{"_id":"@astrixsecurity/mcp-secret-wrapper","_rev":"7-d32a3b9c53400614eee06cab3519dd49","name":"@astrixsecurity/mcp-secret-wrapper","dist-tags":{"latest":"0.1.0"},"versions":{"0.0.2":{"name":"@astrixsecurity/mcp-secret-wrapper","version":"0.0.2","keywords":["mcp","aws","secrets-manager","cli"],"author":{"name":"Astrix Security"},"license":"Apache-2.0","_id":"@astrixsecurity/mcp-secret-wrapper@0.0.2","maintainers":[{"name":"oshri.shmuel","email":"oshri.shmuel@astrix-security.com"}],"homepage":"https://github.com/astrix-security/mcp-secret-wrapper#readme","bugs":{"url":"https://github.com/astrix-security/mcp-secret-wrapper/issues"},"bin":{"mcp-secret":"dist/cli.js"},"dist":{"shasum":"ea202aa6ce86332d28a747496865bdb40adb17c4","tarball":"https://registry.npmjs.org/@astrixsecurity/mcp-secret-wrapper/-/mcp-secret-wrapper-0.0.2.tgz","fileCount":17,"integrity":"sha512-YCk9fjzrny542YMiRjcu3bZl2YG0G5qanMArPjJh4WhDTB0OMaIJrXHZvXoSqas8SEBw90e5J2V/TsXFbUMK9w==","signatures":[{"sig":"MEYCIQCN1/90g/BTlqC+9xtoftadsAlae6O8Txh21d6w1eKhywIhAK8V5IFOIOkaGPJuZ5HzgqMdbs+2eoCv7xZClaEgZlap","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":38977},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=14.0.0"},"gitHead":"aeaa620e41b480eb8524b00af56024b621517a7e","scripts":{"dev":"ts-node src/cli.ts","lint":"eslint .","test":"jest","build":"tsc && shx chmod +x dist/*.js","start":"node dist/cli.js","format":"prettier --write .","prepare":"npm run build","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"oshri.shmuel","email":"oshri.shmuel@astrix-security.com"},"repository":{"url":"git+https://github.com/astrix-security/mcp-secret-wrapper.git","type":"git"},"_npmVersion":"10.8.2","description":"MCP Server Secret Wrapper based on Vaults","directories":{},"_nodeVersion":"18.20.8","dependencies":{"@aws-sdk/client-secrets-manager":"^3.787.0"},"_hasShrinkwrap":false,"devDependencies":{"shx":"^0.3.4","jest":"^29.6.1","eslint":"^8.45.0","ts-jest":"^29.1.1","ts-node":"^10.9.1","prettier":"^3.0.0","typescript":"^5.1.6","@types/jest":"^29.5.3","@types/node":"^20.4.5","@types/aws-sdk":"^2.7.4","eslint-config-prettier":"^9.0.0","eslint-plugin-prettier":"^5.0.0","@typescript-eslint/parser":"^6.2.0","@typescript-eslint/eslint-plugin":"^6.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secret-wrapper_0.0.2_1760006664713_0.2368097943715246","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@astrixsecurity/mcp-secret-wrapper","version":"0.1.0","keywords":["mcp","aws","secrets-manager","azure","key-vault","cli"],"author":{"name":"Astrix Security"},"license":"Apache-2.0","_id":"@astrixsecurity/mcp-secret-wrapper@0.1.0","maintainers":[{"name":"oshri.shmuel","email":"oshri.shmuel@astrix-security.com"}],"homepage":"https://github.com/astrix-security/mcp-secret-wrapper#readme","bugs":{"url":"https://github.com/astrix-security/mcp-secret-wrapper/issues"},"bin":{"mcp-secret":"dist/cli.js"},"dist":{"shasum":"c99d30d9295099b7cfd1bf2ed6c3a61132fda6e5","tarball":"https://registry.npmjs.org/@astrixsecurity/mcp-secret-wrapper/-/mcp-secret-wrapper-0.1.0.tgz","fileCount":21,"integrity":"sha512-F/6aUGCgXA4HPwPwNtDwdCi6P07mfOMrC3HBli/GuzrlvHJeL1xm7GlNEN5IRHzKiVG336kXpaEaUTodRf8AwQ==","signatures":[{"sig":"MEUCIFusYajZ+9pBJxmwe7btMjXvAqBzljWDuDnxINF2ougjAiEAnV2PqFVz1zQJrjSE0XfJS5XR0FeKJXuzYy1r/CT9Dgw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":62141},"jest":{"preset":"ts-jest","testMatch":["**/__tests__/**/*.test.ts"],"testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20.0.0"},"gitHead":"819348df76555a967132d4e3810cb92a1493784d","scripts":{"dev":"ts-node src/cli.ts","lint":"eslint .","test":"jest --passWithNoTests","build":"tsc && shx chmod +x dist/*.js","start":"node dist/cli.js","format":"prettier --write .","prepare":"npm run