{"_id":"@akeyless-community/mistral-connector","name":"@akeyless-community/mistral-connector","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@akeyless-community/mistral-connector","version":"0.1.0","description":"Akeyless ARA and secure secret MCP connector for Mistral AI — stdio and Streamable HTTP","license":"MIT","author":{"name":"Akeyless Community"},"repository":{"type":"git","url":"git+https://github.com/akeyless-community/mistral-akeyless-connector.git"},"homepage":"https://github.com/akeyless-community/mistral-akeyless-connector#readme","keywords":["akeyless","mistral","mcp","agentic-runtime-authority","secrets","connector"],"engines":{"node":">=18"},"bin":{"akeyless-mistral-mcp":"dist/index.js","mistral-connector":"dist/index.js"},"main":"./dist/index.js","types":"./dist/index.d.ts","scripts":{"build":"tsc -p tsconfig.json && chmod +x dist/index.js","start":"node dist/index.js","start:http":"node dist/index.js --http","dev":"tsc -p tsconfig.json --watch","test":"jest","prepublishOnly":"npm run build && npm test"},"publishConfig":{"access":"public"},"dependencies":{"@aws-sdk/credential-providers":"^3.1000.0","@azure/identity":"^4.8.0","@google-cloud/iam-credentials":"^3.3.0","@modelcontextprotocol/sdk":"^1.29.0","akeyless":"^5.0.26","aws4":"^1.13.0","google-auth-library":"^10.6.1","zod":"^3.23.8"},"devDependencies":{"@types/express":"^5.0.0","@types/jest":"^29.5.14","@types/node":"^20.17.0","jest":"^29.7.0","ts-jest":"^29.2.5","typescript":"^5.7.2"},"overrides":{"uuid":"^11.1.1","@grpc/grpc-js":"^1.14.0","protobufjs":"^7.4.0"},"_id":"@akeyless-community/mistral-connector@0.1.0","bugs":{"url":"https://github.com/akeyless-community/mistral-akeyless-connector/issues"},"_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-p5k8IpI1AvGwJX+OwYqeWBzuNmOMQ+dYqVVJO/7vV18ygFoUeLhAFmDBEX6ea6x9NJuLX+ErwnUL3iUT56Nrcw==","shasum":"b6150744b891d703c6426b607adb9138b509498c","tarball":"https://registry.npmjs.org/@akeyless-community/mistral-connector/-/mistral-connector-0.1.0.tgz","fileCount":55,"unpackedSize":162001,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIF1bDMGAiCi5+J+jwumNibhifzgUjYhFGUBcw3jYiNhFAiBq/oYIDtDD5capd1SuneQUPEBS1JhPWhQuBAWgsEdu2g=="}]},"_npmUser":{"name":"barak-akeyless","email":"barak.a@akeyless.io"},"directories":{},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mistral-connector_0.1.0_1783832943125_0.02346696582958785"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-12T05:09:02.997Z","0.1.0":"2026-07-12T05:09:03.267Z","modified":"2026-07-12T05:09:03.496Z"},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"description":"Akeyless ARA and secure secret MCP connector for Mistral AI — stdio and Streamable HTTP","homepage":"https://github.com/akeyless-community/mistral-akeyless-connector#readme","keywords":["akeyless","mistral","mcp","agentic-runtime-authority","secrets","connector"],"repository":{"type":"git","url":"git+https://github.com/akeyless-community/mistral-akeyless-connector.git"},"author":{"name":"Akeyless Community"},"bugs":{"url":"https://github.com/akeyless-community/mistral-akeyless-connector/issues"},"license":"MIT","readme":"# Akeyless Connector for Mistral AI\n\nAn SDK-based MCP connector that brings [Akeyless Agentic Runtime Authority (ARA)](https://docs.akeyless.io/docs/agentic-runtime-authority) and **secure secret fetching** to [Mistral AI](https://mistral.ai) — without installing the Akeyless CLI.\n\nMistral orchestrates. Akeyless holds the credentials. **ARA tools never expose secret values to the model.