{"_id":"@askalf/strongroom-mcp","_rev":"4-bc288f888f69374dda09f4df3ebe690c","name":"@askalf/strongroom-mcp","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.1":{"name":"@askalf/strongroom-mcp","version":"0.1.1","keywords":["mcp","model-context-protocol","ai-agents","agent-security","secrets","credentials","leases","least-privilege","own-your-stack"],"author":{"name":"Thomas Sprayberry"},"license":"MIT","_id":"@askalf/strongroom-mcp@0.1.1","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"homepage":"https://github.com/askalf/strongroom#readme","bugs":{"url":"https://github.com/askalf/strongroom/issues"},"bin":{"strongroom-mcp":"server.mjs"},"dist":{"shasum":"5ed90bda4b2d1303e41b0030498b69500a1875cd","tarball":"https://registry.npmjs.org/@askalf/strongroom-mcp/-/strongroom-mcp-0.1.1.tgz","fileCount":3,"integrity":"sha512-PlTpjkwLnMxCpuvRoNuia3SO0S+vP7jfiXF73S0aTcS8HV5IHaULcNWbv6cfL2nl/i99rhmjcy7hsskkDBRu/g==","signatures":[{"sig":"MEQCIDHxtRZWR+uTPQaI8bYpeQKoJSwydJMPPJhJUK7T3/OEAiAHAoNEadsMPLLt9RcJ8C+OMy+qIdVnaz+TaWPaqgysmQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14813},"type":"module","engines":{"node":">=20"},"exports":{".":"./server.mjs"},"scripts":{"test":"node --test smoke.mjs","start":"node server.mjs"},"_npmUser":{"name":"askalf","email":"support@askalf.org"},"repository":{"url":"git+https://github.com/askalf/strongroom.git","type":"git","directory":"mcp"},"_npmVersion":"10.9.4","description":"An MCP server that is the strongroom control plane: its tools mint scoped, expiring, revocable leases and hand agents a lease-backed base URL — so API keys never enter agent context. Part of Own Your Stack.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"4.4.3","@askalf/strongroom":"^0.3.0","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/strongroom-mcp_0.1.1_1784328959084_0.3264323337565247","host":"s3://npm-registry-packages-npm-production"},"deprecated":"strongroom-mcp is archived and no longer maintained. Source:github.com/sprayberry-archive/strongroom"},"0.1.2":{"name":"@askalf/strongroom-mcp","version":"0.1.2","keywords":["mcp","model-context-protocol","ai-agents","agent-security","secrets","credentials","leases","least-privilege","own-your-stack"],"author":{"name":"Thomas Sprayberry"},"license":"MIT","_id":"@askalf/strongroom-mcp@0.1.2","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"homepage":"https://github.com/askalf/strongroom#readme","bugs":{"url":"https://github.com/askalf/strongroom/issues"},"bin":{"strongroom-mcp":"server.mjs"},"dist":{"shasum":"2014eb6499b3570e833062d0c66608af2edc6159","tarball":"https://registry.npmjs.org/@askalf/strongroom-mcp/-/strongroom-mcp-0.1.2.tgz","fileCount":3,"integrity":"sha512-OJyOUguF1PLn3ABoWw4tynR9LxjWx7nKfe4C/juFr7PPjf3GXwQR9bcjKRh5ChSUaT3V2ZXGjckVfd0ZYKwywg==","signatures":[{"sig":"MEUCIQCTfW0T83UyIYxDYOQbd67F1J9ylqtmPYjgbWqbLfXACgIgFdPRrHHYLmokJeCtctAXPzHpU0vze8me3yS7ac1VvhQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askalf%2fstrongroom-mcp@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":14539},"type":"module","engines":{"node":">=20"},"exports":{".":"./server.mjs"},"gitHead":"2f5c0489c9cb08dff810cdc2bb5407c4640bb9ff","scripts":{"test":"node --test smoke.mjs e2e.mjs","start":"node server.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bbcbe732-fc60-4226-b90a-99e260afbd73"}},"repository":{"url":"git+https://github.com/askalf/strongroom.git","type":"git","directory":"mcp"},"_npmVersion":"11.16.0","description":"An MCP server that is the strongroom control plane: its tools mint scoped, expiring, revocable leases and hand agents a lease-backed base URL — so API keys never enter agent context. Part of Own Your Stack.