{"_id":"@akari-os/keymaster-mcp","_rev":"4-528e5b67613547684e3544d2d176f950","name":"@akari-os/keymaster-mcp","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.0":{"name":"@akari-os/keymaster-mcp","version":"1.0.0","keywords":["mcp","model-context-protocol","vault","secrets","keymaster","akari","hashicorp-vault","ai-agent","claude","secret-management"],"author":{"url":"https://ai-akari.ai","name":"AInoAKARI","email":"aino-akari@ai-akari.ai"},"license":"MIT","_id":"@akari-os/keymaster-mcp@1.0.0","maintainers":[{"name":"akari-os","email":"aino-akari@ai-akari.ai"}],"homepage":"https://github.com/AInoAKARI/keymaster-mcp#readme","bugs":{"url":"https://github.com/AInoAKARI/keymaster-mcp/issues"},"bin":{"keymaster-mcp":"dist/index.js"},"dist":{"shasum":"0d4ce54ff0ea09e9bf3280e9f04901ed38dffcf7","tarball":"https://registry.npmjs.org/@akari-os/keymaster-mcp/-/keymaster-mcp-1.0.0.tgz","fileCount":6,"integrity":"sha512-fMyeMzOrOiDvbz5u+ZrBUI9Sn/5TfNqWJUBPDVKEMhozo9Nb6A9i8UjOx5D90Q7YoQEh7VcpJ/Ps0ISuTf9gFw==","signatures":[{"sig":"MEUCIGtzlLyf+l3WCdxT0Q2YQK8+iSh2a6CcbuyBqhQc5XUGAiEAgca71Szm/bfLklCgk4MQcS4++3Ucmazrgih5LTKPaH0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36962},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"36bc7caadd8ce45eaeb5ce542b69f651035c4a06","scripts":{"dev":"ts-node src/index.ts","build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"_npmUser":{"name":"akari-os","email":"aino-akari@ai-akari.ai"},"repository":{"url":"git+https://github.com/AInoAKARI/keymaster-mcp.git","type":"git"},"_npmVersion":"10.9.4","description":"MCP server for secure secret retrieval from HashiCorp Vault via Keymaster proxy. The Vault for AI Agents.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/keymaster-mcp_1.0.0_1775023793387_0.289263873855623","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@akari-os/keymaster-mcp","version":"1.0.1","keywords":["mcp","model-context-protocol","vault","secrets","keymaster","akari","hashicorp-vault","ai-agent","claude","secret-management"],"author":{"url":"https://ai-akari.ai","name":"AInoAKARI","email":"aino-akari@ai-akari.ai"},"license":"MIT","_id":"@akari-os/keymaster-mcp@1.0.1","maintainers":[{"name":"akari-os","email":"aino-akari@ai-akari.ai"}],"homepage":"https://github.com/AInoAKARI/keymaster-mcp#readme","bugs":{"url":"https://github.com/AInoAKARI/keymaster-mcp/issues"},"bin":{"keymaster-mcp":"dist/index.js"},"dist":{"shasum":"020044d00385be881eeeb452ee487d4959746f56","tarball":"https://registry.npmjs.org/@akari-os/keymaster-mcp/-/keymaster-mcp-1.0.1.tgz","fileCount":9,"integrity":"sha512-9Go+s8Ed49IcKOqtRZprlpxNenxfvnxQQEz+InUt5vTRSeGkwHuEWd+ajfYWnOqx+jm9Ijd2d3OHQyBHVdzKQA==","signatures":[{"sig":"MEYCIQC84vyycLNJEAe6zrSIeh0OSA3soHyAMHrL6h7hWmFVbgIhAOtC0FmHImoNP5W6k1fkktlXQG15Xu1Z/oCf1CI5+icG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":39637},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"36bc7caadd8ce45eaeb5ce542b69f651035c4a06","mcpName":"io.github.ainoakari/keymaster-mcp","scripts":{"dev":"ts-node src/index.ts","build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"_npmUser":{"name":"akari-os","email":"aino-akari@ai-akari.ai"},"repository":{"url":"git+https://github.com/AInoAKARI/keymaster-mcp.git","type":"git"},"_npmVersion":"10.9.4","description":"Read-only MCP server for runtime secret retrieval from HashiCorp Vault via Keymaster, built for autonomous AI agents.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.24.1","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/keymaster-mcp_1.0.1_1775103474140_0.8506666679143924","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@akari-os/keymaster-mcp","version":"1.0.2","keywords":["mcp","model-context-protocol","vault","secrets","keymaster","akari","hashicorp-vault","ai-agent","claude","secret-management"],"author":{"url":"https://ai-akari.ai","name":"AInoAKARI","email":"aino-akari@ai-akari.ai"},"license":"MIT","_id":"@akari-os/keymaster-mcp@1.0.2","maintainers":[{"name":"akari-os","email":"aino-akari@ai-akari.ai"}],"homepage":"https://github.com/AInoAKARI/keymaster-mcp#readme","bugs":{"url":"https://github.com/AInoAKARI/keymaster-mcp/issues"},"bin":{"keymaster-mcp":"dist/index.js"},"dist":{"shasum":"9c8670e61b1a4e50ac74e1023dd2233efdc57b80","tarball":"https://registry.npmjs.org/@akari-os/keymaster-mcp/-/keymaster-mcp-1.0.2.tgz","fileCount":9,"integrity":"sha512-hkZOdlpS8X1gj8ioN+l13NpQN8bsgFbiEo69or4Z8UninfIeXgH6+64aX2AJBUM7Fns6g8bqIw4Lx3vO6QxQug==","signatures":[{"sig":"MEUCIBIAGrj2+FZoUuirlkqeOHpdVwlpzX+I6YxFRbG9eRUKAiEA/jMMfUwAwuA6JmL8xABCooz+EvLNK463QJs31hPxAVQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":39795},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"36bc7caadd8ce45eaeb5ce542b69f651035c4a06","mcpName":"io.github.AInoAKARI/keymaster-mcp","scripts":{"dev":"ts-node