proton-pass-community-mcp
Enables interaction with Proton Pass via CLI operations, including vault and item management, secret injection, and password generation.
README
<div align="center"><img src="./assets/social-preview-image.png" width="400px"></div>
<br />
proton-pass-community-mcp is an MCP server for Proton Pass, with broad coverage of pass-cli operations.
It is an independent community project. It is not affiliated with or endorsed by Proton AG.
It is designed as a production-ready integration layer:
- typed tool inputs with
zod - stdio transport for MCP clients
📌 Current Version of pass-cli used in development: v2.0.2
Available Tools
The server exposes the following MCP tool surface:
| Tool | Purpose |
|---|---|
view_session_info |
Session/account status from pass-cli info |
view_user_info |
User account details from pass-cli user info |
check_status |
Check user authentication status and CLI version |
inject |
Inject secrets into template files |
run |
Run commands with secret references resolved |
list_vaults |
List vaults |
list_shares |
List shares |
list_invites |
List pending invitations |
accept_invite |
Accept an invitation token |
reject_invite |
Reject an invitation token |
view_settings |
View current Proton Pass CLI settings |
list_vault_members |
List members of a specific vault |
update_vault_member |
Update a vault member role |
remove_vault_member |
Remove a vault member |
list_items |
List vault or share items, omitting contents |
search_items |
Search items by title |
view_item |
View item by URI or selectors |
create_vault |
Create a vault |
update_vault |
Update a vault name |
delete_vault |
Delete a vault |
share_vault |
Share a vault with a user |
transfer_vault |
Transfer vault ownership |
create_login_item |
Create a login item |
create_login_item_from_template |
Create a login item from template payload |
create_note_item |
Create a note item |
create_credit_card_item |
Create a credit card item |
create_wifi_item |
Create a WiFi item |
create_custom_item |
Create a custom item from template payload |
create_identity_item |
Create an identity item from template payload |
move_item |
Move an item between vaults |
trash_item |
Move an item to trash |
untrash_item |
Restore an item from trash |
update_item |
Update an item field set |
delete_item |
Delete an item |
download_item_attachment |
Download an item attachment |
list_item_members |
List members of an item |
update_item_member |
Update an item member role |
remove_item_member |
Remove an item member |
create_item_alias |
Create an alias item |
share_item |
Share an item with a user |
generate_item_totp |
Generate item TOTP codes |
generate_random_password |
Generate a random password |
generate_passphrase |
Generate a passphrase |
generate_totp |
Generate TOTP from secret/URI |
score_password |
Score password strength |
Coverage goal: provide comprehensive support for Proton Pass CLI workflows that fit MCP tool semantics. Intentionally excluded are CLI behaviors that are purely interactive or otherwise not a good fit for reliable MCP tool execution.
The search_items operation is additional functionality that is not provided by the base CLI.
Mutative tools currently require write gate opt-in (ALLOW_WRITE=1) and explicit per-call confirmation (confirm: true).
Proposed protocol-aligned confirmation policy (elicitation-first with fail-closed fallback) is documented in docs/TOOL_SCHEMA_PLAN.md.
Available Resources
The server also exposes static MCP resources for item-create template snapshots:
pass://templates/item-create(catalog/index)pass://templates/item-create/loginpass://templates/item-create/notepass://templates/item-create/credit-cardpass://templates/item-create/wifipass://templates/item-create/custompass://templates/item-create/identity
Snapshot artifact source:
These template resources are example well-formed payloads from pass-cli --get-template, not authoritative validation schemas.
Item Discovery Contract
list_items and search_items return token-efficient results. These operations do not contain the full contents or secrets of any items, thus preventing unnecessary leakage of sensitive data from the CLI to the host application or the LLM.
list_items and search_items both support MCP pagination:
- Input fields:
pageSize(optional,1..250, default100for JSON output)cursor(optional non-negative integer string offset, for example"100")
- Behavior:
- Response includes
items,pageSize,cursor,returned,total, andnextCursor. - Use
nextCursorin a follow-up call to fetch the next page.
- Response includes
list_items also forwards filterType, filterState, and sortBy to pass-cli item list.
search_items semantics:
- title-only search (
field: "title") - matching modes:
contains,prefix,exact - optional
caseSensitive
Requirements
[!NOTE] Currently, the server expects the user to handle authentication. If it's not able to authenticate, it will simply prompt the user to authenticate using one of the
pass-climethods.
- Node.js
24(.nvmrc) pass-cliinstalled and authenticated- MCP client capable of stdio transport
- For project development and testing, use the repo wrapper (
npm run pass -- <args>orscripts/pass-dev.sh <args>) instead of barepass-cliso auth stays in the repo-local session scope.