**\n\n## Features\n\n| Capability | Tools |\n|---|---|\n| **ARA (secretless)** | `list-secrets`, `query-db`, `service-execute`, `list-sub-tools` |\n| **Secure secret fetch** | `list-items`, `get-secret-value` (RBAC, masking, JSON field extraction) |\n| **Transports** | stdio (local) and Streamable HTTP (Mistral Connectors) |\n\n## Install\n\nPublished on npm as [`@akeyless-community/mistral-connector`](https://www.npmjs.com/package/@akeyless-community/mistral-connector):\n\n```bash\nnpm install -g @akeyless-community/mistral-connector\n```\n\nOr use `npx` without a global install.\n\n## Quick start\n\n### Option A — Mistral Studio Connectors (recommended)\n\nMistral Connectors require a **public HTTPS** MCP endpoint. Deploy the HTTP transport behind TLS (reverse proxy, load balancer, or cloud runtime), then register it in Studio.\n\n1. **Start the HTTP server** (behind your TLS terminator):\n\n```bash\nexport AKEYLESS_GATEWAY_URL=https://your-gateway.example.com:8000/api/v2\nexport AKEYLESS_ACCESS_ID=p-xxxxx\nexport AKEYLESS_ACCESS_KEY=your-access-key\nexport AKEYLESS_AGENT_ID=mistral\nexport AKEYLESS_MCP_TRANSPORT=http\nexport AKEYLESS_MCP_HTTP_API_KEY=your-mcp-api-key   # recommended\nnpx -y @akeyless-community/mistral-connector --http\n```\n\n2. **Register in Mistral Studio** → **Connectors** → **Custom MCP Connector**:\n\n| Field | Value |\n|---|---|\n| Connector name | `akeyless-ara` |\n| Server URL | `https://your-public-host.example.com/mcp` |\n| Auth | Bearer token matching `AKEYLESS_MCP_HTTP_API_KEY` |\n\nOr register via API:\n\n```bash\nexport MISTRAL_API_KEY=your-mistral-api-key\nexport MISTRAL_CONNECTOR_SERVER_URL=https://your-public-host.example.com/mcp\npython3 scripts/register-mistral-connector.py\n```\n\n3. **Attach the connector** to a conversation or agent and ask in natural language:\n\n> \"List my Akeyless ARA secrets and run `SELECT count(*) FROM users` against `/prod/db/postgres-readonly`.\"\n\n### Option B — Local stdio (development)\n\n```bash\nexport AKEYLESS_GATEWAY_URL=https://your-gateway.example.com:8000/api/v2\nexport AKEYLESS_ACCESS_ID=p-xxxxx\nexport AKEYLESS_ACCESS_KEY=your-access-key\nnpx -y @akeyless-community/mistral-connector\n```\n\nUse with any MCP client that supports stdio transport.\n\n## Architecture\n\n```mermaid\nsequenceDiagram\n    participant User as User\n    participant Mistral as Mistral Agent\n    participant MCP as akeyless-mistral-mcp\n    participant API as Akeyless API\n    participant GW as Akeyless Gateway\n    participant Target as Database / Cloud\n\n    User->>Mistral: \"Query prod postgres for user count\"\n    Mistral->>MCP: list-secrets\n    MCP->>API: list-items via gw:8000/api/v2\n    API-->>MCP: secret paths + target types\n    MCP-->>Mistral: /prod/db/postgres-ro\n    Mistral->>MCP: query-db\n    MCP->>GW: POST gw:8000/config/target_query\n    GW->>Target: execute with JIT credentials\n    Target-->>GW: query results\n    GW-->>MCP: JSON results (no credentials)\n    MCP-->>Mistral: { count: 42 }\n```\n\n## MCP tools\n\n### ARA tools (secretless — preferred)\n\n| Tool | Purpose |\n|---|---|\n| `list-secrets` | List ARA-enabled dynamic, rotated, and custom-MCP secrets |\n| `query-db` | Run database queries (MySQL, PostgreSQL, MongoDB, Redis, etc.) |\n| `service-execute` | Run AWS, GCP, Azure, Kubernetes, GitHub, or custom MCP actions |\n| `list-sub-tools` | Optional: discover service sub-tool names/parameters |\n\n### Secure secret tools\n\n| Tool | Purpose |\n|---|---|\n| `list-items` | List static, dynamic, and rotated secrets — **metadata only** |\n| `get-secret-value` | Fetch a secret value with RBAC, optional masking, and JSON field extraction |\n\n`get-secret-value` supports:\n\n- `secret-type`: `static` (default), `dynamic`, or `rotated`\n- `json-key`: extract one field from a JSON secret (e.g. `OPENAI_API_KEY`)\n- `mask=true`: return a masked preview instead of the full value\n- `ignore-cache=true`: bypass Gateway cache\n\nSet `AKEYLESS_DISABLE_SECRET_VALUE_TOOLS=true` for ARA-only mode.