src/index.ts","build":"tsc","start":"node dist/index.js","prepublishOnly":"npm run build"},"_npmUser":{"name":"akari-os","email":"aino-akari@ai-akari.ai"},"repository":{"url":"git+https://github.com/AInoAKARI/keymaster-mcp.git","type":"git"},"_npmVersion":"10.9.4","description":"Read-only MCP server for runtime secret retrieval from HashiCorp Vault via Keymaster, built for autonomous AI agents.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.24.1","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/keymaster-mcp_1.0.2_1775103731044_0.9319275746876343","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@akari-os/keymaster-mcp","version":"1.0.3","description":"Read-only MCP server for runtime secret retrieval from HashiCorp Vault via Keymaster, built for autonomous AI agents.","mcpName":"io.github.ainoakari/keymaster-mcp","main":"dist/index.js","types":"dist/index.d.ts","bin":{"keymaster-mcp":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js","dev":"ts-node src/index.ts","prepublishOnly":"npm run build"},"keywords":["mcp","model-context-protocol","vault","secrets","keymaster","akari","hashicorp-vault","ai-agent","claude","secret-management"],"author":{"name":"AInoAKARI","email":"aino-akari@ai-akari.ai","url":"https://ai-akari.ai"},"license":"MIT","homepage":"https://github.com/AInoAKARI/keymaster-mcp#readme","repository":{"type":"git","url":"git+https://github.com/AInoAKARI/keymaster-mcp.git"},"bugs":{"url":"https://github.com/AInoAKARI/keymaster-mcp/issues"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","zod":"^3.24.1"},"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0","ts-node":"^10.9.0"},"engines":{"node":">=18.0.0"},"_id":"@akari-os/keymaster-mcp@1.0.3","gitHead":"68d9c9a1ba5e3d60ef1e94775faaff391da85acb","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-ZXI7DIAREyJ3narN/AdFXhnNWSnru2rc6s7maFr806l2kVi3RvSfyyPzDic0Wz1AeZBp5EMzlss9FxXbec3+mQ==","shasum":"9d86700839df7c28c63ea411012532ade9b7de5d","tarball":"https://registry.npmjs.org/@akari-os/keymaster-mcp/-/keymaster-mcp-1.0.3.tgz","fileCount":9,"unpackedSize":40735,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCsbe3aH64U1rlV4vdf36+skwCRR8zZmYP4lrQgveqaKgIgVQC58GU9vOh3nbvmk4aFhzQbUAyox7dxHgJaKKh73Hc="}]},"_npmUser":{"name":"akari-os","email":"aino-akari@ai-akari.ai"},"directories":{},"maintainers":[{"name":"akari-os","email":"aino-akari@ai-akari.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/keymaster-mcp_1.0.3_1775104351355_0.804423853139361"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-01T06:09:53.323Z","modified":"2026-04-02T04:32:31.614Z","1.0.0":"2026-04-01T06:09:53.534Z","1.0.1":"2026-04-02T04:17:54.323Z","1.0.2":"2026-04-02T04:22:11.184Z","1.0.3":"2026-04-02T04:32:31.510Z"},"bugs":{"url":"https://github.com/AInoAKARI/keymaster-mcp/issues"},"author":{"name":"AInoAKARI","email":"aino-akari@ai-akari.ai","url":"https://ai-akari.ai"},"license":"MIT","homepage":"https://github.com/AInoAKARI/keymaster-mcp#readme","keywords":["mcp","model-context-protocol","vault","secrets","keymaster","akari","hashicorp-vault","ai-agent","claude","secret-management"],"repository":{"type":"git","url":"git+https://github.com/AInoAKARI/keymaster-mcp.git"},"description":"Read-only MCP server for runtime secret retrieval from HashiCorp Vault via Keymaster, built for autonomous AI agents.","maintainers":[{"name":"akari-os","email":"aino-akari@ai-akari.ai"}],"readme":"# Keymaster MCP Server\n\n`@akari-os/keymaster-mcp` is the read-only Vault bridge for autonomous agents.\nAgents fetch secrets at runtime through Keymaster instead of carrying API keys in `.env`, prompts, or shell history.\nIt is built for Claude Code, Codex, OpenClaw, cron jobs, and A2A agents that need credentials with no human in the loop.