Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Secrets Vault

FreeNot checked

Enables AI agents and MCP clients to securely store, retrieve, and manage encrypted credentials without hardcoding API keys.

GitHubEmbed

About

Enables AI agents and MCP clients to securely store, retrieve, and manage encrypted credentials without hardcoding API keys.

README

Security-first secrets vault for MCP servers, Claude Code, Cursor, and AI agents.

License: AGPL v3 npm MCP Compatible

Stop hardcoding API keys in .env files and MCP configs. MCP-Secrets-Vault stores credentials encrypted (AES-256-GCM) on your machine and exposes them to AI clients via MCP tools.

Quick Start

npx @gpitrella/mcp-secrets-vault init
# Set VAULT_PASSPHRASE in ~/.mcp-secrets-vault/.env
npx @gpitrella/mcp-secrets-vault set openai_key sk-your-key
npx @gpitrella/mcp-secrets-vault get openai_key

Claude Desktop / Cursor

{
  "mcpServers": {
    "secrets-vault": {
      "command": "npx",
      "args": ["-y", "@gpitrella/mcp-secrets-vault"],
      "env": {
        "VAULT_PASSPHRASE": "your-passphrase"
      }
    }
  }
}

MCP Tools

Tool Description
set_secret Store encrypted credential
get_secret Retrieve decrypted credential
rotate_secret Rotate value (keeps 5 versions)
list_secrets List metadata (no values)
delete_secret Soft or hard delete
search_secrets Full-text search
import_env Bulk import from .env content
export_env Export as .env format
dashboard Interactive HTML dashboard

CLI

npx @gpitrella/mcp-secrets-vault init
npx @gpitrella/mcp-secrets-vault set <name> <value> [--workspace=default]
npx @gpitrella/mcp-secrets-vault get <name>
npx @gpitrella/mcp-secrets-vault list
npx @gpitrella/mcp-secrets-vault import .env --workspace=memxus
npx @gpitrella/mcp-secrets-vault export --workspace=memxus
npx @gpitrella/mcp-secrets-vault gen-key

Security

  • Bound to 127.0.0.1 only for HTTP (NeighborJack defense)
  • AES-256-GCM with Node.js crypto (zero third-party crypto deps)
  • Strict Zod validation, additionalProperties: false on all tools
  • Audit logs never contain secret values
  • All dependencies pinned to exact versions

See docs/SECURITY.md for the threat model.

License

AGPL v3 — See LICENSE.

Vault Cloud (coming soon)

Self-hosted is free forever. Hosted tier with team workspaces, RBAC, and compliance reports.

from github.com/gpitrella/mcp-secrets-vault

Installing Secrets Vault

This server has no published package — it is built from source. Open the repository and follow its README.

▸ github.com/gpitrella/mcp-secrets-vault

FAQ

Is Secrets Vault MCP free?

Yes, Secrets Vault MCP is free — one-click install via Unyly at no cost.

Does Secrets Vault need an API key?

No, Secrets Vault runs without API keys or environment variables.

Is Secrets Vault hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Secrets Vault in Claude Desktop, Claude Code or Cursor?

Open Secrets Vault on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Secrets Vault with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All ai MCPs