MCP tools

The MCP server exposes exactly two tools. There is deliberately no tool to store or read a secret value: if a value passed through a tool call, it would be in the model’s context.

list_secrets

No input. Returns one line per secret with its name, description, use count and last use:

- STRIPE_KEY: stripe, test mode [used 2x, last: 2026-10-10T13:10:03+00:00]
- OPENAI_KEY: openai, personal [used 0x, last: never]

With an empty vault it says so and tells the agent that secrets are added out-of-band with keygrant set.

exec_with_secrets

Run a shell command with secrets injected as environment variables.

InputTypeRequiredMeaning
commandstringyesThe command. Runs through sh -c on macOS and Linux, cmd /c on Windows.
secretsstring[]yesNames of the secrets to inject.
cwdstringnoWorking directory.

Behaviour:

Example call:

{
  "command": "curl -s https://api.stripe.com/v1/charges?limit=5 -u \"$STRIPE_KEY:\"",
  "secrets": ["STRIPE_KEY"]
}