Claude Code and other clients

keygrant’s MCP server speaks the standard stdio protocol. It can be started two equivalent ways: the keygrant-mcp command, or keygrant mcp.

Claude Code, one project

keygrant init writes this into the project’s .mcp.json:

{
  "mcpServers": {
    "keygrant": { "command": "keygrant-mcp" }
  }
}

Commit .mcp.json if your team uses keygrant too: it contains no secrets.

Claude Code, every project

Register it once at user scope instead:

claude mcp add --scope user keygrant -- keygrant mcp

You still want the CLAUDE.md guidance in each project (or in your user-level CLAUDE.md) so the model knows to use $NAME rather than asking for values. keygrant init adds it; you can also copy it yourself:

## Secrets (keygrant)

API keys and other secrets are managed by keygrant and must NEVER appear in
this conversation. Rules:

- Never ask the user to paste a secret value; never echo, log, or hardcode one.
- To see which secrets exist, use the `list_secrets` MCP tool.
- To run a command that needs a secret, use the `exec_with_secrets` MCP tool
  and reference the secret as an environment variable (e.g. `$STRIPE_KEY` /
  `%STRIPE_KEY%`). The user approves each use via a native dialog.
- If access is denied, do not retry; ask the user what they want to do.

Other MCP clients

Any client that launches stdio MCP servers works. Point it at keygrant-mcp with no arguments. Most clients, Cursor’s mcp.json among them, use the same mcpServers shape shown above.

If the client can’t find the command, use the absolute path: uv tool dir or pipx environment shows where the tool was installed.

Shell syntax inside commands

exec_with_secrets runs its command through the platform shell:

PlatformShellReference a secret as
macOS, Linuxsh -c$STRIPE_KEY
Windowscmd /c%STRIPE_KEY%
Windows, via PowerShellcmd /c powershell -Command "..."$env:STRIPE_KEY

The model is told this in the tool description, so you rarely need to correct it.