site build).
License
MIT. See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Secrets for developers and agents—secure context and workflows without exposing secret values.
- FullmaktOAuthai.fullmakt
Credential broker for AI agents: scoped, revocable API access with policy enforcement and audit.
Security reviews for coding agents: diffs checked against your org policy and live infrastructure.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceLocal-first security check for AI coding agents — finds hardcoded secrets, exposed .env files, git-history leaks and vulnerable dependencies (OSV), entirely on your machine. Ask your agent "is this safe to ship?" and get a Launch Readiness score with a fix for every finding.MIT
- AlicenseNot gradedqualityBmaintenanceAgent Vault is a local credential vault for AI agents. It enables agents to use secrets by name without ever seeing their values, with host allowlists, output scrubbing, and audit logging.4MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI coding agents to securely inject API keys and secrets into environment files, configs, or commands without the agent ever seeing the secret values.13 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to scan and audit environment files for leaked secrets, sanitize them, encrypt/decrypt vaults, and run processes with zero-disk secret injection.MIT