Claude Code 与其他客户端

keygrant 的 MCP server 使用标准的 stdio 协议。有两种等价的启动方式:keygrant-mcp 命令,或 keygrant mcp。

Claude Code:单个项目

keygrant init 会把以下内容写入项目的 .mcp.json:

{
  "mcpServers": {
    "keygrant": { "command": "keygrant-mcp" }
  }
}

如果你的团队也在用 keygrant,可以把 .mcp.json 提交到仓库:它不包含任何密钥。

Claude Code:所有项目

改为在用户级别注册一次:

claude mcp add --scope user keygrant -- keygrant mcp

你仍然需要在每个项目中(或在用户级 CLAUDE.md 中)加入 CLAUDE.md 指引,让模型知道要使用 $NAME,而不是索要密钥值。keygrant init 会自动添加;你也可以自己复制:

## Secrets (keygrant)

API keys and other secrets are managed by keygrant and must NEVER appear in
this conversation. Rules:

- Never ask the user to paste a secret value; never echo, log, or hardcode one.
- To see which secrets exist, use the `list_secrets` MCP tool.
- To run a command that needs a secret, use the `exec_with_secrets` MCP tool
  and reference the secret as an environment variable (e.g. `$STRIPE_KEY` /
  `%STRIPE_KEY%`). The user approves each use via a native dialog.
- If access is denied, do not retry; ask the user what they want to do.

其他 MCP 客户端

任何能启动 stdio MCP server 的客户端都可以使用。把它指向 keygrant-mcp,不带任何参数。大多数客户端(包括 Cursor 的 mcp.json)都使用上面所示的 mcpServers 结构。

如果客户端找不到该命令,请使用绝对路径:uv tool dir 或 pipx environment 会显示工具的安装位置。

命令中的 shell 语法

exec_with_secrets 通过平台 shell 运行命令:

平台Shell引用密钥的写法
macOS、Linuxsh -c$STRIPE_KEY
Windowscmd /c%STRIPE_KEY%
Windows,通过 PowerShellcmd /c powershell -Command "..."$env:STRIPE_KEY

工具描述中已经向模型说明了这些规则,所以你很少需要纠正它。