MCP Hub
Back to servers

@secr/mcp

Provides AI coding agents with direct access to secrets management (get, set, list, delete secrets, and list environments) through the Model Context Protocol, enabling secure secret operations during development.

glama
Updated
May 8, 2026

@secr/mcp

Secr MCP server — gives AI coding agents (Claude Code, Cursor, Copilot) direct access to secrets via the Model Context Protocol.

Install

npm install @secr/mcp

Setup

Claude Code

claude mcp add secr -e SECR_TOKEN=secr_agent_xxx -- npx @secr/mcp

Cursor

Add to ~/.cursor/mcp.json:

{
  "mcpServers": {
    "secr": {
      "command": "npx",
      "args": ["@secr/mcp"],
      "env": { "SECR_TOKEN": "secr_agent_xxx" }
    }
  }
}

VS Code (Copilot)

Add to .vscode/mcp.json:

{
  "servers": {
    "secr": {
      "command": "npx",
      "args": ["@secr/mcp"],
      "env": { "SECR_TOKEN": "secr_agent_xxx" }
    }
  }
}

Tools

The server exposes 5 tools to AI agents:

ToolDescription
get_secretGet a single secret value by key
list_secretsList secret key names (no values) with optional search
set_secretCreate or update a secret
delete_secretDelete a secret
list_environmentsList environments for a project

All tools accept optional org, project, and environment parameters. When omitted, they resolve from environment variables or .secr.json.

Environment Variables

VariableRequiredDefaultDescription
SECR_TOKENYes--Agent token (secr_agent_...)
SECR_ORGNo.secr.jsonOrganization slug
SECR_PROJECTNo.secr.jsonProject slug
SECR_ENVIRONMENTNo.secr.jsonDefault environment slug
SECR_API_URLNohttps://api.secr.devAPI base URL

Creating an Agent Token

secr agents create --name "claude-code" --scope "read:secrets,write:secrets"

Agent tokens use scoped permissions — the server only has access to what the token allows.

Documentation

Full docs at secr.dev/docs.

License

MIT

Reviews

No reviews yet

Sign in to write a review