secrets-mcp

secrets-mcp

An encrypted credential vault for MCP clients that stores and uses sensitive material without exposing values to the model, enabling secure command execution, HTTP requests, and template rendering.

Category
访问服务器

README

secrets-mcp

An encrypted credential vault for Claude Code (and any MCP client): store and use API keys, passwords, tokens, SSH keys, TLS certificates, and other sensitive material without the values ever entering the model's context.

The model can list what exists, collect new credentials from the user, run commands with credentials injected, call APIs with stored tokens, and render config files — but it never sees a value. Ships as a Claude Code plugin bundling the MCP server, a guard hook, and a skill.

How values stay out of the model

  • Input never crosses the chat. vault_set opens a native dialog (hidden input on macOS) where the user types the value; vault_import reads a file straight from disk into the vault. Headless/Linux/Windows: the secrets-vault CLI reads from a hidden TTY prompt or piped stdin — never argv.
  • Output is redacted. vault_run and vault_http scrub every stored value from captured output before it is returned — raw, base64, base64url, hex, URL-encoded, and JSON-escaped forms, plus each individual line of multi-line values (so grep/head on a PEM file comes back redacted).
  • Disk is guarded. A PreToolUse hook denies the model Read/Edit/Grep/Bash access to the vault directory and to any file produced by vault_render or vault_write.
  • Storage is encrypted. AES-256-GCM vault files; the master key lives in the platform credential store — macOS Keychain, Linux libsecret (secret-tool), Windows DPAPI — with a 0600 key file as last-resort fallback. Key material moves over stdin/stdout, never argv.

Threat model — read this

This protects against accidental exposure: secrets pasted into chat, echoed by commands, logged, committed, or read out of config files into the conversation. It is not a sandbox against an adversarial model. A model that deliberately transforms a secret before printing it (e.g. cut -c1-4, character arithmetic, XOR) defeats exact-match redaction — the redaction layer catches common encodings and line-wise extraction, not arbitrary computation. If that is your threat, the mitigation is Claude Code's permission prompts on vault_run commands, not this tool.

Materialized files (vault_render / vault_write outputs, files: temp paths) are plaintext on disk while they exist; temp files are 0600, created inside the guarded directory, and deleted when the command exits.

Entry model

Scope project (per project directory, resolved first) or global (all projects). Project vaults are stored centrally under ~/.secrets-mcp/projects/, keyed by project path — nothing lives in the repo, so nothing can be committed.
Kind secret (text) or file (arbitrary bytes: PEM, PKCS#12, kubeconfig, ...)
Type password, api_key, bearer_token, oauth_token, ssh_private_key, ssh_public_key, tls_certificate, tls_private_key, pkcs12_bundle, gpg_key, connection_string, webhook_secret, totp_seed, ip_address, hostname, url, username, email, generic

Non-credential types (ip_address, hostname, url, username, email) get a visible input dialog but are stored, redacted, and injected exactly like secrets — useful for infrastructure details that should not appear in transcripts.

MCP tools

Tool Purpose
vault_list Names and metadata only — never values
vault_set Store a text value via native user dialog
vault_import Import a file (keys, certs, .env) from disk; optional source shredding
vault_delete Delete after native user confirmation
vault_run Run a shell command; entries injected as env vars (env) or auto-cleaned 0600 temp files (files); output redacted
vault_http HTTP request with {{vault:NAME}} placeholders in URL/headers/body; response redacted
vault_render Render a template ({{vault:NAME}}) to a 0600 file; output path guarded
vault_write Materialize one entry to a permanent path (installing certs/keys); path guarded
vault_cleanup Delete rendered files and release them from the guard (only guard-registered paths; list: true shows them)
vault_check Leak check: report whether text contains any stored value in any common encoding

Example — the model deploys over SSH without ever holding the key:

vault_run {
  "command": "ssh -i \"$KEY\" -o IdentitiesOnly=yes deploy@prod 'systemctl restart app'",
  "files": { "KEY": "deploy-ssh-key" }
}

CLI

For terminals, SSH sessions, and multi-line values:

$ secrets-vault set github-token --type api_key --scope global
Value for 'github-token' (input hidden): ...
$ secrets-vault import deploy-key --file ~/.ssh/id_deploy --type ssh_private_key
$ pbpaste | secrets-vault set staging-db --type connection_string
$ secrets-vault list
$ secrets-vault rm old-token --scope project

Install

$ npm install && npm run build

As a Claude Code plugin (MCP server + guard hook + skill). Plugins install from marketplaces, and this repo self-hosts as one:

$ claude plugin marketplace add DatanoiseTV/secrets-mcp
$ claude plugin install secrets-mcp@datanoise --scope user

From a local clone (development):

$ claude --plugin-dir /path/to/secrets-mcp        # try it without installing
$ claude plugin marketplace add /path/to/secrets-mcp
$ claude plugin install secrets-mcp@datanoise --scope user

Both paths work out of the box: dist/ is a committed, self-contained esbuild bundle with no runtime dependencies — installing the plugin requires no npm step, only Node >= 20 on PATH.

Or just the MCP server, without the plugin:

$ claude mcp add --scope user secrets -- node /path/to/secrets-mcp/dist/index.js

Permissions: skipping the "allow this tool?" prompts

Claude Code asks before every MCP tool call unless the tool is allowlisted. For the plugin, the tools are named mcp__plugin_secrets-mcp_secrets__<tool> (standalone claude mcp add install: mcp__secrets__<tool>). Add rules to ~/.claude/settings.json (user-wide) or .claude/settings.json (per project), or interactively via the /permissions command.

Recommended allowlist — everything whose consent already happens elsewhere or that cannot expose a value:

{
  "permissions": {
    "allow": [
      "mcp__plugin_secrets-mcp_secrets__vault_list",
      "mcp__plugin_secrets-mcp_secrets__vault_check",
      "mcp__plugin_secrets-mcp_secrets__vault_set",
      "mcp__plugin_secrets-mcp_secrets__vault_import",
      "mcp__plugin_secrets-mcp_secrets__vault_delete",
      "mcp__plugin_secrets-mcp_secrets__vault_render",
      "mcp__plugin_secrets-mcp_secrets__vault_write",
      "mcp__plugin_secrets-mcp_secrets__vault_cleanup"
    ]
  }
}

vault_set, vault_import (with remove_source), and vault_delete open native dialogs — the dialog is the consent, so auto-allowing the tool call loses nothing. vault_list and vault_check return metadata only.

Deliberately not on the list:

  • vault_run — executes arbitrary shell with secrets injected. The permission prompt showing you the command is the backstop against a malicious or confused command extracting a value past the redaction layer (see threat model). Keep it prompted.
  • vault_http — sends stored credentials to whatever URL is in the call. A prompt showing the destination is what stands between a stored token and an unintended host. Keep it prompted.

If you accept those risks in a trusted workflow, one rule allows the whole server: "mcp__plugin_secrets-mcp_secrets".

Environment

Variable Effect
SECRETS_MCP_HOME Vault directory (default ~/.secrets-mcp)
SECRETS_MCP_KEY Master key override, 64 hex chars — tests/headless use
SECRETS_MCP_PROJECT Project directory override (default: server cwd)

Development

$ npm test          # vitest: crypto round-trips, scoping, redaction, injection, cleanup

Tests run against an isolated SECRETS_MCP_HOME with an env master key; they never touch the real keychain or vault.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选