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"4.4.3","@askalf/strongroom":"^0.3.0","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/strongroom-mcp_0.1.2_1784379753027_0.035975552044305914","host":"s3://npm-registry-packages-npm-production"},"deprecated":"strongroom-mcp is archived and no longer maintained. Source:github.com/sprayberry-archive/strongroom"},"0.1.3":{"name":"@askalf/strongroom-mcp","version":"0.1.3","keywords":["mcp","model-context-protocol","ai-agents","agent-security","secrets","credentials","leases","least-privilege","own-your-stack"],"author":{"name":"Thomas Sprayberry"},"license":"MIT","_id":"@askalf/strongroom-mcp@0.1.3","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"homepage":"https://github.com/askalf/strongroom#readme","bugs":{"url":"https://github.com/askalf/strongroom/issues"},"bin":{"strongroom-mcp":"server.mjs"},"dist":{"shasum":"af9b43dcbfbe2698f474bfc62d9f6dac7ee747d1","tarball":"https://registry.npmjs.org/@askalf/strongroom-mcp/-/strongroom-mcp-0.1.3.tgz","fileCount":3,"integrity":"sha512-WU3XWsS+qEx4jaHu3GDPF4hoBVUCVnhZrZKB9X2orR9u79FI7ar6/yVxurmVmng7yE9qEoqRoRk+Thag3WefAA==","signatures":[{"sig":"MEQCICLFoAP09mthBlPvudqPtEIqNYX8q1hfsiPhvP5cB8+cAiBoxe4tJCfsKbH3URoY8xmofzGDThgXdgvFSKajHkxqJQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askalf%2fstrongroom-mcp@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":14621},"type":"module","engines":{"node":">=20"},"exports":{".":"./server.mjs"},"gitHead":"e73715bb5c6a3262a2d8afa87ee2b45345d0dce9","scripts":{"test":"node --test smoke.mjs e2e.mjs","start":"node server.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bbcbe732-fc60-4226-b90a-99e260afbd73"}},"overrides":{"fast-uri":"^3.1.4","@hono/node-server":"^2.0.5"},"repository":{"url":"git+https://github.com/askalf/strongroom.git","type":"git","directory":"mcp"},"_npmVersion":"11.16.0","description":"An MCP server that is the strongroom control plane: its tools mint scoped, expiring, revocable leases and hand agents a lease-backed base URL — so API keys never enter agent context. Part of Own Your Stack.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"4.4.3","@askalf/strongroom":"^0.4.0","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/strongroom-mcp_0.1.3_1784927414538_0.8256290253284277","host":"s3://npm-registry-packages-npm-production"},"deprecated":"strongroom-mcp is archived and no longer maintained. Source:github.com/sprayberry-archive/strongroom"}},"time":{"created":"2026-07-17T22:55:58.935Z","modified":"2026-09-27T12:52:40.106Z","0.1.1":"2026-07-17T22:55:59.204Z","0.1.2":"2026-07-18T13:02:33.167Z","0.1.3":"2026-07-24T21:10:14.778Z"},"bugs":{"url":"https://github.com/askalf/strongroom/issues"},"author":{"name":"Thomas Sprayberry"},"license":"MIT","homepage":"https://github.com/askalf/strongroom#readme","keywords":["mcp","model-context-protocol","ai-agents","agent-security","secrets","credentials","leases","least-privilege","own-your-stack"],"repository":{"url":"git+https://github.com/askalf/strongroom.git","type":"git","directory":"mcp"},"description":"An MCP server that is the strongroom control plane: its tools mint scoped, expiring, revocable leases and hand agents a lease-backed base URL — so API keys never enter agent context. Part of Own Your Stack.","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"readme":"# @askalf/strongroom-mcp\n\n**An MCP server that is the [strongroom](https://github.com/askalf/strongroom) control plane.** Its tools mint scoped, expiring, revocable **leases** and hand agents a lease-backed base URL — so **API keys never enter agent context**. Part of [Own Your Stack](https://sprayberrylabs.com).\n\n> Every MCP server that talks to a credentialed API faces the same question: **where does the key live?** A key in the server's env is one compromise away from gone, and an MCP tool that *returns* a credential writes it straight into the calling agent's context window — persisted in history, logs, and traces, readable by every poisoned tool that shares the conversation.