\n\n<!-- mcp-name: io.github.ainoakari/keymaster-mcp -->\n\n## Install In One Command\n\n```bash\nclaude mcp add keymaster -- npx -y @akari-os/keymaster-mcp --vault-url https://your-keymaster.example.com --token YOUR_TOKEN\n```\n\nIf you prefer environment variables instead of inline credentials:\n\n```bash\nclaude mcp add keymaster keymaster-mcp \\\n  -e USER_KEYMASTER_URL=https://your-keymaster.example.com \\\n  -e USER_KEYMASTER_TOKEN=YOUR_TOKEN\n```\n\n## What You Get\n\n- `get_secret` fetches `openai/api_key`, `stripe/webhook_secret`, and other approved Vault values on demand.\n- `list_services` and `list_secrets` let agents discover available service/key pairs before a workflow starts.\n- `healthcheck` validates 30+ service credentials against upstream APIs before production jobs fail.\n- `rotate_secret` stays read-only and returns the safe Vault-side rotation path instead of mutating secrets.\n\n## Why This Exists Next To 1Password\n\n1Password is great when a human is present to unlock a vault and copy a credential.\nKeymaster MCP is for unattended agents that need runtime access over MCP and should never be given full secret-store write access.\n\n| | 1Password | Keymaster MCP |\n|---|---|---|\n| Primary user | Human operator | Autonomous agent |\n| Retrieval flow | Unlock UI and copy | MCP tool call |\n| Secret-store writes | Full CRUD | No writes |\n| Rotation model | Human updates each consumer | Rotate once in Vault, agents pick up the new value next call |\n| Multi-agent usage | Manual and awkward | Native |\n| Best fit | Person in the loop | No person in the loop |\n\n## Quick Config\n\n### Claude Desktop or Codex CLI\n\n```json\n{\n  \"mcpServers\": {\n    \"keymaster\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@akari-os/keymaster-mcp\"],\n      \"env\": {\n        \"USER_KEYMASTER_URL\": \"https://your-keymaster.example.com\",\n        \"USER_KEYMASTER_TOKEN\": \"YOUR_TOKEN\"\n      }\n    }\n  }\n}\n```\n\n### Configuration\n\n| CLI argument | Environment variable | Description |\n|---|---|---|\n| `--vault-url <url>` | `USER_KEYMASTER_URL` | Keymaster proxy URL |\n| `--token <token>` | `USER_KEYMASTER_TOKEN` | Bearer token for Keymaster |\n| `-h, --help` | | Show help |\n\nCLI arguments override environment variables.\n\n## Core Tools\n\n### `get_secret`\n\nRetrieve a secret from Vault through the read-only Keymaster boundary.\n\n```json\nget_secret({ \"service\": \"openai\" })\n```\n\n```json\n{\n  \"service\": \"openai\",\n  \"key_name\": \"api_key\",\n  \"api_key\": \"sk-...\"\n}\n```\n\n### `list_services`\n\nList known service and key-name pairs, including whether each key can be verified upstream.\n\n### `list_secrets`\n\nList retrievable secret paths in `service/key_name` form.\n\n### `healthcheck`\n\nRun a full status sweep across known secrets.\n\n```json\n{\n  \"total\": 34,\n  \"valid\": 28,\n  \"exists_only\": 4,\n  \"invalid\": 1,\n  \"errors\": 1\n}\n```\n\n### `rotate_secret`\n\nKeymaster MCP is intentionally read-only. This tool explains the safe Vault-side rotation path instead of performing writes.\n\n## Runtime Model\n\n```text\nAI Agent\n  -> MCP: get_secret({ service, key_name })\n    -> Keymaster HTTP proxy\n      -> HashiCorp Vault KV v2\n```\n\nSecrets are fetched at runtime, not stored locally. Rotate once in Vault and every agent sees the new value on its next call.\n\n## A2A And Multi-Agent Use\n\n- Each agent fetches its own credentials instead of passing secrets agent-to-agent.\n- `healthcheck` can run before nightly jobs, deploys, or long workflows.\n- The same Vault-backed source can serve Claude Code, Codex, OpenClaw, cron jobs, and remote A2A agents.\n\n## Supported Services\n\nBuilt-in validation covers 30+ services including OpenAI, Anthropic, Groq, Moonshot, DeepSeek, GitHub, Notion, Stripe, SendGrid, Discord, Telegram, Vercel, Render, Cloudflare, Supabase, Resend, and Daily.\n\n## Security Model\n\n- Read-only by design\n- TLS transport to Keymaster\n- No secret caching\n- No secret logging\n- Token-scoped access\n\n## Requirements\n\n- Node.js 18+\n- A running Keymaster proxy connected to HashiCorp Vault\n- A valid bearer token for that proxy\n\n## License\n\nMIT\n","readmeFilename":"README.md"}