\n\n## Environment variables\n\n| Variable | When to set |\n|---|---|\n| `AKEYLESS_GATEWAY_URL` | Always — e.g. `https://gw.example.com:8000/api/v2` |\n| `AKEYLESS_ACCESS_TYPE` | `access_key` (default), `saml`, `oidc`, `universal_identity`, `jwt`, `aws_iam`, `azure_ad`, `gcp` |\n| `AKEYLESS_ACCESS_ID` | `access_key`, `saml`, `oidc`, `jwt`, cloud IAM |\n| `AKEYLESS_ACCESS_KEY` | `access_key` only |\n| `AKEYLESS_AGENT_ID` | Recommended (default `mistral`) |\n| `AKEYLESS_MCP_TRANSPORT` | Set to `http` for Mistral Connectors |\n| `AKEYLESS_MCP_HTTP_HOST` | HTTP bind host (default `0.0.0.0`) |\n| `AKEYLESS_MCP_HTTP_PORT` | HTTP port (default `8787`) |\n| `AKEYLESS_MCP_HTTP_PATH` | MCP endpoint path (default `/mcp`) |\n| `AKEYLESS_MCP_HTTP_API_KEY` | Bearer token for HTTP auth (recommended in production) |\n| `AKEYLESS_DISABLE_SECRET_VALUE_TOOLS` | Set `true` to disable `get-secret-value` |\n\nSee [`.env.example`](.env.example) for all auth options.\n\n## Prerequisites\n\n- Akeyless Gateway with [Agentic Runtime Authority enabled](https://docs.akeyless.io/docs/agentic-runtime-authority)\n- A role with ARA **Allow Access** on relevant secret paths (for ARA tools)\n- Read permission on secret paths (for `get-secret-value`)\n- Node.js >= 18\n- For Mistral Connectors: public HTTPS endpoint with valid TLS certificate\n\n## Security model\n\n- **ARA is secretless** — credentials are resolved and used by the Gateway; only query/action results are returned\n- **RBAC-scoped** — Akeyless enforces role permissions on every API call\n- **Masked previews** — `get-secret-value` supports `mask=true` for verification without full exposure\n- **JSON field extraction** — `json_key` avoids returning entire JSON blobs\n- **HTTP API key** — protect the public MCP endpoint with `AKEYLESS_MCP_HTTP_API_KEY`\n- **Audited** — ARA executions are recorded with agent ID + MCP ID\n\n**Recommendations:**\n\n- Prefer ARA tools over `get-secret-value` whenever possible\n- Scope roles to least-privilege secret paths\n- Use `mask=true` unless the full value is explicitly required\n- Set meaningful Agent IDs per user or workload (e.g. `mistral-alice-workflow`)\n\n## Example prompts\n\n> \"List my Akeyless ARA secrets.\"\n\n> \"Run `SELECT count(*) FROM customers` against `/prod/db/postgres-readonly`.\"\n\n> \"Use service-execute on `/prod/aws/devops` to list all S3 buckets.\"\n\n> \"Verify I can read `/prod/api/openai-key` with masking enabled.\"\n\n## Development\n\n```bash\ncd mistral-akeyless-connector\nnpm install\nnpm run build\nnpm test\n```\n\nRun locally:\n\n```bash\n# stdio\nnpm start\n\n# HTTP\nnpm run start:http\n```\n\nHealth check (HTTP mode): `GET /health`\n\n## Related projects\n\n- [`cursor-akeyless-connector`](../cursor-akeyless-connector) — SDK-based MCP for Cursor\n- [`claude-akeyless-connector`](../claude-akeyless-connector) — SDK-based MCP for Claude Desktop\n- [`codex-akeyless-integration`](../codex-akeyless-integration) — SDK-based MCP for OpenAI Codex\n- [`devin-akeyless-connector`](../devin-akeyless-connector) — SDK-based MCP for Devin / Windsurf\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","readmeFilename":"README.md","_rev":"1-659d4b1f1848cb4aa28d4ffcd2c78dc8"}