loading…
Search for a command to run...
loading…
Provides AI coding agents with direct access to secrets management (get, set, list, delete secrets, and list environments) through the Model Context Protocol, e
Provides AI coding agents with direct access to secrets management (get, set, list, delete secrets, and list environments) through the Model Context Protocol, enabling secure secret operations during development.
Secr MCP server — gives AI coding agents (Claude Code, Cursor, Copilot) direct access to secrets via the Model Context Protocol.
npm install @secr/mcp
claude mcp add secr -e SECR_TOKEN=secr_agent_xxx -- npx @secr/mcp
Add to ~/.cursor/mcp.json:
{
"mcpServers": {
"secr": {
"command": "npx",
"args": ["@secr/mcp"],
"env": { "SECR_TOKEN": "secr_agent_xxx" }
}
}
}
Add to .vscode/mcp.json:
{
"servers": {
"secr": {
"command": "npx",
"args": ["@secr/mcp"],
"env": { "SECR_TOKEN": "secr_agent_xxx" }
}
}
}
The server exposes 5 tools to AI agents:
| Tool | Description |
|---|---|
get_secret |
Get a single secret value by key |
list_secrets |
List secret key names (no values) with optional search |
set_secret |
Create or update a secret |
delete_secret |
Delete a secret |
list_environments |
List environments for a project |
All tools accept optional org, project, and environment parameters. When omitted, they resolve from environment variables or .secr.json.
| Variable | Required | Default | Description |
|---|---|---|---|
SECR_TOKEN |
Yes | -- | Agent token (secr_agent_...) |
SECR_ORG |
No | .secr.json |
Organization slug |
SECR_PROJECT |
No | .secr.json |
Project slug |
SECR_ENVIRONMENT |
No | .secr.json |
Default environment slug |
SECR_API_URL |
No | https://api.secr.dev |
API base URL |
secr agents create --name "claude-code" --scope "read:secrets,write:secrets"
Agent tokens use scoped permissions — the server only has access to what the token allows.
Full docs at secr.dev/docs.
MIT
Run in your terminal:
claude mcp add secr-mcp -- npx Yes, @Secr/ MCP is free — one-click install via Unyly at no cost.
No, @Secr/ runs without API keys or environment variables.
A hosted option is available: Unyly runs the server in the cloud, no local setup required.
Open @Secr/ on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
CSA PROJECT - FZCO © 2026 IFZA Business Park, DDP, Premises Number 31174 - 001
Security
Low riskAutomated heuristic from public metadata — not a security guarantee.