{"_id":"@akeyless-community/devin-connector","name":"@akeyless-community/devin-connector","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@akeyless-community/devin-connector","version":"0.1.0","description":"Akeyless Agentic Runtime Authority MCP connector for Devin Desktop (Windsurf) — SDK-based, no CLI required","license":"MIT","author":{"name":"Akeyless Community"},"mcpName":"io.github.akeyless-community/akeyless-rta","repository":{"type":"git","url":"git+https://github.com/akeyless-community/devin-akeyless-connector.git"},"homepage":"https://github.com/akeyless-community/devin-akeyless-connector#readme","keywords":["akeyless","devin","windsurf","cascade","mcp","agentic-runtime-authority","secrets","connector"],"engines":{"node":">=18"},"bin":{"akeyless-devin-mcp":"dist/index.js","devin-connector":"dist/index.js"},"main":"./dist/index.js","types":"./dist/index.d.ts","scripts":{"build":"tsc -p tsconfig.json && chmod +x dist/index.js","start":"node dist/index.js","dev":"tsc -p tsconfig.json --watch","test":"jest","prepublishOnly":"npm run build && npm test"},"publishConfig":{"access":"public"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","akeyless":"^5.0.26","akeyless-cloud-id":"^1.0.0","zod":"^3.23.8"},"devDependencies":{"@types/jest":"^29.5.14","@types/node":"^20.17.0","jest":"^29.7.0","ts-jest":"^29.2.5","typescript":"^5.7.2"},"gitHead":"5a63133798a0e750ab24e75c95ad68991335af49","_id":"@akeyless-community/devin-connector@0.1.0","bugs":{"url":"https://github.com/akeyless-community/devin-akeyless-connector/issues"},"_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-HSC7D0O3rUZNaWjDKX8hbvpL87pyRT6F2hzPFKv6TW3cP+LJwvfIbBayDEcS9uiAEPGNy2yE0RmXWTQnKPC1AA==","shasum":"24953a592f29d378ed6ab4df5f7d7a5bcbf6da94","tarball":"https://registry.npmjs.org/@akeyless-community/devin-connector/-/devin-connector-0.1.0.tgz","fileCount":45,"unpackedSize":150486,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHAoQ6foukrKR4uUnd1W8PjJo1E8zHPDUcLY2j22lPfrAiEA2HJ9NZgpQCcYINlerCdGRXjbE6wIxl78lz5Gg1AWv8M="}]},"_npmUser":{"name":"barak-akeyless","email":"barak.a@akeyless.io"},"directories":{},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/devin-connector_0.1.0_1783407590781_0.08399353929397146"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-07T06:59:50.615Z","0.1.0":"2026-07-07T06:59:50.920Z","modified":"2026-07-07T06:59:51.136Z"},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"description":"Akeyless Agentic Runtime Authority MCP connector for Devin Desktop (Windsurf) — SDK-based, no CLI required","homepage":"https://github.com/akeyless-community/devin-akeyless-connector#readme","keywords":["akeyless","devin","windsurf","cascade","mcp","agentic-runtime-authority","secrets","connector"],"repository":{"type":"git","url":"git+https://github.com/akeyless-community/devin-akeyless-connector.git"},"author":{"name":"Akeyless Community"},"bugs":{"url":"https://github.com/akeyless-community/devin-akeyless-connector/issues"},"license":"MIT","readme":"# Akeyless Connector for Devin Desktop\n\nAn SDK-based MCP connector that brings [Akeyless Agentic Runtime Authority (ARA)](https://docs.akeyless.io/docs/agentic-runtime-authority) to [Devin Desktop](https://devin.ai/desktop) (formerly Windsurf) — without installing the Akeyless CLI.\n\nCascade orchestrates. Akeyless holds the credentials. **Secret values never enter the model context.**\n\n[![Install in Devin Desktop](https://img.shields.io/badge/Install-Devin%20Desktop%20MCP-blue)](windsurf://windsurf-mcp-registry?serverName=akeyless-rta)\n\n## Install\n\n### One-click (after marketplace listing)\n\nOpen in Devin Desktop:\n\n```text\nwindsurf://windsurf-mcp-registry?serverName=akeyless-rta\n```\n\nOr: **Cascade panel → MCPs icon → Marketplace → search \"Akeyless\" → Install**\n\nConfigure your Gateway URL and credentials when prompted, then refresh MCP servers.\n\n### npm / npx (manual config)\n\nPublished on npm as [`@akeyless-community/devin-connector`](https://www.npmjs.com/package/@akeyless-community/devin-connector):\n\n```bash\nnpm install -g @akeyless-community/devin-connector\n```\n\nOr use `npx` without a global install — see [MCP configuration](#mcp-configuration) below.