Secret MCP Server

Write secrets into .env without the agent ever seeing the value - Windows masked dialog (繁中 UI)

Local serverstdio

What is the Secret MCP server?

If you already use Secret, the secret mcp server is the piece that lets your assistant work with it directly. Write secrets into .env without the agent ever seeing the value - Windows masked dialog (繁中 UI).

What the server does

A Model Context Protocol server that lets an AI agent put a secret (API key, token, password, connection string) into a project's .env file without the agent ever seeing the value.

Installation

secret-safe-env on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.

Credentials and setup notes

Configuration is passed through the environment: OPENAI_API_KEY, DATABASE_URL. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

Where it fits

Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. It is maintained by irrenwill; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

How to install the Secret MCP server

{
  "mcpServers": {
    "secret-safe-env": {
      "command": "npx",
      "args": ["-y", "secret-safe-env"],
      "env": {
        "OPENAI_API_KEY": "your-value",
        "DATABASE_URL": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

VariableDescriptionRequired
OPENAI_API_KEYCredential the server authenticates with.Yes
DATABASE_URLEndpoint or connection string the server talks to.Yes

Frequently asked questions

It connects Secret to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Secret directly.