build","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"oshri.shmuel","email":"oshri.shmuel@astrix-security.com"},"repository":{"url":"git+https://github.com/astrix-security/mcp-secret-wrapper.git","type":"git"},"_npmVersion":"10.8.2","description":"MCP Server Secret Wrapper based on Vaults","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@azure/identity":"^4.13.1","@azure/keyvault-secrets":"^4.10.0","@google-cloud/secret-manager":"^6.0.0","@aws-sdk/client-secrets-manager":"^3.1011.0"},"_hasShrinkwrap":false,"devDependencies":{"shx":"^0.3.4","jest":"^29.6.1","eslint":"^8.45.0","ts-jest":"^29.1.1","ts-node":"^10.9.1","prettier":"^3.0.0","typescript":"^5.1.6","@types/jest":"^29.5.3","@types/node":"^20.4.5","@types/aws-sdk":"^2.7.4","eslint-config-prettier":"^9.0.0","eslint-plugin-prettier":"^5.0.0","@typescript-eslint/parser":"^6.2.0","@typescript-eslint/eslint-plugin":"^6.2.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secret-wrapper_0.1.0_1776765791755_0.44926357578900755","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2025-10-09T10:44:24.583Z","modified":"2026-04-24T08:43:24.153Z","0.0.1":"2025-10-09T10:12:20.077Z","0.0.2":"2025-10-09T10:44:24.931Z","0.1.0":"2026-04-21T10:03:11.891Z"},"bugs":{"url":"https://github.com/astrix-security/mcp-secret-wrapper/issues"},"author":{"name":"Astrix Security"},"license":"Apache-2.0","homepage":"https://github.com/astrix-security/mcp-secret-wrapper#readme","keywords":["mcp","aws","secrets-manager","azure","key-vault","cli"],"repository":{"url":"git+https://github.com/astrix-security/mcp-secret-wrapper.git","type":"git"},"description":"MCP Server Secret Wrapper based on Vaults","maintainers":[{"email":"neta.ravid@astrix-security.com","name":"neta-astrix"},{"email":"yuval.sasson@astrix-security.com","name":"yuval-astrix"},{"email":"oshri.shmuel@astrix-security.com","name":"oshri.shmuel"}],"readme":"<div align=\"center\">\n<img src=\"https://public-astrix-bucket.s3.us-east-1.amazonaws.com/mcp-wrapper-banner.png\" alt=\"MCP Secret Wrapper Logo\" maxWidth=\"500px\"/>\n\n[![License: Apache 2.0](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\n</div>\n\nSecurely inject secrets from vault systems into MCP (Model Context Protocol) servers without exposing credentials in configuration files.\n\n## Usage\n\nConvert any MCP Server configured for your client and uses a static secret in 2 simple steps:\n\n1. Add the secret to one of the [supported vaults](#support)\n2. Replace the server's settings in the configuration file to use MCP Secret Wrapper:\n   - Run MCP Secret Wrapper with `npx`\n   - Pass any environment variables that should be injected. Their value is the secret location.\n   - Place the separator (`--`) followed by the previous command and all its arguments\n   - Add the required `VAULT_TYPE` environment variable and any additional optional environment variables either in the `env` section or as CLI arguments (`--vault-type`). You can find examples of both usages in our [Example MCP Server](./example/README.md)\n\n### Example Usage - GitHub MCP with AWS Secret Manager\n\n**Before: Config Environment Variable (❌ Insecure - Hardcoded Secret)**\n\n```json\n{\n  \"mcpServers\": {\n    \"githubApi\": {\n      \"command\": \"docker\",\n      \"args\": [\n        \"run\",\n        \"-i\",\n        \"--rm\",\n        \"-e\",\n        \"GITHUB_PERSONAL_ACCESS_TOKEN\",\n        \"ghcr.io/github/github-mcp-server\"\n      ],\n      \"env\": {\n        \"GITHUB_PERSONAL_ACCESS_TOKEN\": \"github_pat_EXAMPLE\"\n      }\n    }\n  }\n}\n```\n\n**After: Using Vault (✅ No Exposed Secret)**\n\n```json\n{\n  \"mcpServers\": {\n    \"githubApi\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@astrixsecurity/mcp-secret-wrapper\",\n        \"GITHUB_PERSONAL_ACCESS_TOKEN=arn:aws:secretsmanager:us-east-1:123456789012:secret:example-ABCDE\",\n        \"--\",\n        \"docker\",\n        \"run\",\n        \"-i\",\n        \"--rm\",\n        \"-e\",\n        \"GITHUB_PERSONAL_ACCESS_TOKEN\",\n        \"ghcr.io/github/github-mcp-server\"\n      ],\n      \"env\": {\n        \"VAULT_TYPE\": \"aws\",\n        \"VAULT_PROFILE\": \"aws-profile\",\n        \"VAULT_REGION\": \"us-east-1\"\n      }\n    }\n  }\n}\n```\n\nhttps://github.com/user-attachments/assets/9af6e6b3-3694-49de-b107-8749e0630db3\n\n**See what's going on behind-the-scenes by using our example MCP server:** [Example MCP Server](./example/README.md)\n\n## JSON Path Extraction\n\nWhen your vault stores secrets as JSON objects, you can extract specific values using dot-notation paths. This is useful when a single secret contains multiple values that need to be injected as separate environment variables.\n\n### How It Works\n\nAppend a `#` delimiter followed by a JSON path to your secret ID. The path uses dot notation to navigate through nested JSON objects.\n\n**Format:** `SECRET_ID#path.to.value`\n\n### Example: Database Configuration\n\nSuppose your vault contains a secret with the following JSON structure:\n\n```json\n{\n  \"db\": {\n    \"credentials\": {\n      \"username\": \"demo_user\",\n      \"password\": \"demo_password\"\n    },\n    \"host\": \"postgres\",\n    \"port\": 5432,\n    \"name\": \"demo\"\n  }\n}\n```\n\nYou can extract individual values using these paths:\n\n- `db.credentials.username` - Extracts `\"demo_user\"`\n- `db.credentials.password` - Extracts `\"demo_password\"`\n- `db.host` - Extracts `\"postgres\"`\n- `db.port` - Extracts `5432` (converted to string)\n\n### Usage Example\n\n```json\n{\n  \"mcpServers\": {\n    \"myServer\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@astrixsecurity/mcp-secret-wrapper\",\n        \"DB_USERNAME=arn:aws:secretsmanager:us-east-1:123456789012:secret:my-db-config#db.credentials.username\",\n        \"DB_PASSWORD=arn:aws:secretsmanager:us-east-1:123456789012:secret:my-db-config#db.credentials.password\",\n        \"DB_HOST=arn:aws:secretsmanager:us-east-1:123456789012:secret:my-db-config#db.host\",\n        \"--\",\n        \"node\",\n        \"/path/to/server.js\"\n      ],\n      \"env\": {\n        \"VAULT_TYPE\": \"aws\",\n        \"VAULT_REGION\": \"us-east-1\"\n      }\n    }\n  }\n}\n```\n\n### Important Notes\n\n⚠️ **Secret ID and the `#` Delimiter**: The `#` character is used as the delimiter for JSON path extraction.\n\n**Why this delimiter?** Using `#` in secret names is generally considered bad practice across vault systems (AWS Secrets Manager, GCP Secrets Manager, etc.), so it's unlikely to appear in real secret IDs. This makes it a safe choice for our delimiter.\n\n**What happens if your secret ID contains `#`?**\n\n- ❌ **Without JSON path**: If your secret ID is `my#secret` and you use it without a JSON path (`API_KEY=my#secret`), the parser will incorrectly split it, treating `my` as the secret ID and `secret` as a JSON path. This will cause the lookup to fail.\n\n- ✅ **With JSON path**: If your secret ID is `my#secret` and you use it with a JSON path (`API_KEY=my#secret#db.password`), it will work correctly because the parser splits on the **last** `#` character.\n\n**Best practice**: Avoid using `#` in your secret names entirely. This follows vault naming conventions and prevents parsing issues when you're not using JSON path extraction.\n\n### Supported Value Types\n\nJSON path extraction supports extracting primitive values:\n\n- **Strings**: Returned as-is\n- **Numbers**: Converted to string representation\n- **Booleans**: Converted to string (`\"true\"` or `\"false\"`)\n\n**Not supported:**\n\n- Arrays\n- Objects (nested objects)\n- `null` values\n\nIf you need to extract a nested object or array, you'll need to store it as a separate secret or use a different approach.