\n\n### Install script\n\n```bash\n# Pre-publish local testing (uses dist/index.js on this machine)\n./scripts/install-devin-mcp.sh --local\n\n# After npm publish\n./scripts/install-devin-mcp.sh\n```\n\nMerges the template into `~/.codeium/windsurf/mcp_config.json`.\n\nValidate your config:\n\n```bash\n./scripts/validate-mcp-config.sh\n```\n\n## How to use it (after install)\n\n1. **Add or enable the MCP server** in Devin Desktop (marketplace or config below).\n2. **Set `AKEYLESS_*` env vars** in `mcp_config.json` or your shell.\n3. **Refresh MCP** in Cascade (MCPs icon → Refresh).\n4. **Ask Cascade in natural language.** The agent calls the connector tools automatically.\n\nExample prompts:\n\n> \"List my Akeyless ARA secrets.\"\n\n> \"Run `SELECT count(*) FROM customers` against `/prod/db/postgres-readonly`.\"\n\n> \"Use service-execute on `/prod/aws/devops` to list S3 buckets.\"\n\n### What happens under the hood\n\n| Step | Tool | What you see |\n|---|---|---|\n| 1 | `list-secrets` | Secret paths and target types (no credentials) |\n| 2 | `query-db` or `service-execute` | Query/action results only |\n| 3 | ARA audit | Session recorded in Akeyless with your Agent ID |\n\nCascade may ask you to **approve** tool calls before they run — that is expected for infrastructure access.\n\n### First-time SAML/OIDC login\n\nIf you configured **saml** or **oidc** as the authentication method, the **first tool call** opens your browser for login. Complete the IdP sign-in, then return to Devin Desktop — subsequent calls reuse the cached session until it expires.\n\n### Universal Identity\n\nSet `AKEYLESS_ACCESS_TYPE=universal_identity` and point `AKEYLESS_UID_TOKEN_FILE` at the auto-rotated token path (default: `~/.akeyless/uid_rotator/uid-token`).\n\n## Why this exists\n\nDevin Desktop natively supports MCP, but connecting to Akeyless ARA still requires knowing the right `mcp_config.json` shape and auth env vars. The CLI-based `akeyless mcp-runtime-authority` path also requires installing and maintaining the Akeyless CLI.\n\nThis connector uses the official **Akeyless Node.js SDK** (`akeyless` npm package) and ships as a stdio MCP server for one-click marketplace install or manual configuration.\n\n## Architecture\n\n```mermaid\nsequenceDiagram\n    participant User as User\n    participant Cascade as Cascade Agent\n    participant MCP as akeyless-devin-mcp\n    participant API as Akeyless API\n    participant GW as Akeyless Gateway\n    participant Target as Database / Cloud\n\n    User->>Cascade: \"Query prod postgres for user count\"\n    Cascade->>MCP: list-secrets\n    MCP->>API: list-items via gw:8000/api/v2\n    API-->>MCP: secret paths + target types\n    MCP-->>Cascade: /prod/db/postgres-ro\n    Cascade->>MCP: query-db\n    MCP->>GW: POST gw:8000/config/target_query\n    GW->>Target: execute with JIT credentials\n    Target-->>GW: query results\n    GW-->>MCP: JSON results (no credentials)\n    MCP-->>Cascade: { count: 42 }\n```\n\n## MCP tools\n\n| Tool | Purpose |\n|---|---|\n| `list-secrets` | List ARA-enabled dynamic, rotated, and custom-MCP secrets your role can access |\n| `query-db` | Run database queries (MySQL, PostgreSQL, MongoDB, Redis, etc.) |\n| `service-execute` | Run AWS, GCP, Azure, Kubernetes, GitHub, or custom MCP actions |\n| `list-sub-tools` | Optional: discover a service secret's sub-tool names/parameters before calling `service-execute` |\n\nThese match the tools exposed by `akeyless mcp-runtime-authority`, but run through the SDK instead of the CLI.\n\n## MCP configuration\n\nGlobal config path:\n\n| OS | Path |\n|---|---|\n| macOS / Linux | `~/.codeium/windsurf/mcp_config.json` |\n| Windows | `%USERPROFILE%\\.codeium\\windsurf\\mcp_config.json` |\n\nAdd to `mcp_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"akeyless-rta\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@akeyless-community/devin-connector\"],\n      \"env\": {\n        \"AKEYLESS_GATEWAY_URL\": \"${env:AKEYLESS_GATEWAY_URL}\",\n        \"AKEYLESS_ACCESS_TYPE\": \"access_key\",\n        \"AKEYLESS_ACCESS_ID\": \"${env:AKEYLESS_ACCESS_ID}\",\n        \"AKEYLESS_ACCESS_KEY\": \"${env:AKEYLESS_ACCESS_KEY}\",\n        \"AKEYLESS_AGENT_ID\": \"devin-desktop\"\n      }\n    }\n  }\n}\n```\n\nSee [`examples/mcp_config.json`](examples/mcp_config.json) for a copy-paste template.