MCP tools
The MCP server exposes exactly two tools. There is deliberately no tool to store or read a secret value: if a value passed through a tool call, it would be in the model’s context.
list_secrets
No input. Returns one line per secret with its name, description, use count and last use:
- STRIPE_KEY: stripe, test mode [used 2x, last: 2026-10-10T13:10:03+00:00]
- OPENAI_KEY: openai, personal [used 0x, last: never]
With an empty vault it says so and tells the agent that secrets are added
out-of-band with keygrant set.
exec_with_secrets
Run a shell command with secrets injected as environment variables.
| Input | Type | Required | Meaning |
|---|---|---|---|
command | string | yes | The command. Runs through sh -c on macOS and Linux, cmd /c on Windows. |
secrets | string[] | yes | Names of the secrets to inject. |
cwd | string | no | Working directory. |
Behaviour:
- Every name must exist, or the call fails without asking you.
- Commands over 2000 characters are refused.
- The user approves through a native dialog; see Approvals and grants. A grant covers that exact command for 15 minutes, so the agent should reuse the identical command for retries.
- A denial is returned as an error with an instruction not to retry.
- The command times out after 120 seconds.
- stdout and stderr are returned with every secret value redacted.
Example call:
{
"command": "curl -s https://api.stripe.com/v1/charges?limit=5 -u \"$STRIPE_KEY:\"",
"secrets": ["STRIPE_KEY"]
}