\n>\n> strongroom-mcp is the answer, as one rule: **a credential-granting tool returns a capability, not a secret.** The answer to \"give me upstream access\" is a lease-backed base URL. It is *safe to land in agent context* precisely because it is not a secret.\n\n## Install\n\n```bash\nnpm install -g @askalf/strongroom-mcp\n```\n\n## How it works\n\nThis server **is** the control plane. It owns the encrypted strongroom vault and runs strongroom's egress **broker** in-process:\n\n```\nMCP client (agent) ── stdio/JSON-RPC ──▶ strongroom-mcp (owns vault + broker)\n        │  grant_lease → base_url                 │\n        │  (a capability, NOT a key)              ▼\n        └── direct API calls, NO key ──────▶ egress broker ──▶ upstream API\n                    via the lease-backed base URL   REAL key injected here\n```\n\n1. The operator loads secrets into the vault **out-of-band** with the strongroom CLI (`strongroom add NAME`). The MCP server never sees a secret value — deliberately there is **no `add_secret` tool**, so no secret value ever crosses the MCP wire in either direction.\n2. An agent calls `grant_lease`; the server mints a scoped, expiring, revocable lease and returns a **lease-backed base URL** (`http://127.0.0.1:<port>/<lease>`).\n3. The agent points its HTTP client's base URL at that URL and calls the upstream with **no key**. The broker checks the lease (host + path allowlist + rate + concurrency), redeems it (atomic + audited), and **injects the real secret at the network boundary**.\n\nCompromise the agent — or read its whole context window — and you get a scoped, expiring, revocable capability. Never the key.\n\n## Tools\n\n| Tool | Returns | Notes |\n|------|---------|-------|\n| `grant_lease` | a lease-backed `base_url` + fingerprint | mints a scoped, expiring, revocable lease. The raw key is never returned. |\n| `list_secrets` | secret **names** | never values — just what you can grant against. |\n| `list_leases` | outstanding leases by **fingerprint** | raw lease ids are never stored or returned. |\n| `revoke_lease` | `{ revoked }` | kills a lease at once (by id or its base URL); the real secret is untouched. |\n| `broker_status` | broker base URL + listening state | lease URLs are `broker_base + \"/\" + <lease>`. |\n\n`grant_lease` inputs: `secret` (name), `upstream` (URL the secret may be injected toward), and optional `ttl_s`, `uses`, `inject` (`bearer` | `x-api-key`), `paths` (glob allowlist), `rate` (req/min), `concurrency`.\n\n## Configure (MCP client)\n\n```json\n{\n  \"mcpServers\": {\n    \"strongroom\": {\n      \"command\": \"strongroom-mcp\",\n      \"env\": {\n        \"KEEPER_HOME\": \"/home/you/.keeper\",\n        \"STRONGROOM_BROKER_HOST\": \"127.0.0.1\",\n        \"STRONGROOM_BROKER_PORT\": \"8771\"\n      }\n    }\n  }\n}\n```\n\nThe vault must already hold your secrets (`strongroom add openai:key`, etc). The broker binds to loopback only; `STRONGROOM_BROKER_PORT=0` picks an ephemeral port (read it back with `broker_status`). `STRONGROOM_MAX_TTL` / `STRONGROOM_MAX_USES`, if set, cap every lease this server mints.\n\n## Why keys never enter context\n\n- The **server** holds a vault + broker, not raw keys in tool return values. The secret only touches the request at the broker's network boundary.\n- Every **tool result** is a capability or a fingerprint — safe to persist in agent history, logs, and traces.\n- A lease is **bound to one upstream** (and optionally to specific paths), so even the capability can only be injected toward that host — not an attacker URL. Revoke it and both the tool and any direct access die instantly, without rotating the real key.\n\n## License\n\nMIT © Thomas Sprayberry\n","readmeFilename":"README.md"}