\n\n## Support\n\n| Vault Type          | Status         | Description                                                                                       |\n| ------------------- | -------------- | ------------------------------------------------------------------------------------------------- |\n| AWS Secrets Manager | ✅ Supported   | Full support for AWS Secrets Manager with IAM authentication                                      |\n| GCP Secret Manager  | ✅ Supported   | Full support for GCP Secret Manager with service account and ADC authentication                   |\n| HashiCorp Vault     | 🚧 In-Progress | Support for HashiCorp Vault                                                                       |\n| Azure Key Vault     | ✅ Supported   | Full support for Azure Key Vault with DefaultAzureCredential and service principal authentication |\n\n**📚 Detailed Documentation:** [Vault Specific Guides](./docs)\n\n## Why?\n\nMCP servers are becoming the backbone of AI agent infrastructure, but most implementations lead to severe risk by exposing hardcoded credentials. Our analysis of 5,000+ MCP server implementations revealed that **over 50% use static, hardcoded API keys and secrets** in their configuration files.\n\n### The Problem\n\n- **Exposed Credentials**: API keys, tokens, and secrets stored in plain text\n- **No Rotation**: Static credentials that never expire or rotate\n- **Access Control**: No fine-grained access control\n- **Compliance**: Violates security best practices and compliance requirements\n\n### The Solution\n\nMCP Secret Wrapper provides:\n\n- **Dynamic Secret Retrieval**: Secrets are fetched at runtime from secure vaults\n- **No Hardcoded Secerts**: No secrets are present on the local machine\n- **Multi-Vault Support**: Works with AWS, HashiCorp, Azure, and Google vaults\n\n**Read our research:** [Blog](https://astrix.security/blog) - An analysis of 5,000 MCP server implementations and their identity security gap.\n\n## Contributing\n\nWe welcome contributions - this tool can and should be improved by the community. Here's how you can help:\n\n### Quick Start\n\n1. Fork the repository\n2. Create a feature branch: `git checkout -b feat/your-feature`\n3. Make your changes and add tests\n4. Commit your changes: `git commit -m 'Add your feature'`\n5. Push to your branch: `git push origin feat/your-feature`\n6. Open a Pull Request\n\n### Adding New Vault Support\n\n1. Create a new plugin in `src/vaults/plugins/`\n2. Implement the `VaultPlugin` interface\n3. Add tests for your implementation\n4. Update the registry and documentation\n\nFor more details, see our [Contributing Guidelines](./CONTRIBUTING.md).\n\n## License\n\nThis project is licensed under the Apache License 2.0 - see the [LICENSE](./LICENSE) file for details.\n\n## Acknowledgements\n\n- **Yuval Sasson** - For pioneering the initiative to dynamically retrieve secrets for MCP servers\n- **Omer Alon** - For developing and releasing the MCP Secert Wrapper tool\n- **Oshri Shmuel** - For developing and releasing the MCP Secert Wrapper tool\n- **Neta Ravid** - For developing, releasing, and maintaining the MCP Secret Wrapper tool\n- **MCP Community** - For creating and maintaining the MCP framework\n\n---\n\n<div align=\"center\">\n  <p>Built with ❤️ by the <a href=\"https://astrix.security\">Astrix Security</a> team</p>\n  <p>\n    <a href=\"https://astrix.security\">Website</a> •\n    <a href=\"https://astrix.security/blog\">Blog</a> •\n    <a href=\"https://github.com/astrix-security/mcp-secret-wrapper/issues\">Issues</a>\n  </p>\n</div>\n","readmeFilename":"README.md"}