Run Locally
npm ci
npm run build
npm run dev
For project-side pass-cli work, prefer:
npm run pass -- info
This routes through the repo wrapper, which uses a project-local session dir and avoids OS keychain/keyring by default. To assert that the active repo-local session is the intended throwaway account before mutative work:
export PASS_DEV_EXPECTED_ACCOUNT=<throwaway-account-identifier>
npm run pass:dev:preflight
Install and Run via npm/npx
Install from npm or run directly with npx:
npm install --global proton-pass-community-mcp
proton-pass-community-mcp --allow-version-drift
or:
npx -y proton-pass-community-mcp --allow-version-drift
Release operations for maintainers are documented in docs/DEPLOYMENT.md.
Anonymized Demo Shell (Docker)
Use this when recording demos and you want a neutral workspace path in tooling metadata:
npm run demo:shell
This launches a container with the project mounted at /workspace/project.
To run a single command instead of an interactive shell:
npm run demo:shell -- npm run check
Notes:
- Shell prompt aliases/PS1 tweaks only change terminal display; they do not change real working-directory metadata emitted by tools.
- For true path anonymization in logs, run the host/tooling process from inside this containerized workspace.
MCP Client Configuration
Example MCP server config using npx package execution:
{
"mcpServers": {
"proton-pass-community-mcp": {
"command": "npx",
"args": ["-y", "proton-pass-community-mcp", "--allow-version-drift"]
}
}
}
If you are developing locally from source, use a direct local build path:
Example MCP server config using command-line args:
{
"mcpServers": {
"proton-pass-community-mcp": {
"command": "node",
"args": ["/absolute/path/to/proton-pass-community-mcp/dist/index.js", "--allow-version-drift"]
}
}
}
Example MCP server config using environment overrides:
{
"mcpServers": {
"proton-pass": {
"command": "node",
"args": ["/absolute/path/to/proton-pass-community-mcp/dist/index.js"],
"env": {
"PASS_CLI_BIN": "pass-cli",
"PASS_CLI_ALLOW_VERSION_DRIFT": "true"
}
}
}
}
Authentication Model
- Authentication is user-managed outside MCP with
pass-cli login. - The
pass-clisession may be established with normal account credentials or with a pre-provisioned personal access token (PAT). - On auth failure, tools return standardized
AUTH_*errors and a retry instruction. - The MCP server does not collect credentials, OTP codes, private keys, or PAT values.
- PAT-backed login does not change the boundary: login/logout remain outside MCP, and PAT provisioning is not currently exposed as an MCP tool surface.
- For project development, the canonical
pass-clientrypoint is the repo wrapper (npm run pass -- <args>/scripts/pass-dev.sh <args>), not barepass-cli. - The repo wrapper isolates project auth into
.tmp/proton-pass-dev-sessionand avoids default keychain/keyring access, but it does not by itself prove the correct account is active; usescripts/pass-dev-preflight.shornpm run pass:dev:preflightto assert the expected throwaway account. - Use
check_statusonce as a session preflight (not per tool call); rely onAUTH_*fallback errors if the session later expires. check_statuscompares your local CLI version against the development baseline and reports a version assessment for LLMs:equal: exact semver matchcompatible: semver differs but appears compatible by policypossibly_incompatible: semver indicates potential drift, or version parsing/execution prevented a strict comparison
- Version assessments are advisory.
check_statusis marked as an MCP error only when connectivity/authentication fails. - There is no MCP-specific API token auth layer in this server. Authentication methods are those supported by
pass-cliin the server process environment.
Test Account Workflow
For disposable test-account usage in local development and CI (including account preflight checks and session isolation), see docs/testing/TEST_ACCOUNT_WORKFLOW.md.
Startup Flags
--allow-version-drift: treat semver mismatch/version-parse uncertainty as compatible forcheck_status
Equivalent environment variable:
PASS_CLI_ALLOW_VERSION_DRIFT=true|false(accepted truthy values:true,1,yes,on; falsy:false,0,no,off)- If both are set, the CLI flag takes precedence.
Example:
npm run dev -- --allow-version-drift
Notes
- This is not an official Proton project.
- This project currently targets Proton Pass via
pass-clionly. - See ROADMAP.md for planned features.
- In addition to the MCP server, there is an agent skill file that is intended to be integrated with this MCP - however, it is currently only a draft.
- Developer runtime configuration and validation workflows are documented in CONTRIBUTING.md.
- Disposable account setup and contributor/CI guidance are documented in docs/testing/TEST_ACCOUNT_WORKFLOW.md.
- See CONTRIBUTING.md if you're interested in contributing to this project. Contributors are welcome.
LICENSE
GPL-3 © 2026 Really Him
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。