\n\nDevin Desktop supports `${env:VAR}` interpolation in `env` fields — keep secrets in your shell or a `.env` file, not hardcoded in the config.\n\n### CLI alternative\n\n```bash\ndevin mcp add akeyless-rta -- npx -y @akeyless-community/devin-connector\n```\n\n## Troubleshooting\n\n### MCP server does not appear in Devin\n\n1. **Validate JSON** — one typo makes Devin ignore the whole file:\n   ```bash\n   ./scripts/validate-mcp-config.sh\n   ```\n   Common mistake: `\"\"https://...` (double quote before the URL).\n\n2. **Check Devin logs**:\n   ```text\n   ~/Library/Application Support/Devin/logs/*/window*/exthost/codeium.windsurf/Devin.log\n   ```\n\n3. **Pre-publish testing** — use local install (npm package not published yet):\n   ```bash\n   npm run build\n   ./scripts/install-devin-mcp.sh --local\n   ```\n\n4. **Refresh MCP** — Cascade panel → **MCPs** icon → **Refresh**.\n\n5. **Where in UI** — look for MCP server **`akeyless-rta`** in the Cascade MCP panel (MCPs icon). Devin’s settings UI varies by version; if you do not see a Tools list, the server can still work when configured correctly.\n\n6. **macOS PATH** — GUI apps may not find `npx`. Use absolute `node` + `dist/index.js` paths (see `mcp_config.local.json`).\n\n## Marketplace submission\n\nTo get a **one-click install** in the default Devin Desktop MCP Marketplace:\n\n1. Publish `@akeyless-community/devin-connector` to npm\n2. Publish `server.json` to the [official MCP Registry](https://modelcontextprotocol.io/registry/quickstart)\n3. Submit listing request using [docs/MARKETPLACE.md](docs/MARKETPLACE.md) and [docs/SUBMISSION.md](docs/SUBMISSION.md)\n\nTarget server ID: **`akeyless-rta`**  \nInstall deeplink: `windsurf://windsurf-mcp-registry?serverName=akeyless-rta`\n\n## Development\n\n### Requirements\n\n- Node.js >= 18\n- Devin Desktop with MCP support (for end-to-end testing)\n\n### Build and test\n\n```bash\nnpm ci\nnpm run build\nnpm test\nnpm start\n```\n\n### Local MCP override (before npm publish)\n\n```json\n{\n  \"mcpServers\": {\n    \"akeyless-rta\": {\n      \"command\": \"node\",\n      \"args\": [\"/absolute/path/to/devin-akeyless-connector/dist/index.js\"],\n      \"env\": { \"...\": \"...\" }\n    }\n  }\n}\n```\n\n## Comparison with CLI-based setup\n\n| | CLI (`mcp-runtime-authority`) | This connector |\n|---|---|---|\n| Runtime | Akeyless CLI binary | Node.js + `akeyless` SDK |\n| Auth | CLI profile (`--profile`) | Env vars in `mcp_config.json` |\n| Gateway config | `--gateway-url` (ARA port) | Single `AKEYLESS_GATEWAY_URL` (derives `/api/v2` + config port) |\n| Install | Install CLI + configure profile | `npx` or marketplace one-click |\n| Tools | list-secrets, query-db, service-execute, list-sub-tools | Same four tools |\n\n## Related projects\n\n- [`claude-akeyless-connector`](https://github.com/akeyless-community/claude-akeyless-connector) — SDK-based MCP for Claude Desktop (`.mcpb` extension)\n- [`cursor-akeyless-connector`](https://github.com/akeyless-community/cursor-akeyless-connector) — SDK-based MCP for Cursor (plugin marketplace)\n- [`codex-akeyless-integration`](https://github.com/akeyless-community/codex-akeyless-mcp) — SDK-based MCP for OpenAI Codex\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n\n## Privacy Policy\n\nThis connector runs **locally on your machine** as a stdio MCP server. It does not send conversation content to Akeyless.\n\n**What the connector accesses**\n\n- Your configured **Akeyless Gateway** for authentication, secret listing, and ARA execution\n- Environment variables you provide for auth (`AKEYLESS_ACCESS_ID`, `AKEYLESS_ACCESS_KEY`, etc.)\n\n**What leaves your machine**\n\n- API calls to **your** Akeyless Gateway only (auth, list-items, target_query, service execution)\n- Query and action **results** returned to Cascade (never raw secret values from the vault)\n\n**What is not collected**\n\n- No telemetry or analytics from this connector\n- No conversation logs sent to Akeyless\n- Secret values are resolved server-side by the Gateway and are not included in MCP tool responses\n\nFor Akeyless platform privacy terms, see https://www.akeyless.io/privacy-policy/\n","readmeFilename":"README.md","_rev":"1-96f50ac4d4168ff9db9cbd5a55363b7d"}