Claude Code 与其他客户端
keygrant 的 MCP server 使用标准的 stdio 协议。有两种等价的启动方式:keygrant-mcp 命令,或 keygrant mcp。
Claude Code:单个项目
keygrant init 会把以下内容写入项目的 .mcp.json:
{
"mcpServers": {
"keygrant": { "command": "keygrant-mcp" }
}
}
如果你的团队也在用 keygrant,可以把 .mcp.json 提交到仓库:它不包含任何密钥。
Claude Code:所有项目
改为在用户级别注册一次:
claude mcp add --scope user keygrant -- keygrant mcp
你仍然需要在每个项目中(或在用户级 CLAUDE.md 中)加入 CLAUDE.md 指引,让模型知道要使用 $NAME,而不是索要密钥值。keygrant init 会自动添加;你也可以自己复制:
## Secrets (keygrant)
API keys and other secrets are managed by keygrant and must NEVER appear in
this conversation. Rules:
- Never ask the user to paste a secret value; never echo, log, or hardcode one.
- To see which secrets exist, use the `list_secrets` MCP tool.
- To run a command that needs a secret, use the `exec_with_secrets` MCP tool
and reference the secret as an environment variable (e.g. `$STRIPE_KEY` /
`%STRIPE_KEY%`). The user approves each use via a native dialog.
- If access is denied, do not retry; ask the user what they want to do.
其他 MCP 客户端
任何能启动 stdio MCP server 的客户端都可以使用。把它指向 keygrant-mcp,不带任何参数。大多数客户端(包括 Cursor 的 mcp.json)都使用上面所示的 mcpServers 结构。
如果客户端找不到该命令,请使用绝对路径:uv tool dir 或 pipx environment 会显示工具的安装位置。
命令中的 shell 语法
exec_with_secrets 通过平台 shell 运行命令:
| 平台 | Shell | 引用密钥的写法 |
|---|---|---|
| macOS、Linux | sh -c | $STRIPE_KEY |
| Windows | cmd /c | %STRIPE_KEY% |
| Windows,通过 PowerShell | cmd /c powershell -Command "..." | $env:STRIPE_KEY |
工具描述中已经向模型说明了这些规则,所以你很少需要纠正它。